Multi-factor authentication (MFA) has been the go-to advice from IT providers for years, and rightly so – it stops the vast majority of basic password-theft attacks in their tracks. But a recent international police operation has put a spotlight on a growing problem: criminals now have off-the-shelf tools that bypass MFA entirely, and they’ve been selling access to these tools to anyone willing to pay. If your business relies on Microsoft 365 (and most do), this is worth ten minutes of your time.
German and US law enforcement, working with Indonesian authorities, took down the infrastructure behind a phishing kit known as Kratos. Investigators described it as one of the most widely used criminal phishing kits in the world, and arrested the man they allege built and operated it. The kit wasn’t a clumsy “your account has been suspended” email scam – it was purpose-built to steal active Microsoft 365 login sessions, allowing attackers to slip past MFA protections without ever needing a victim’s second factor.
This is a significant win, but the takedown of one kit doesn’t mean the technique disappears. Kratos was popular precisely because the method it used – known as adversary-in-the-middle (AiTM) phishing – works reliably against millions of businesses worldwide, and other criminal groups run similar kits right now.
Most business owners have been told “turn on MFA and you’re safe.” That advice was true for older-style phishing, where a criminal just wanted your password. With AiTM kits like Kratos, the attack works differently:
The victim usually has no idea anything went wrong. Everything looked and behaved normally. From there, attackers can read email, reset passwords on other accounts, redirect invoices to their own bank details, or quietly monitor communications for weeks before striking.
Small and medium businesses in regional Victoria are attractive targets precisely because they’re seen as lower-effort, lower-defence environments compared to large corporates, while still handling real money, supplier relationships, and customer data. A compromised Microsoft 365 account is often the first step toward invoice fraud, where an attacker intercepts a legitimate invoice thread and asks a customer or supplier to pay into a different bank account. By the time anyone notices, the money is gone and difficult to recover.
The good news, as reported by The Hacker News, is that law enforcement cooperation across countries is disrupting these operations at the source. But relying on police to shut down every phishing kit isn’t a security strategy – prevention at your end still matters most.
You don’t need an enterprise security budget to meaningfully reduce this risk. Consider the following:
This takedown is a reminder that cybersecurity isn’t a “set and forget” exercise. MFA remains essential and dramatically reduces risk, but criminals adapt their tools to work around whatever defence becomes standard. The businesses that stay safest are the ones that combine sensible technical controls with staff awareness and a habit of double-checking anything involving money or login credentials, particularly when it arrives by email.
If you’re not sure whether your current Microsoft 365 setup includes protections against this kind of session-hijacking attack, it’s a conversation worth having with whoever manages your IT before it becomes a costly lesson learned the hard way.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804
(+61) 0412 440 804