Methodology
About the Internet Takedown Index
The Internet Takedown Index documents publicly verifiable law enforcement actions that seized, disabled, redirected, took control of, or compelled the shutdown of internet infrastructure serving an illicit online service. This page is the whole method: what qualifies, how it is counted, how strongly it is sourced, and what the record does not cover.
- Research cutoff
- August 20, 2026
- Last updated
- August 21, 2026
- Documented incidents
- 104
- Umbrella campaigns
- 4
- Verified core
- 38
- Extended pass
- 70
What counts as a takedown
The inclusion rule is carried in the dataset itself, not written for this page. This is it, unedited.
An incident enters the verified core when a law-enforcement agency, prosecutor, court, or other government-backed authority materially seized, redirected, sinkholed, disabled, covertly took control of, remotely remediated, or compelled the shutdown of internet infrastructure serving an illicit online service. Arrest-only cases, indictment-only cases, sanctions-only actions, ordinary platform moderation, and purely private civil takedowns are excluded from the core and recorded separately.
Outcomes for the people attached to an incident use a fixed vocabulary, so incidents can be compared across years, jurisdictions, and case types. Every label below is a group of action types recorded against a named person, never an aggregate figure quoted by an agency. Official aggregate counts are kept in separate fields and are never added to these.
| Status label | Definition |
|---|---|
| Charged | A formal criminal charge against a named person is on the public record. A superseding indictment does not create a second person record or a second count. Counted from person records with an action type of charged or indicted. |
| Apprehended | A named person was taken into custody, or handed themselves in. Extradition is recorded as its own action and is never counted as a second apprehension. Counted from person records with an action type of arrested, detained, or surrendered. |
| Convicted | A named person was convicted at trial or entered a guilty plea. Sentencing is recorded separately, so a conviction here does not imply a sentence is on the record. Counted from person records with an action type of convicted or pleaded guilty. |
| Fugitive | A named person is publicly sought and not recorded as being in custody. The label reflects the last public statement, not a check made at the research cutoff. Counted from person records with an action type of wanted. |
Unknown does not mean zero. A blank count means the public record does not establish a number. Zero appears only where a source explicitly establishes that the number is zero.
Counting incidents
One entry is one enforcement action against one target. Where a single operation is announced by several agencies it is recorded once, with every participating organization listed against it. Follow-on actions against the same target are separate entries linked back to the original, so a long-running operation does not inflate the totals.
The counting rules below are recorded in the dataset and applied to every figure on this site.
- record_kind=umbrella_campaign records are excluded from incident totals.
- reported_* fields carry official aggregate counts; named_* fields carry counts derived from normalized person records. These are never added together.
- Extradition is recorded as a distinct person_action and is never counted as a second apprehension.
- Superseding indictments do not create new person records.
- null means unknown. 0 is used only where a reliable source explicitly establishes zero.
Verification tiers
Not every record was checked to the same depth, and the record says which is which. Every takedown page carries its tier, so an extended-pass entry cannot pass for a verified one.
Verified core
38 records
34 incidents and 4 umbrella campaigns went through a dedicated source-verification pass: publisher, title, publication date, and docket or case number confirmed for each cited record.
Extended pass
70 records
Added in a broader aggregation pass and not independently re-verified source by source. Their sources are capped at P2 and S2, and their dates and figures may still need reconciling. Treat them as a research queue, not a finished account.
The dataset's own note on the verified core:
The 'verified_core' subset (38 incidents/4 umbrellas, IDs td_2013_silk_road through td_2026_poweroff_apr plus the four um_* umbrella records) underwent a dedicated source-verification and inline-embedding pass confirming publisher, title, publication date, and docket/case numbers for each record; several date and figure conflicts were explicitly resolved (Genesis Market = 11 official domains; Fitzpatrick arrest 2023-03-15 and 2025-09-16 resentencing to 36 months; Cazes docket 1:17-CR-00144-LJO, E.D. Cal.).
And on the extended pass:
All remaining takedown records were added in a second, broader aggregation pass drawing on three independent deep-research reports covering roughly 75-78 worldwide incidents each. These records were NOT independently re-verified source-by-source to the same standard as the verified core: source_quality for extended-pass sources is capped at P2/S2, URLs are not yet populated, and several dates/figures may need reconciliation (e.g. td_2026_poweroff_apr_offsides may be a duplicate report of the same action as td_2026_poweroff_apr under a different domain count -- flagged, not merged, pending confirmation). Treat extended-pass records as a prioritized research queue for the same verification workflow already applied to the core.
One figure in the snapshot does not add up. The snapshot stores the extended pass as 66 records. Counted directly from the records it is 70, because the stored figure subtracts the 4 umbrella campaigns from the incident total, and every umbrella campaign is in the verified core. The counted figure is the one used across this site.
Classification labels
Where a service or a group is documented operating again after an action, that later activity is recorded as its own row against the original entry. Two vocabularies describe it: what the successor's relationship to the original is, and how strongly the sources support that reading. Both are defined in the dataset. Silence is not read as a shutdown, and a reused name is not read as a return.
| Relationship | Definition |
|---|---|
| Same operators | The same people are documented running the replacement. |
| Same service on replacement infrastructure | The service itself came back on different domains or servers. Whether the same people run it is not established. |
| Rebrand | The service returned under a different name, with continuity documented. |
| Partial operator continuity | Some of the original operators appear in the successor, not all of them. |
| Copycat | Someone else took the name or the model. No continuity of people or infrastructure is documented. |
| Ecosystem successor | A different service absorbed the users or the market. No direct continuity with the original. |
| Claimed return | A return was announced, by the operators or by a party claiming to be them, and nothing independent confirms it. |
| Relationship not established | A successor was recorded but its relationship to the original is not established. |
| Confidence | Definition |
|---|---|
| Confirmed | An official source states the link. |
| High | Well supported by the cited sources, without an official statement of the link. |
| Medium | Supported by the cited sources but not settled. |
| Low | Weakly supported. Recorded so the possibility is visible, not because it is established. |
| Disputed | The cited sources disagree about whether the link is real. |
| Not established | Not graded. |
On the return class letters
Some records also carry a return class, a single letter from A to G. That grading comes from the source dataset and its scale is published nowhere in the data, so this site does not translate the letters into words. Where a letter appears it is shown as it is, labeled "Return class B" and nothing more.
To judge whether something came back, read the relationship and the confidence above, the date the successor was first seen, and whether it was seized again in a later action. Those fields are defined. The letter is not, and inventing a definition for it would be the same kind of guess this index exists to avoid.
Sources
Every claim in an entry is tied to at least one cited source, and each source is a full bibliographic record: publisher, title, publication date, and where available a docket or case number. Official records take precedence. Charging documents, seizure notices, and agency statements set the facts. Reporting is used to establish timing and aftermath. Where accounts conflict, the entry follows the official record and marks the remainder as not established. Every source is listed on the Sources page.
Each source also carries a provenance grade. The grading scale is the dataset's own, not this site's. The letter is the class of source, P for primary and official, S for secondary, T for tertiary, and the digit is the dataset's confidence in the record, with 0 the strongest. The dataset does not publish a fuller definition than that, so the table below reports what actually carries each grade in this corpus rather than a definition nobody wrote down.
| Grade | In this corpus | What carries it |
|---|---|---|
| P0, Primary | 4 sources, all marked official | Indictment (2), Court filing (1), Judgment (1) |
| P1, Primary | 58 sources, all marked official | Prosecutor release (29), Government release (18), Law enforcement release (11) |
| P2, Primary | 60 sources, all marked official | International agency release (51), Law enforcement release (5), Government release (4) |
| S1, Secondary | 3 sources, none marked official | News report (3) |
| S2, Secondary | 18 sources, 15 marked official | Prosecutor release (10), Law enforcement release (4), News report (3), Government release (1) |
| T1, Tertiary | 6 sources, none marked official | Participating company report (6) |
| T2, Tertiary | 3 sources, none marked official | Cybersecurity report (3) |
The grades are applied unevenly. Prosecutor and law enforcement releases appear under both P1 and S2, and participating company reports sit at T1 rather than in the S range. The grades are reported as the dataset recorded them and have not been reassigned here, because rewriting them would put this site's judgment over the record's.
Only 4 of the 152 sources carry a URL. The rest were recorded with publisher, title, and date so they can be retrieved from the publisher. No URL was reconstructed from memory, because a plausible invented link is worse than no link.
Known limitations
These are the dataset's own recorded limitations. They are published in full rather than summarized, because a summary is where the inconvenient ones go missing.
- Not exhaustive. No complete global registry of law-enforcement internet takedowns exists in the public record.
- Corpus is weighted toward US-led and Europol/INTERPOL-coordinated actions documented in English.
- Extended-pass records (added in this consolidation) require a dedicated verification pass equivalent to the one already applied to the original 38-incident core before their source_quality can be upgraded from P2/S2.
- Source URLs are recorded with publisher, title, and publication date where known; exact URL strings were not re-opened and verified character-for-character for extended-pass records. No URL has been invented.
- Unnamed CSAM services, routine piracy and counterfeit-domain waves, national blocking actions, terrorist-content referrals, and infrastructure disconnected quietly at police request are materially undercounted.
- Non-English national records (BKA.de, Politie.nl, Gendarmerie, Japanese NPA, Korean National Police, Latin American prosecutors, Italian Polizia Postale) were consulted only through English-language relays.
- Aggregate official arrest counts are never summed with counts of publicly named people. Placeholder person records were not created.
- Several final legal outcomes remain open as of the cutoff and are recorded as pending rather than resolved.
- td_2026_poweroff_apr (53 domains/21 countries/4 arrests, Europol-sourced) and td_2026_poweroff_apr_offsides (8 domains, USAO Alaska-sourced) may describe the same April 2026 PowerOFF wave reported through two different agency channels with different domain counts; both are retained separately pending reconciliation rather than merged or dropped.
- A second people-and-person_actions pass (after initial consolidation) added named individuals present in the source deep-research reports but initially omitted from the extended-pass incidents (e.g. the 17 named ANOM distributors, DanaBot's two named lead defendants, Backpage's Carl Ferrer, Megaupload's co-defendants, BTC-e's Alexander Vinnik, Bitzlato's Anatoly Legkodymov, ChipMixer's Minh Quốc Nguyễn, Z-Library's Napolsky and Ermakova, Kingdom Market's Alan Bill, Dridex's Andrey Ghinkul, and RedLine's Maxim Rudometov). Where a source described an arrest or charge without naming the individual (e.g. Wall Street Market's three German administrators, Ragnar Locker's Paris arrestee, Samourai Wallet's founders), the record was deliberately left as an aggregate reported_apprehended_count rather than a placeholder person record, per the project's own counting rules.
Coverage gaps
A coverage gap is something this index knows it is missing. Each one records the dimension it sits on, what is absent, why the pass did not reach it, and the search that would close it. Publishing the gaps is the only way a count of 104 incidents can be read for what it is: what was found, not what happened.
| Dimension | What is missing | Why | Recommended next search |
|---|---|---|---|
| Activity type Child sexual abuse material | Only one CSAM takedown is represented despite this being one of the most frequent categories of hidden-service seizure. Playpen, Boystown, and numerous unnamed services are absent. | Many CSAM operations are announced without naming the service, and details are frequently sealed to protect victims. | Search DOJ, BKA, and Europol releases for hidden-service CSAM seizures, accepting that service names will often be withheld and recording them as unnamed targets. |
| Activity type Piracy and IP | No piracy or counterfeit-goods domain seizures are included, despite recurring US operations such as Operation In Our Sites seizing hundreds of domains annually. | These are high-volume, low-individuation waves that were deprioritized in this pass. | Search HSI and IPR Center releases by year for In Our Sites waves and model each annual wave as a linked incident under an umbrella campaign. |
| Activity type Terrorism and extremism | No terrorism or violent-extremism infrastructure takedowns are included. Europol referral-action days and the Amaq and Rocket.Chat server seizures are absent. | Referral actions often amount to voluntary provider removal, which is excluded, but several Europol operations did involve server seizures that would qualify. | Search Europol EU Internet Referral Unit action-day releases and distinguish referral-based removals from actual server seizures. |
| Activity type Criminal hosting and proxies | Bulletproof hosting takedowns beyond Avalanche are underrepresented, including the Lolek Hosted seizure and various VPN service seizures such as DoubleVPN and Safe-Inet. | Not searched systematically in this pass. | Search Europol and DOJ releases for bulletproof hosting and criminal VPN seizures between 2018 and 2026. |
| Language | Nearly all sources in the corpus are English. German, Dutch, French, Belgian, Korean, and Japanese official releases are cited but their original-language titles and URLs were not captured. | This pass relied on English-language relays of national announcements. | Query bka.de, politie.nl, gendarmerie.interieur.gouv.fr, om.nl, and police.go.kr directly in the local language and record original titles with translation notes. |
| Named people | Several incidents have official charge counts materially higher than the number of named person records, notably ANOM (17 charged, 1 named), the DanaBot indictment (16 charged, 1 named), and the December 2022 PowerOFF wave (6 charged, 0 named). | Names were published but were not individually captured in this pass. Placeholder people were deliberately not created. | Retrieve the relevant DOJ releases and indictments and create one person record per named defendant, deduplicating against existing records. |
| Legal outcomes | Several legal outcomes remain unresolved, including US sentencing for Vasiliev and Astamirov, the Panev trial, Coelho's extradition status, Fitzpatrick's resentencing, and the reported Russian prosecution of Matveev. | Outcomes postdate the original announcements and require targeted docket checks. | Check the District of New Jersey and Eastern District of Virginia dockets, and seek an official Russian source for the Matveev report before treating it as established. |
| Time period pre-2013 | The corpus begins in 2013. Significant earlier operations including Mariposa (2010), Waledac (2010), Rustock (2011), Coreflood (2011), DNSChanger (2011), and the Bredolab server seizure (2010) are absent. | Research effort in this pass concentrated on the period with the richest official documentation. Older press releases are frequently delinked or archived only. | Search DOJ and Europol archives plus the Internet Archive for 2008 to 2012 botnet and domain seizure releases, then verify each infrastructure action against a contemporaneous official source. |
| Possible duplicate US/EU, DDoS for hire, 2026-04 | td_2026_poweroff_apr (Europol-sourced: 53 domains, 21 countries, 4 arrests, 25 search warrants) and td_2026_poweroff_apr_offsides (USAO Alaska-sourced: 8 domains) both describe an April 2026 PowerOFF wave. These may be the same action reported through two different agency press channels with different domain counts, or genuinely separate concurrent waves. | The two source reports describing this period were not cross-reconciled against a single primary document in this pass. | Retrieve the underlying USAO Alaska press release and the Europol April 2026 release side by side and determine whether the 8-domain figure is a subset of, or distinct from, the 53-domain figure. |
| Unannounced actions | Infrastructure disconnected quietly at police request, provider-compelled shutdowns without public announcement, and sealed matters are structurally invisible to this method. | These actions produce no public record by design. | Consult academic and NGO synthesis literature and hosting-provider transparency reports, and treat any resulting entries as probable edge cases rather than verified core. |
| Region | Latin America, Africa, South Asia, Southeast Asia, the Middle East, and China are almost entirely absent as lead jurisdictions. INTERPOL-coordinated operations in these regions are not represented. | The pass indexed heavily on US and EU sources. | Search INTERPOL operation releases including Africa Cyber Surge, Operation Serengeti, Operation HAECHI, and Operation Synergia, then verify whether each involved a qualifying infrastructure action. |
| Source quality | Most sources in this corpus are graded P1 or P2 press releases. Only three records cite a P0 court document, and two of those lack a docket number. | Court dockets require targeted retrieval that was not performed in this pass. | Retrieve indictments and judgments from CourtListener and PACER for each named defendant and attach docket numbers to every charge and sentence action. |
| Source verification | Most source records carry a publisher, title, and date but a null URL, flagged in notes as not re-verified in this pass. | URLs were deliberately left null rather than reconstructed from memory, since fabricating plausible URLs would violate the source rules. | Run a verification pass that opens every source, records the canonical URL and an archive URL, corrects any title drift, and downgrades to U any source that cannot be retrieved. |
| Verification depth | 62 takedown records (added in the August 2026 consolidation pass drawing on three deep-research reports) have not undergone the docket-level, inline-source-embedding verification pass applied to the original 38-incident core. Dates, agency attributions, and figures are believed accurate but are sourced from aggregated secondary research rather than re-opened primary documents. | Time-boxed consolidation prioritized breadth of coverage over per-incident verification depth in this pass. | Apply the same source-verification and inline-embedding methodology used for the original core (see the project's source-verification pass) to each extended-pass record, starting with state-sponsored and ransomware incidents where legal/technical precision matters most. |
Excluded candidates
These are the actions that were considered and deliberately left out, with the reason for each. Most fail the inclusion rule on a single point: a sanctions designation that did not touch infrastructure, an indictment with no seizure beside it, a disruption carried out by someone other than a government authority. A handful are marked unresolved, meaning they probably do belong here and were not promoted because their primary sources were not opened in this pass.
This list is part of the record, not an appendix to it. A corpus that only shows what it included cannot be checked.
| Candidate | Date | Classification | Why it was left out |
|---|---|---|---|
| LockBit administration panel compromise | May 7, 2025 | Excluded | The compromise was carried out by an unknown actor, not by a law-enforcement or government-backed authority. Fails the government-action requirement. |
| OFAC designation of Integrity Technology Group | January 3, 2025 | Excluded | Sanctions-only action following the Raptor Train disruption. |
| OFAC and OFSI designations of Khoroshev, Sungatov, and Kondratyev | May 7, 2024 | Excluded | Sanctions-only. Recorded as person_actions of type sanctioned rather than as takedowns. |
| Mikhail Matveev US indictment | May 16, 2023 | Excluded | Indictment with no accompanying infrastructure seizure. Recorded as a person_action against td_2024_cronos_w1 rather than as its own takedown. |
| OFAC sanctions on Genesis Market | April 11, 2023 | Excluded | Sanctions-only action, separate from the domain seizure recorded as td_2023_genesis. |
| OFAC sanctions on Hydra Market and Garantex | April 5, 2022 | Excluded | Sanctions-only action. The designation itself did not seize, redirect, or disable internet infrastructure. The German server seizure on the same date is recorded separately as td_2022_hydra. |
| Sky Global chief executive US indictment | March 12, 2021 | Excluded | Indictment only. Not merged into td_2021_sky_ecc, which records the separate infrastructure and interception action. |
| DNSChanger and Operation Ghost Click | November 8, 2011 | Unresolved | Strong verified-core candidate involving court-authorized replacement DNS servers. Not promoted in this pass because the primary sources were not opened and verified. |
| Coreflood botnet disruption | April 13, 2011 | Unresolved | Strong verified-core candidate involving a court-authorized stop command issued to infected machines. Not promoted in this pass for the same reason. |
| Microsoft civil botnet disruptions without law-enforcement participation, including Waledac, Rustock, and Necurs | No single date | Probable edge case | Purely private civil takedowns under US civil process with no material law-enforcement-controlled infrastructure action. Excluded per the stated scope. Rustock involved some law-enforcement support and is flagged as a probable edge case for reassessment. |
| National website-blocking orders against piracy sites | No single date | Excluded | Blocking orders that restrict access within a single jurisdiction without a broader infrastructure disruption are excluded by the stated scope. |
| Operation PowerOFF waves in 2019, 2023, and May 2025 | No single date | Unresolved | Identified as real waves belonging to um_operation_poweroff but not verified to incident standard in this pass. |
Corrections and updates
Entries are revised whenever new public records appear. Each takedown page carries the date it was last reviewed and the tier it was verified to, so a correction is visible as a change in both. Corrections are applied to the entry itself rather than appended as a note, and the review date advances with them.
A useful correction names three things: the entry it concerns, the field that is wrong, and the document that shows it. Official documents carry the most weight, in the same order used everywhere else here: court filings first, then agency releases, then reporting. A correction that changes a count will also change what the entry says is not established, since a figure moving out of unknown is itself a substantive edit.
A submission address is not published yet. Until it is, the fastest way to see what would need correcting is the coverage gaps table above, which already names the searches this index has not run.
Data download
The full text of every page on this site is published as Markdown, regenerated at each research cutoff, and that is currently the complete export. It carries the same fields as the entries themselves, including source references, status labels, and verification tiers.
Structured CSV and JSON exports of the underlying tables are coming and are not available yet. Reuse of what is published is permitted with attribution. This is a research record, not a legal reference.
Download the full site text or the page index.