Skip to main content

Methodology

How internet takedowns work

A takedown is not one thing. The word covers at least six different mechanisms, and they differ in what they actually remove, how long the effect lasts, and what legal authority they need. Two actions described in the press with the same word can be doing completely different things.

The distinction matters for reading this index. A seized domain and a seized server are not comparable outcomes, and neither is comparable to a botnet that was redirected but left running. Where the public record establishes which mechanism was used, the entry says so in its own words rather than flattening everything into "taken down".

Mechanism Definition
Domain seizure A court orders the registry or registrar to transfer control of a domain name to the acting authority, which then points it at a seizure notice. The servers behind the name may keep running, and the service can reappear under a different name. Seizing a domain removes an address, not a system. Recorded here in Megaupload seizure.
Server seizure The physical or hosted machines running a service are taken, usually with a judicial order in the country where they sit. This ends the service as it was and hands investigators its stored data, which is often what makes later charges possible. Recorded here in Hydra Market server seizure.
Sinkholing Rather than removing the command infrastructure, investigators take over the addresses infected machines call home to and redirect them to servers under their control. The botnet keeps running, but it is talking to law enforcement. Sinkholing also measures the infection, which is how published victim counts are produced. Recorded here in Operation Tovar.
Covert takeover Investigators take control of a running service and keep operating it, without telling its users, so that activity and identities can be collected before it is closed. The public announcement comes at the end, so the recorded action date and the date control actually changed are usually not the same. Recorded here in Hansa covert takeover and shutdown.
Controlled platform A step beyond takeover: the service is run by or for law enforcement from the start, so everything on it is collected. This raises evidentiary and jurisdictional questions that the authorities involved generally answer through a third country's legal process. Recorded here in Operation Trojan Shield.
Remote remediation With court authorisation, investigators send a command to already infected machines to stop the malware or remove it. It is the most invasive mechanism recorded here, because the instruction reaches computers belonging to victims who are not party to the case. Recorded here in Operation Ladybird.

Why several appear in one action

Large operations rarely use a single mechanism. A campaign against a botnet may seize the command servers, sinkhole the domains that reach them, and deliver a removal instruction to infected machines, all under different court orders in different countries on the same day. The entry records what the sources establish about each part, and the ones they do not establish are left unrecorded rather than inferred from the others.

What none of them settle

No mechanism here guarantees that a service stays gone, and this index does not treat any of them as if it did. Where a service or a group is documented operating again afterwards, that is recorded against the original entry and graded on its own evidence. The classification labels explain that grading, and what the record shows about return rates sets out what the aggregate evidence does and does not support.