Methodology
Excluded candidates
These are the actions that were considered and deliberately left out, with the reason for each. Most fail the inclusion rule on a single point: a sanctions designation that did not touch infrastructure, an indictment with no seizure beside it, a disruption carried out by someone other than a government authority. A handful are marked unresolved, meaning they probably do belong here and were not promoted because their primary sources were not opened in this pass.
This list is part of the record, not an appendix to it. A corpus that only shows what it included cannot be checked.
| Candidate | Date | Classification | Why it was left out |
|---|---|---|---|
| LockBit administration panel compromise | May 7, 2025 | Excluded | The compromise was carried out by an unknown actor, not by a law-enforcement or government-backed authority. Fails the government-action requirement. |
| OFAC designation of Integrity Technology Group | January 3, 2025 | Excluded | Sanctions-only action following the Raptor Train disruption. |
| OFAC and OFSI designations of Khoroshev, Sungatov, and Kondratyev | May 7, 2024 | Excluded | Sanctions-only. Recorded as person_actions of type sanctioned rather than as takedowns. |
| Mikhail Matveev US indictment | May 16, 2023 | Excluded | Indictment with no accompanying infrastructure seizure. Recorded as a person_action against td_2024_cronos_w1 rather than as its own takedown. |
| OFAC sanctions on Genesis Market | April 11, 2023 | Excluded | Sanctions-only action, separate from the domain seizure recorded as td_2023_genesis. |
| OFAC sanctions on Hydra Market and Garantex | April 5, 2022 | Excluded | Sanctions-only action. The designation itself did not seize, redirect, or disable internet infrastructure. The German server seizure on the same date is recorded separately as td_2022_hydra. |
| Sky Global chief executive US indictment | March 12, 2021 | Excluded | Indictment only. Not merged into td_2021_sky_ecc, which records the separate infrastructure and interception action. |
| 2019 Islamic State online-content referral action | November 25, 2019 | Excluded after reverification | Official source documents more than 26,000 content referrals to nine online service providers for terms-of-service review, not a government seizure, takeover, sinkhole or compelled infrastructure shutdown. It fails the dataset inclusion definition. |
| DNSChanger and Operation Ghost Click | November 8, 2011 | Unresolved | Strong verified-core candidate involving court-authorized replacement DNS servers. Not promoted in this pass because the primary sources were not opened and verified. |
| Coreflood botnet disruption | April 13, 2011 | Unresolved | Strong verified-core candidate involving a court-authorized stop command issued to infected machines. Not promoted in this pass for the same reason. |
| Microsoft civil botnet disruptions without law-enforcement participation, including Waledac, Rustock, and Necurs | No single date | Probable edge case | Purely private civil takedowns under US civil process with no material law-enforcement-controlled infrastructure action. Excluded per the stated scope. Rustock involved some law-enforcement support and is flagged as a probable edge case for reassessment. |
| National website-blocking orders against piracy sites | No single date | Excluded | Blocking orders that restrict access within a single jurisdiction without a broader infrastructure disruption are excluded by the stated scope. |
| Operation PowerOFF waves in 2019, 2023, and May 2025 | No single date | Unresolved | Identified as real waves belonging to um_operation_poweroff but not verified to incident standard in this pass. |