Logo

Phishing Kit Take-Down Shows MFA Alone Won't Stop Hackers

Multi-factor authentication (MFA) has been the go-to advice from IT providers for years, and rightly so – it stops the vast majority of basic password-theft attacks in their tracks. But a recent international police operation has put a spotlight on a growing problem: criminals now have off-the-shelf tools that bypass MFA entirely, and they’ve been selling access to these tools to anyone willing to pay. If your business relies on Microsoft 365 (and most do), this is worth ten minutes of your time.

What actually happened

German and US law enforcement, working with Indonesian authorities, took down the infrastructure behind a phishing kit known as Kratos. Investigators described it as one of the most widely used criminal phishing kits in the world, and arrested the man they allege built and operated it. The kit wasn’t a clumsy “your account has been suspended” email scam – it was purpose-built to steal active Microsoft 365 login sessions, allowing attackers to slip past MFA protections without ever needing a victim’s second factor.

This is a significant win, but the takedown of one kit doesn’t mean the technique disappears. Kratos was popular precisely because the method it used – known as adversary-in-the-middle (AiTM) phishing – works reliably against millions of businesses worldwide, and other criminal groups run similar kits right now.

Why MFA doesn’t always save you

Most business owners have been told “turn on MFA and you’re safe.” That advice was true for older-style phishing, where a criminal just wanted your password. With AiTM kits like Kratos, the attack works differently:

  • You receive a very convincing email – often mimicking a supplier invoice, a Microsoft security alert, or a shared document notification.
  • You click through to what looks exactly like the real Microsoft 365 login page.
  • You type in your username and password, and complete your MFA prompt as normal – because you genuinely believe you’re logging into your own account.
  • Behind the scenes, the fake page is actually relaying everything in real time to the real Microsoft login. Once you complete MFA, the attacker’s server captures the resulting session token – essentially a digital “already logged in” pass – and uses it to access your account directly, no further authentication required.

The victim usually has no idea anything went wrong. Everything looked and behaved normally. From there, attackers can read email, reset passwords on other accounts, redirect invoices to their own bank details, or quietly monitor communications for weeks before striking.

Why this matters for regional small businesses

Small and medium businesses in regional Victoria are attractive targets precisely because they’re seen as lower-effort, lower-defence environments compared to large corporates, while still handling real money, supplier relationships, and customer data. A compromised Microsoft 365 account is often the first step toward invoice fraud, where an attacker intercepts a legitimate invoice thread and asks a customer or supplier to pay into a different bank account. By the time anyone notices, the money is gone and difficult to recover.

The good news, as reported by The Hacker News, is that law enforcement cooperation across countries is disrupting these operations at the source. But relying on police to shut down every phishing kit isn’t a security strategy – prevention at your end still matters most.

Practical steps you can take now

You don’t need an enterprise security budget to meaningfully reduce this risk. Consider the following:

  • Move to phishing-resistant MFA where possible. App-based number matching or physical security keys (like FIDO2/passkeys) are far harder for AiTM kits to intercept than simple push-approval or SMS codes.
  • Enable Conditional Access policies in Microsoft 365 (available on Business Premium plans) to block sign-ins from unfamiliar countries or devices, and to require compliant, registered devices for access.
  • Turn on mailbox alerting for suspicious forwarding rules – a common trick attackers use is quietly setting up an email forwarding rule so they keep seeing your mail even after you change your password.
  • Train staff to check the actual web address before entering credentials, not just the look of the page. AiTM phishing pages often use near-identical but slightly wrong domain names.
  • Verify any request to change bank details for suppliers or customers with a phone call to a known number – never by replying to the email thread itself.
  • Review sign-in logs periodically for logins from unexpected locations, especially overseas IP addresses outside business hours.
  • Have an incident response plan so that if an account is compromised, you know immediately who to call and what steps to take – session tokens can be revoked, but only if the compromise is caught quickly.

The bigger lesson

This takedown is a reminder that cybersecurity isn’t a “set and forget” exercise. MFA remains essential and dramatically reduces risk, but criminals adapt their tools to work around whatever defence becomes standard. The businesses that stay safest are the ones that combine sensible technical controls with staff awareness and a habit of double-checking anything involving money or login credentials, particularly when it arrives by email.

If you’re not sure whether your current Microsoft 365 setup includes protections against this kind of session-hijacking attack, it’s a conversation worth having with whoever manages your IT before it becomes a costly lesson learned the hard way.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions
Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions