{"table":"takedowns","columns":["reference_id","slug","record_kind","name","aliases","started_on","ended_on","announced_on","activity_type","secondary_activity_types","target_name","target_type","summary","technical_outcome","later_status","legal_mechanism","geographic_scope","reported_charged_count","reported_apprehended_count","reported_convicted_count","reported_fugitive_count","estimated_group_size_min","estimated_group_size_max","group_size_basis","group_completeness","completeness_basis","resurgence_class","confidence","notes","parent_reference_id","parent_slug"],"row_count":108,"research_cutoff_on":"2026-08-21","generated_on":"2026-08-21","terms":"Free to reuse with attribution to the Internet Takedown Index. A research aggregation of public reporting, not a legal reference.","rows":[{"reference_id":"td_2013_silk_road","slug":"silk-road-seizure","record_kind":"incident","name":"Silk Road seizure","aliases":["Silk Road takedown"],"started_on":"2013-10-01","ended_on":"2013-10-02","announced_on":"2013-10-02","activity_type":"darknet_market","secondary_activity_types":["fraud_stolen_data","crypto_laundering"],"target_name":"Silk Road","target_type":"tor_hidden_service_marketplace","summary":"FBI seized the Silk Road Tor hidden service and its supporting servers, replacing the site with a seizure notice, and arrested founder Ross Ulbricht in San Francisco.","technical_outcome":"Hidden service and servers seized; site replaced with seizure banner; approximately 173,991 BTC ultimately seized across 2013 and later actions.","later_status":"Ulbricht convicted 2015 and sentenced to life without parole; pardoned by President Trump 2025-01-21.","legal_mechanism":"US seizure and arrest warrants, Southern District of New York","geographic_scope":["US","IS"],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":1,"estimated_group_size_max":6,"group_size_basis":"Single founder-administrator plus a small paid staff of moderators and support personnel described in SDNY charging documents; several staff were separately prosecuted.","group_completeness":"likely_complete","completeness_basis":"The single controlling administrator was arrested, convicted, and sentenced, and several staff members were separately charged. No official source states that the complete staff roster was accounted for.","resurgence_class":"C","confidence":"high","notes":["The 2025 presidential pardon is a later outcome and does not alter the 2013 infrastructure action.","Bitcoin seizure figures differ across the 2013 action and the November 2020 forfeiture; both are recorded rather than harmonized."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2014_operation_onymous","slug":"operation-onymous","record_kind":"incident","name":"Operation Onymous","aliases":["Silk Road 2.0 seizure"],"started_on":"2014-11-05","ended_on":"2014-11-07","announced_on":"2014-11-07","activity_type":"darknet_market","secondary_activity_types":["criminal_hosting_proxy"],"target_name":"Silk Road 2.0 and additional Tor marketplaces","target_type":"tor_hidden_service_marketplaces","summary":"Coordinated multinational action seizing Silk Road 2.0 and dozens of additional dark-web marketplaces and hidden services.","technical_outcome":"Silk Road 2.0 hidden service seized; dozens of additional onion services seized or disabled; servers seized across multiple countries.","later_status":"Blake Benthall prosecuted in SDNY.","legal_mechanism":"US seizure warrants (SDNY) plus parallel European judicial process coordinated via Europol EC3 and Eurojust","geographic_scope":["US","EU","GB","DE","NL","FR"],"reported_charged_count":null,"reported_apprehended_count":17,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Multiple independent marketplaces were targeted; no single finite operator group applies to the campaign as a whole.","group_completeness":"partial","completeness_basis":"Arrests were made across several sites, but operator rosters for most seized services were never published.","resurgence_class":"E","confidence":"high","notes":["Arrest count of 17 is an official aggregate reported at the time and is not reconciled with the single publicly named defendant record.","The method used to locate the hidden services was never disclosed and remains disputed."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2017_alphabay","slug":"alphabay-seizure","record_kind":"incident","name":"AlphaBay seizure","aliases":["Operation Bayonet (AlphaBay component)"],"started_on":"2017-07-04","ended_on":"2017-07-05","announced_on":"2017-07-20","activity_type":"darknet_market","secondary_activity_types":["fraud_stolen_data","crypto_laundering"],"target_name":"AlphaBay","target_type":"tor_hidden_service_marketplace","summary":"FBI-led seizure of AlphaBay, then the largest darknet marketplace, with simultaneous arrest of founder Alexandre Cazes in Bangkok by Royal Thai Police.","technical_outcome":"Marketplace servers and hidden service seized; site taken offline; assets and cryptocurrency frozen in multiple jurisdictions.","later_status":"Cazes died in Thai custody days after arrest; forfeiture proceedings continued.","legal_mechanism":"US seizure and arrest warrants (Eastern District of California) plus Thai judicial cooperation and Canadian asset action","geographic_scope":["US","TH","CA","LT","NL"],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":0,"reported_fugitive_count":null,"estimated_group_size_min":1,"estimated_group_size_max":5,"group_size_basis":"Single founder-administrator with a small moderator and security staff; only the founder was publicly charged in the 2017 action.","group_completeness":"likely_complete","completeness_basis":"The sole controlling administrator was arrested and the infrastructure seized. Subordinate staff were not comprehensively charged, so absolute certainty is not available.","resurgence_class":"E","confidence":"high","notes":["AlphaBay scale figures reported at announcement: over 200,000 users, roughly 40,000 vendors, roughly 250,000 listings.","A later service using the AlphaBay brand appeared in 2021 under an alleged former staff member; recorded as a resurgence, not as continuity of this operator."],"parent_reference_id":"um_operation_bayonet","parent_slug":"operation-bayonet"},{"reference_id":"td_2017_hansa","slug":"hansa-covert-takeover-and-shutdown","record_kind":"incident","name":"Hansa covert takeover and shutdown","aliases":["Operation Bayonet (Hansa component)"],"started_on":"2017-06-20","ended_on":"2017-07-20","announced_on":"2017-07-20","activity_type":"darknet_market","secondary_activity_types":["fraud_stolen_data"],"target_name":"Hansa Market","target_type":"tor_hidden_service_marketplace","summary":"Dutch National Police covertly assumed control of Hansa Market under Dutch judicial authorization and operated it for approximately one month to collect intelligence on vendors and buyers before shutting it down.","technical_outcome":"Full covert takeover of the marketplace; servers seized in the Netherlands, Germany, and Lithuania; user credentials and transaction data collected; site replaced with seizure notice.","later_status":"Two German administrators prosecuted in Germany; follow-on vendor arrests in multiple countries.","legal_mechanism":"Dutch judicial authorization for covert continuation of a criminal service; German arrest warrants","geographic_scope":["NL","DE","LT","EU"],"reported_charged_count":null,"reported_apprehended_count":2,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":2,"estimated_group_size_max":3,"group_size_basis":"Two German-national administrators publicly described as running the market.","group_completeness":"likely_complete","completeness_basis":"Both publicly described administrators were arrested in Germany and the infrastructure was under police control. Names were not released by Dutch or German authorities.","resurgence_class":"F","confidence":"high","notes":["This is one of the clearest documented cases of covert law-enforcement operation of a seized criminal service.","Administrators were not publicly named, so no person records were created despite an official apprehension count of two."],"parent_reference_id":"um_operation_bayonet","parent_slug":"operation-bayonet"},{"reference_id":"td_2022_hydra","slug":"hydra-market-server-seizure","record_kind":"incident","name":"Hydra Market server seizure","aliases":["Hydra Market takedown"],"started_on":"2022-04-05","ended_on":"2022-04-05","announced_on":"2022-04-05","activity_type":"darknet_market","secondary_activity_types":["crypto_laundering","fraud_stolen_data"],"target_name":"Hydra Market","target_type":"tor_hidden_service_marketplace","summary":"German Federal Criminal Police Office and the Frankfurt General Prosecutor's Office cybercrime unit seized the German-hosted server infrastructure of Hydra Market, the largest Russian-language darknet marketplace, together with cryptocurrency held on the platform.","technical_outcome":"Server infrastructure in Germany seized; approximately 543.3 BTC seized in 88 transactions; marketplace taken offline.","later_status":"No arrests on the action date. Dmitry Olegovich Pavlov charged in the US and remains at large.","legal_mechanism":"German judicial seizure orders; parallel US indictment (Northern District of California)","geographic_scope":["DE","US","RU"],"reported_charged_count":1,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":1,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Core operator group never publicly enumerated. Platform had roughly 17 million customer accounts and more than 19,000 seller accounts, which are separate populations.","group_completeness":"partial","completeness_basis":"One alleged server administrator was charged in the US and remains a fugitive. German authorities explicitly confirmed no arrests were made on the action date. The controlling operator group was never identified publicly.","resurgence_class":"E","confidence":"high","notes":["OFAC sanctioned Hydra and the exchange Garantex on the same date. Sanctions are recorded as a separate action and are not treated as part of the infrastructure seizure or as criminal charges.","Apprehended count of 0 is explicitly established by German authorities and is therefore recorded as 0 rather than null.","Estimated lifetime volume of approximately 5.2 billion USD and roughly 80 percent of 2021 darknet-market cryptocurrency volume are analyst estimates, not official figures."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_archetyp","slug":"operation-deep-sentinel","record_kind":"incident","name":"Operation Deep Sentinel","aliases":["Archetyp Market takedown"],"started_on":"2025-06-11","ended_on":"2025-06-13","announced_on":"2025-06-16","activity_type":"darknet_market","secondary_activity_types":[],"target_name":"Archetyp Market","target_type":"tor_hidden_service_marketplace","summary":"German-led multinational operation seizing the Monero-only Archetyp drug marketplace, with the administrator arrested in Spain and vendors and a moderator arrested in Germany and Sweden.","technical_outcome":"Server infrastructure seized by Dutch police; marketplace taken offline and replaced with seizure notice; approximately 7.8 million EUR in assets seized.","later_status":"Prosecutions ongoing in Germany and Spain as of the cutoff.","legal_mechanism":"German judicial orders, European Arrest Warrant, Dutch and Spanish judicial cooperation, Eurojust coordination","geographic_scope":["DE","ES","NL","SE","RO","US","EU"],"reported_charged_count":null,"reported_apprehended_count":8,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":2,"estimated_group_size_max":null,"group_size_basis":"One administrator and one moderator publicly described as the core operating group; six additional arrests were top vendors, a separate population.","group_completeness":"likely_complete","completeness_basis":"The administrator and a moderator were arrested and infrastructure seized. Digital forensics were described as ongoing, so the full core roster is not confirmed closed.","resurgence_class":"F","confidence":"high","notes":["Suspects were not publicly named, so no person records were created despite an official apprehension count of eight.","Do not conflate the six arrested vendors with core operators. They are recorded as a separate group segment in commentary only.","Platform scale at takedown: more than 600,000 users, roughly 3,200 vendors, more than 17,000 listings, more than 250 million EUR in turnover."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_raidforums","slug":"operation-tourniquet","record_kind":"incident","name":"Operation Tourniquet","aliases":["RaidForums seizure"],"started_on":"2022-04-12","ended_on":"2022-04-12","announced_on":"2022-04-12","activity_type":"fraud_stolen_data","secondary_activity_types":["phishing"],"target_name":"RaidForums","target_type":"clearnet_criminal_forum","summary":"US-led seizure of the RaidForums domains, a major English-language marketplace for stolen databases, coordinated with European partners under Europol.","technical_outcome":"Domains raidforums.com, rf.ws, and raid.lol seized and redirected to a seizure notice; forum infrastructure taken offline.","later_status":"Founder arrested in the UK in January 2022; extradition proceedings to the US.","legal_mechanism":"US seizure warrant (Eastern District of Virginia); UK arrest at US request; Europol coordination","geographic_scope":["US","GB","PT","SE","RO","EU"],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":1,"estimated_group_size_max":null,"group_size_basis":"One founder-administrator publicly charged; co-administrators and staff not comprehensively named.","group_completeness":"partial","completeness_basis":"The founder was arrested and charged, but the forum's wider administrative staff was not publicly accounted for, and a successor forum appeared within weeks.","resurgence_class":"C","confidence":"high","notes":["Forum hosted more than 10 billion records across roughly 530,000 registered users, which is a user population and not an operator count.","Arrest occurred 2022-01-31, more than two months before the domain seizure. Dates are kept distinct."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_genesis","slug":"operation-cookie-monster","record_kind":"incident","name":"Operation Cookie Monster","aliases":["Genesis Market takedown"],"started_on":"2023-04-04","ended_on":"2023-04-05","announced_on":"2023-04-05","activity_type":"fraud_stolen_data","secondary_activity_types":["phishing","botnet_malware"],"target_name":"Genesis Market","target_type":"criminal_marketplace","summary":"FBI and Dutch National Police led a 17-country action seizing the clearnet domains and infrastructure of Genesis Market, which sold stolen credentials packaged with browser fingerprints and cookies.","technical_outcome":"Eleven domains seized under a US warrant; US-based servers seized; marketplace clearnet access replaced with seizure notice.","later_status":"Follow-on arrests continued in multiple countries after the action date.","legal_mechanism":"US seizure warrant (Eastern District of Wisconsin); parallel Dutch and partner judicial process; Europol and Eurojust coordination","geographic_scope":["US","NL","GB","EU"],"reported_charged_count":null,"reported_apprehended_count":119,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Core administrators were never publicly identified. The 119 arrests were predominantly users and customers.","group_completeness":"partial","completeness_basis":"Infrastructure was seized and a large number of users arrested, but no core administrator was publicly identified, charged, or apprehended.","resurgence_class":"G","confidence":"high","notes":["119 arrests and 208 property searches are official aggregate figures across 13 countries and are not converted into person records.","Approximately 1.5 million compromised devices and 80 million credentials are victim-side figures, not operator counts.","Reporting indicates the Tor mirror was not immediately affected by the clearnet seizure. Recorded as a partial technical outcome.","OFAC sanctioned Genesis Market separately. Sanctions are not treated as charges."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_breachforums","slug":"breachforums-shutdown-following-administrator-arrest","record_kind":"incident","name":"BreachForums shutdown following administrator arrest","aliases":[],"started_on":"2023-03-21","ended_on":"2023-03-29","announced_on":"2023-03-24","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"BreachForums","target_type":"clearnet_criminal_forum","summary":"FBI arrested BreachForums administrator Conor Brian Fitzpatrick; the forum was shut down shortly afterward amid indications that law enforcement had access to backend infrastructure.","technical_outcome":"Forum taken offline by a remaining staff member citing law-enforcement access to infrastructure; administrator's devices and accounts seized.","later_status":"Fitzpatrick pleaded guilty and was sentenced; sentence later revisited on appeal.","legal_mechanism":"US arrest warrant and criminal complaint (Eastern District of Virginia)","geographic_scope":["US"],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":2,"estimated_group_size_max":null,"group_size_basis":"Administrator plus at least one co-administrator who continued operating the brand.","group_completeness":"partial","completeness_basis":"Only the lead administrator was apprehended. Co-administrators immediately reconstituted the forum, demonstrating that the core group was not accounted for.","resurgence_class":"A","confidence":"medium","notes":["This record is a probable edge case for the infrastructure test. The arrest is well documented; the extent of direct law-enforcement control over forum infrastructure at this stage rests substantially on a staff member's public statement rather than an official seizure notice.","The clearly documented infrastructure seizures of this brand are the 2024 and 2025 actions, recorded separately."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_breachforums","slug":"breachforums-domain-seizure","record_kind":"incident","name":"BreachForums domain seizure","aliases":[],"started_on":"2024-05-15","ended_on":"2024-05-15","announced_on":"2024-05-15","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"BreachForums (reconstituted)","target_type":"clearnet_criminal_forum","summary":"FBI seized the BreachForums clearnet domain and associated Telegram channels, replacing the site with a seizure banner.","technical_outcome":"Clearnet domain seized and redirected to a seizure notice; associated Telegram infrastructure disrupted. Operators briefly regained the domain via registrar transfer credentials before losing it again.","later_status":"Forum reconstituted on alternative infrastructure and was seized again in 2025.","legal_mechanism":"US seizure warrant with international partner support","geographic_scope":["US","GB","EU"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":2,"estimated_group_size_max":null,"group_size_basis":"Administrators operating under the handles ShinyHunters and Baphomet, plus associated staff.","group_completeness":"remaining_members","completeness_basis":"No arrests were announced with this action and the operators publicly resumed activity, explicitly demonstrating remaining active members.","resurgence_class":"B","confidence":"medium","notes":["The temporary recovery of the domain by operators using registrar credentials is a documented and unusual reversal of a seizure and is preserved rather than smoothed over."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_breachforums","slug":"breachforums-portal-seizure-2025","record_kind":"incident","name":"BreachForums portal seizure (2025)","aliases":[],"started_on":"2025-10-10","ended_on":"2025-10-10","announced_on":"2025-10-10","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"BreachForums (further reconstituted)","target_type":"clearnet_criminal_forum","summary":"Law enforcement again seized BreachForums infrastructure, which had been used to host extortion pressure pages including a Salesforce-related campaign.","technical_outcome":"Portal infrastructure seized and replaced with a law-enforcement notice.","later_status":"Under investigation as of the cutoff.","legal_mechanism":"FBI/DOJ domain seizure with French BL2C and Paris prosecutor/JUNALCO participation; no operation-specific official press release located.","geographic_scope":["US","FR"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not publicly enumerated.","group_completeness":"unknown","completeness_basis":"Neither the operator roster nor the disposition of its members is established in the public record for this action.","resurgence_class":"G","confidence":"medium","notes":["Retained in the corpus because the seizure banner and multiple specialist reports are consistent, but it should be treated as provisional."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2014_gameover_zeus","slug":"operation-tovar","record_kind":"incident","name":"Operation Tovar","aliases":["Gameover Zeus disruption","CryptoLocker disruption"],"started_on":"2014-05-30","ended_on":"2014-06-02","announced_on":"2014-06-02","activity_type":"botnet_malware","secondary_activity_types":["ransomware","fraud_stolen_data"],"target_name":"Gameover Zeus botnet and CryptoLocker ransomware","target_type":"peer_to_peer_botnet","summary":"Multinational operation that redirected and sinkholed the Gameover Zeus peer-to-peer and domain-generation infrastructure, simultaneously disrupting the CryptoLocker ransomware distribution channel.","technical_outcome":"Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.","later_status":"Evgeniy Bogachev indicted and remains at large in Russia with a 3 million USD State Department reward.","legal_mechanism":"US civil and criminal court orders (Western District of Pennsylvania) authorizing redirection and sinkholing; parallel foreign judicial process","geographic_scope":["US","GB","NL","DE","UA","EU"],"reported_charged_count":1,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":1,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Bogachev was described as leading a tightly knit criminal group whose membership was never fully enumerated publicly.","group_completeness":"partial","completeness_basis":"The named leader was charged but never apprehended; the wider group was never publicly identified or accounted for.","resurgence_class":"B","confidence":"high","notes":["Approximately 500,000 to 1 million infected machines and more than 100 million USD in losses are official estimates.","A Gameover Zeus variant reappeared within weeks of the disruption, recorded as a Class B resurgence."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2016_avalanche","slug":"avalanche-network-takedown","record_kind":"incident","name":"Avalanche network takedown","aliases":[],"started_on":"2016-11-30","ended_on":"2016-11-30","announced_on":"2016-12-01","activity_type":"criminal_hosting_proxy","secondary_activity_types":["botnet_malware","ransomware","fraud_stolen_data"],"target_name":"Avalanche","target_type":"bulletproof_fast_flux_infrastructure","summary":"German-led international operation dismantling the Avalanche double fast-flux network, which provided delivery and command-and-control infrastructure for at least 17 malware families.","technical_outcome":"More than 800,000 domains seized, sinkholed, or blocked; 39 servers seized; 37 premises searched.","later_status":"Sinkhole operation maintained by Shadowserver for years afterward for victim notification.","legal_mechanism":"German judicial orders (Verden Public Prosecutor's Office); coordinated domain actions with registries and registrars across many TLDs; Europol and Eurojust coordination","geographic_scope":["DE","US","CA","EU","UA"],"reported_charged_count":null,"reported_apprehended_count":5,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Operator group behind the hosting infrastructure was never publicly enumerated; the platform served many unrelated criminal customers.","group_completeness":"partial","completeness_basis":"Five arrests were officially reported but no core operator roster was published, and the service supported numerous independent criminal groups that were unaffected.","resurgence_class":"F","confidence":"high","notes":["Official figures: more than 800,000 domains seized, sinkholed, or blocked; five arrests; 37 premises searched; 39 servers seized.","Roughly 500,000 infected devices per day is a victim-side figure and not an operator count.","Domain quantity is recorded as an aggregate infrastructure item because individual domains were not published."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_emotet","slug":"operation-ladybird","record_kind":"incident","name":"Operation Ladybird","aliases":["Emotet takedown"],"started_on":"2021-01-26","ended_on":"2021-01-27","announced_on":"2021-01-27","activity_type":"botnet_malware","secondary_activity_types":["ransomware"],"target_name":"Emotet","target_type":"modular_botnet_loader","summary":"Europol- and Eurojust-coordinated operation in which national authorities took control of Emotet's command-and-control infrastructure from the inside and redirected infected machines to law-enforcement-controlled servers.","technical_outcome":"Roughly 700 command-and-control servers taken over; infected machines redirected to law-enforcement infrastructure; a court-authorized uninstall module was delivered and triggered on 2021-04-25.","later_status":"Emotet returned in November 2021 on new infrastructure.","legal_mechanism":"Judicial authorization across participating states including Dutch and German court process; US court authorization for the uninstall payload; EMPACT framework","geographic_scope":["NL","DE","US","GB","FR","LT","CA","UA","EU"],"reported_charged_count":null,"reported_apprehended_count":2,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Core group commonly tracked as a distinct crew but never publicly enumerated by authorities.","group_completeness":"partial","completeness_basis":"Two individuals were detained in Ukraine, but the malware returned within ten months, demonstrating that core operators remained active.","resurgence_class":"B","confidence":"high","notes":["Approximately 1.6 million infected machines is a victim-side figure.","The delayed uninstall on 2021-04-25 is recorded as part of this incident rather than as a separate takedown because it operated on infrastructure already under law-enforcement control.","The November 2021 return is recorded as a resurgence."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_qakbot","slug":"operation-duck-hunt","record_kind":"incident","name":"Operation Duck Hunt","aliases":["Qakbot takedown","Qbot disruption"],"started_on":"2023-08-25","ended_on":"2023-08-25","announced_on":"2023-08-29","activity_type":"botnet_malware","secondary_activity_types":["ransomware"],"target_name":"Qakbot","target_type":"modular_botnet_loader","summary":"FBI-led operation that redirected Qakbot botnet traffic to FBI-controlled servers and delivered a court-authorized uninstaller to hundreds of thousands of infected computers.","technical_outcome":"Botnet traffic redirected to FBI infrastructure; uninstaller delivered to approximately 700,000 infected computers; 52 servers seized; approximately 8.6 million USD in cryptocurrency seized.","later_status":"No arrests at the time. Alleged administrator Rustam Rafailevich Gallyamov was charged in 2025 in connection with Operation Endgame.","legal_mechanism":"US search and seizure warrants including Rule 41 authorization (Central District of California)","geographic_scope":["US","FR","DE","NL","GB","RO","LV"],"reported_charged_count":0,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Core group not publicly enumerated at the time of the action.","group_completeness":"partial","completeness_basis":"DOJ explicitly stated no arrests accompanied the action. The administrator was identified and charged only two years later, and the malware ecosystem resurfaced in the interim.","resurgence_class":"C","confidence":"high","notes":["Charged and apprehended counts of 0 for this action are explicitly established by DOJ and are recorded as 0 rather than null.","Gallyamov's 2025 charge is recorded against the Operation Endgame wave 2 incident, not retroactively against this one."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_911_s5","slug":"911-s5-botnet-dismantlement","record_kind":"incident","name":"911 S5 botnet dismantlement","aliases":[],"started_on":"2024-05-24","ended_on":"2024-05-29","announced_on":"2024-05-29","activity_type":"botnet_malware","secondary_activity_types":["criminal_hosting_proxy","fraud_stolen_data"],"target_name":"911 S5","target_type":"residential_proxy_botnet","summary":"US-led international operation dismantling the 911 S5 residential proxy botnet, described by the FBI Director as likely the world's largest botnet, with the administrator arrested in Singapore.","technical_outcome":"23 domains and more than 70 servers seized; botnet infrastructure dismantled; approximately 30 million USD in assets seized or restrained.","later_status":"YunHe Wang arrested and prosecuted; OFAC sanctioned Wang, associates, and three Thai entities separately.","legal_mechanism":"US seizure warrants and criminal charges; Singapore, Thai, and German judicial cooperation","geographic_scope":["US","SG","TH","DE"],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":1,"estimated_group_size_max":4,"group_size_basis":"One principal administrator charged; several associates named in the parallel sanctions action rather than in criminal charges.","group_completeness":"likely_complete","completeness_basis":"The principal administrator was arrested and the infrastructure dismantled. Associates were designated under sanctions rather than criminally charged, so the criminal roster is not formally closed.","resurgence_class":"G","confidence":"high","notes":["Official figure: more than 19 million unique IP addresses compromised, including 613,841 in the United States.","Linked to approximately 5.9 billion USD in pandemic-relief fraud losses, a victim-side figure.","Sanctions designations are recorded separately and are not counted as criminal charges."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_endgame_w1","slug":"operation-endgame-wave-1","record_kind":"incident","name":"Operation Endgame wave 1","aliases":["Operation Endgame 1.0"],"started_on":"2024-05-27","ended_on":"2024-05-29","announced_on":"2024-05-30","activity_type":"multi_threat_campaign","secondary_activity_types":["botnet_malware","ransomware"],"target_name":"IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, Trickbot","target_type":"malware_dropper_ecosystem","summary":"Coordinated action led by France, Germany, and the Netherlands against the dropper and loader ecosystem that feeds ransomware deployment, disrupting infrastructure for six malware families simultaneously.","technical_outcome":"More than 100 servers disrupted or taken down; more than 2,000 domains brought under law-enforcement control; 16 location searches.","later_status":"Followed by wave 2 in May 2025 and wave 3 in November 2025; suspects added to the EU Most Wanted list.","legal_mechanism":"National judicial orders in France, Germany, and the Netherlands; European Arrest Warrants; Europol and Eurojust coordination","geographic_scope":["FR","DE","NL","DK","GB","US","UA","AM","PT","BG","LT"],"reported_charged_count":8,"reported_apprehended_count":4,"reported_convicted_count":null,"reported_fugitive_count":8,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Multiple independent malware crews were targeted; a single finite operator group is not a meaningful denominator for the wave as a whole.","group_completeness":"remaining_members","completeness_basis":"German authorities explicitly published a wanted list of suspects who remained at large after the action, establishing remaining members by official statement.","resurgence_class":"B","confidence":"high","notes":["One main suspect was alleged to have earned at least 69 million EUR in cryptocurrency.","Arrests: one in Armenia and three in Ukraine, not publicly named in the announcement.","Charged count reflects suspects publicly listed as wanted or charged by German authorities; the figure is contested across reporting and is not harmonized here."],"parent_reference_id":"um_operation_endgame","parent_slug":"operation-endgame"},{"reference_id":"td_2025_endgame_w2","slug":"operation-endgame-wave-2","record_kind":"incident","name":"Operation Endgame wave 2","aliases":["Operation Endgame 2.0"],"started_on":"2025-05-19","ended_on":"2025-05-22","announced_on":"2025-05-23","activity_type":"multi_threat_campaign","secondary_activity_types":["botnet_malware","ransomware","fraud_stolen_data"],"target_name":"DanaBot, Bumblebee, Lactrodectus, Qakbot, HijackLoader, Trickbot, Warmcookie","target_type":"malware_dropper_ecosystem","summary":"Second Endgame wave targeting initial-access malware and loaders, combining infrastructure seizure with a large set of criminal charges including the DanaBot indictment and the Qakbot administrator.","technical_outcome":"Approximately 300 servers disrupted worldwide; roughly 650 domains neutralized; approximately 3.5 million EUR in cryptocurrency seized during the wave.","later_status":"Prosecutions ongoing; cumulative Endgame cryptocurrency seizures reported at approximately 21.2 million EUR.","legal_mechanism":"National judicial orders across participating states; US indictments (Central District of California and others); Europol and Eurojust coordination","geographic_scope":["DE","NL","FR","DK","GB","US","CA"],"reported_charged_count":20,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Multiple distinct malware crews targeted in one wave.","group_completeness":"remaining_members","completeness_basis":"Authorities announced international targets who remained at large, and the DanaBot defendants were largely charged in absentia.","resurgence_class":"G","confidence":"high","notes":["The DanaBot indictment names 16 defendants, most believed to be in Russia. Only Gallyamov is carried as a named person record in this pass; the remaining DanaBot defendants are a documented gap.","Reported charged count of 20 is an official aggregate and is not equal to the number of named person records."],"parent_reference_id":"um_operation_endgame","parent_slug":"operation-endgame"},{"reference_id":"td_2025_endgame_w3","slug":"operation-endgame-wave-3","record_kind":"incident","name":"Operation Endgame wave 3","aliases":["Operation Endgame 3.0"],"started_on":"2025-11-10","ended_on":"2025-11-13","announced_on":"2025-11-13","activity_type":"multi_threat_campaign","secondary_activity_types":["botnet_malware","fraud_stolen_data"],"target_name":"Rhadamanthys, VenomRAT, Elysium botnet","target_type":"infostealer_and_rat_infrastructure","summary":"Third Endgame wave targeting infostealer and remote-access-trojan infrastructure, with a principal VenomRAT suspect arrested in Greece.","technical_outcome":"1,025 servers taken down or disrupted; 20 domains seized; one VenomRAT suspect arrested in Greece on 2025-11-03.","later_status":"Prosecutions ongoing as of the cutoff.","legal_mechanism":"National judicial orders; European Arrest Warrant; Europol and Eurojust coordination","geographic_scope":["DE","NL","FR","GR","GB","US","EU"],"reported_charged_count":null,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Multiple distinct malware operations targeted.","group_completeness":"partial","completeness_basis":"One principal suspect was arrested; the Rhadamanthys and Elysium operator groups were not publicly accounted for.","resurgence_class":"G","confidence":"medium","notes":["VenomRAT suspect arrested in Greece on 2025-11-03, before the main action window."],"parent_reference_id":"um_operation_endgame","parent_slug":"operation-endgame"},{"reference_id":"td_2025_lumma","slug":"lumma-stealer-disruption","record_kind":"incident","name":"Lumma Stealer disruption","aliases":["LummaC2 takedown"],"started_on":"2025-05-13","ended_on":"2025-05-21","announced_on":"2025-05-21","activity_type":"botnet_malware","secondary_activity_types":["fraud_stolen_data"],"target_name":"Lumma Stealer","target_type":"malware_as_a_service_infostealer","summary":"Hybrid civil and criminal action in which Microsoft's Digital Crimes Unit obtained a US court order to seize Lumma command domains while DOJ seized the central command structure and Europol and Japanese partners suspended locally based infrastructure.","technical_outcome":"Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.","later_status":"Operation rebounded within days on new infrastructure; developer remains at large.","legal_mechanism":"US civil court order (Northern District of Georgia) plus DOJ criminal seizure process; Europol EC3 and Japan JC3 coordination","geographic_scope":["US","JP","EU"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Principal developer known publicly only by the alias Shamel and believed to be in Russia.","group_completeness":"partial","completeness_basis":"No arrests or charges accompanied the action, the developer was not apprehended, and the service resumed operating within days.","resurgence_class":"B","confidence":"high","notes":["Microsoft reported identifying more than 394,000 infected Windows computers globally between 2025-03-16 and 2025-05-16.","PROBABLE EDGE CASE on the private-action exclusion. Included because DOJ seized infrastructure under criminal process alongside the civil order; a purely civil Microsoft action would have been excluded."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_netwalker","slug":"netwalker-ransomware-disruption","record_kind":"incident","name":"NetWalker ransomware disruption","aliases":[],"started_on":"2021-01-27","ended_on":"2021-01-27","announced_on":"2021-01-27","activity_type":"ransomware","secondary_activity_types":[],"target_name":"NetWalker","target_type":"ransomware_as_a_service","summary":"US and Bulgarian authorities disabled the NetWalker dark-web resource used to communicate with victims, alongside charges against a prolific affiliate.","technical_outcome":"Dark-web victim communication and leak resources seized and taken offline; approximately 454,530 USD in cryptocurrency seized.","later_status":"Sebastien Vachon-Desjardins convicted and sentenced in Canada and later in the United States.","legal_mechanism":"US criminal complaint and seizure warrants (Middle District of Florida); Bulgarian judicial action","geographic_scope":["US","BG","CA"],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Core developers were never publicly identified; the charged individual was an affiliate rather than a core operator.","group_completeness":"partial","completeness_basis":"Only an affiliate was charged and convicted. The core developer group was never identified or apprehended.","resurgence_class":"G","confidence":"high","notes":["Vachon-Desjardins is recorded with group_segment affiliate, not core_operator. This distinction matters for the completeness assessment."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_hive","slug":"hive-ransomware-infiltration-and-seizure","record_kind":"incident","name":"Hive ransomware infiltration and seizure","aliases":[],"started_on":"2022-07-01","ended_on":"2023-01-26","announced_on":"2023-01-26","activity_type":"ransomware","secondary_activity_types":[],"target_name":"Hive","target_type":"ransomware_as_a_service","summary":"FBI covertly penetrated Hive's network in July 2022, captured decryption keys for roughly seven months, and then seized the group's servers and dark-web sites with German and Dutch partners.","technical_outcome":"Covert access to the Hive network for approximately seven months; more than 300 decryption keys provided to victims under active attack and more than 1,000 additional keys distributed to previous victims; leak site and payment site seized; servers seized in Germany and the Netherlands.","later_status":"No arrests announced with the action. Researchers subsequently linked Hunters International to the Hive codebase.","legal_mechanism":"US seizure warrants (Middle District of Florida); German and Dutch judicial process; Europol support","geographic_scope":["US","DE","NL","EU"],"reported_charged_count":0,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Core administrator group never publicly identified.","group_completeness":"partial","completeness_basis":"Infrastructure was seized and victims protected, but no operator was charged or arrested and a technically related operation appeared within months.","resurgence_class":"C","confidence":"high","notes":["DOJ reported preventing approximately 130 million USD in ransom demands.","Approximately 1,500 victims in more than 80 countries and roughly 100 million USD collected are official estimates.","The Hunters International relationship is DISPUTED. Multiple technical analyses found substantial code overlap, while the successor group publicly claimed it purchased the source code rather than being a rebrand. Both positions are preserved."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_cronos_w1","slug":"operation-cronos-wave-1","record_kind":"incident","name":"Operation Cronos wave 1","aliases":["LockBit takedown"],"started_on":"2024-02-19","ended_on":"2024-02-20","announced_on":"2024-02-20","activity_type":"ransomware","secondary_activity_types":["crypto_laundering"],"target_name":"LockBit","target_type":"ransomware_as_a_service","summary":"UK National Crime Agency-led international task force that infiltrated and seized LockBit's primary administration environment and leak site, then repurposed the leak site to publish information about the group.","technical_outcome":"34 servers seized across eight countries; source code and affiliate data obtained; more than 1,000 decryption keys recovered; more than 200 cryptocurrency wallets frozen; approximately 14,000 rogue accounts closed; leak site taken over and operated by law enforcement.","later_status":"LockBit relaunched after the February 2024 disruption. Mikhail Vasiliev and Ruslan Astamirov pleaded guilty on 2024-07-18 and were still awaiting sentencing in the latest located official update. Rostislav Panev was arrested in Israel in August 2024, extradited on 2025-03-13, and detained pending trial. Artur Sungatov, Ivan Kondratyev, Mikhail Matveev and Dmitry Khoroshev remained at large in the latest located official update.","legal_mechanism":"UK judicial process; US seizure warrants and indictments (District of New Jersey); Europol and Eurojust coordination; European Arrest Warrants","geographic_scope":["GB","US","FR","DE","CH","JP","AU","SE","CA","NL","FI","PL","UA"],"reported_charged_count":null,"reported_apprehended_count":2,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":3,"estimated_group_size_max":null,"group_size_basis":"A small core comprising the administrator LockBitSupp and at least one developer, surrounded by a large affiliate population that is a separate segment.","group_completeness":"remaining_members","completeness_basis":"The core administrator Khoroshev was identified and charged but remains at large in Russia, as do at least two charged affiliates. The service relaunched within days, explicitly demonstrating remaining members.","resurgence_class":"B","confidence":"high","notes":["Named person records span the February 2024 action and the connected May 2024 unsealing; the charging events are recorded with their own dates.","Two individuals were arrested in Poland and Ukraine on the action date but were not publicly named, so they do not appear as person records.","LockBit was reported to have extorted approximately 500 million USD from more than 2,500 victims.","Post-takedown LockBit leak-site activity is widely assessed as inflated with recycled victim claims. Recorded as a source disagreement."],"parent_reference_id":"um_operation_cronos","parent_slug":"operation-cronos"},{"reference_id":"td_2020_encrochat","slug":"encrochat-interception-and-shutdown","record_kind":"incident","name":"EncroChat interception and shutdown","aliases":["Operation Venetic","Operation Emma","Operation Lemont"],"started_on":"2020-04-01","ended_on":"2020-06-13","announced_on":"2020-07-02","activity_type":"criminal_communications","secondary_activity_types":["trafficking_exploitation"],"target_name":"EncroChat","target_type":"encrypted_communications_network","summary":"A French and Dutch joint investigation team placed a technical implant on EncroChat's France-hosted servers, harvesting messages from roughly 60,000 users before the network was shut down.","technical_outcome":"Server infrastructure in France compromised by a law-enforcement implant; more than 100 million messages intercepted; network shut down and users warned by the operator.","later_status":"Thousands of prosecutions across Europe. Several courts have since challenged or excluded EncroChat-derived evidence.","legal_mechanism":"French judicial authorization for the technical device; Joint Investigation Team with the Netherlands; European Investigation Orders; Europol and Eurojust coordination","geographic_scope":["FR","NL","GB","SE","NO","EU"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not applicable. The target was a communications service used by many unrelated criminal groups.","group_completeness":"not_applicable","completeness_basis":"The service is not a finite criminal operator group. Arrest totals reflect users of the platform, not its operators.","resurgence_class":"F","confidence":"high","notes":["UK NCA initially reported 746 arrests, later revised upward past 1,500 as cases progressed. Both figures are aggregate user arrests, not operator arrests.","CONFLICTING LEGAL RECORD. Courts in several jurisdictions have since ruled on the admissibility of the intercepted material with differing outcomes. This does not affect the fact of the infrastructure action."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_sky_ecc","slug":"sky-ecc-interception-and-action-day","record_kind":"incident","name":"Sky ECC interception and action day","aliases":["Operation Argus"],"started_on":"2021-02-01","ended_on":"2021-03-09","announced_on":"2021-03-10","activity_type":"criminal_communications","secondary_activity_types":["trafficking_exploitation"],"target_name":"Sky ECC","target_type":"encrypted_communications_network","summary":"Belgian, Dutch, and French authorities monitored Sky ECC communications and executed a coordinated action day, unlocking roughly a billion messages from approximately 70,000 users.","technical_outcome":"Encrypted traffic decrypted and monitored; infrastructure disrupted; large-scale searches and seizures on the action day.","later_status":"Extensive Belgian and Dutch prosecutions. Sky Global publicly disputed the characterization of the company.","legal_mechanism":"Belgian and Dutch judicial authorization; French cooperation; Europol and Eurojust coordination","geographic_scope":["BE","NL","FR","US","EU"],"reported_charged_count":null,"reported_apprehended_count":48,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not applicable for the same reasons as EncroChat.","group_completeness":"not_applicable","completeness_basis":"The target was a communications platform used by many unrelated criminal groups rather than a finite operator group.","resurgence_class":"F","confidence":"high","notes":["Reported 48 arrests on the Belgian action day and approximately 200 premises searched.","A separate US indictment against Sky Global's chief executive is a distinct legal action and is not merged into this infrastructure record.","Admissibility of Sky ECC evidence has been litigated with mixed outcomes."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_anom","slug":"operation-trojan-shield","record_kind":"incident","name":"Operation Trojan Shield","aliases":["Operation Ironside","Operation Greenlight","ANOM"],"started_on":"2018-10-01","ended_on":"2021-06-08","announced_on":"2021-06-08","activity_type":"criminal_communications","secondary_activity_types":["trafficking_exploitation"],"target_name":"ANOM","target_type":"encrypted_communications_network","summary":"The FBI and Australian Federal Police designed and covertly operated the ANOM encrypted device network for roughly three years, reading messages in real time before executing a global action week.","technical_outcome":"Law enforcement operated the platform itself from inception; more than 27 million messages collected from roughly 12,000 devices across more than 300 criminal syndicates; network shut down at the action week.","later_status":"Seventeen distributors were indicted in the Southern District of California. By 2025-02-07, all eight defendants extradited to the United States had pleaded guilty; eight additional defendants had been arrested abroad but not extradited, and one remained a fugitive. The broader operation produced approximately 1,200 arrests worldwide.","legal_mechanism":"US court authorization for interception via a third country; Australian legislation; European Investigation Orders; Europol and Eurojust coordination","geographic_scope":["US","AU","SE","NL","DE","FI","LT","NZ","EU"],"reported_charged_count":17,"reported_apprehended_count":1200,"reported_convicted_count":8,"reported_fugitive_count":1,"estimated_group_size_min":17,"estimated_group_size_max":17,"group_size_basis":"The relevant criminal enterprise for this record is the ANOM distribution network, charged as 17 defendants in a single San Diego indictment.","group_completeness":"likely_complete","completeness_basis":"The distribution enterprise was charged as a defined group of 17 and the platform itself was law-enforcement-operated. Not all defendants were apprehended, so absolute completeness is not claimed.","resurgence_class":"F","confidence":"high","notes":["The 800-plus arrests figure is an aggregate of platform users arrested worldwide and must never be added to the 17 named distribution defendants.","Only one defendant is carried as a named person record in this pass. The remaining 16 San Diego defendants are a documented named-person gap.","This is the clearest case in the corpus of law enforcement operating a criminal service from inception rather than seizing an existing one."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2019_welcome_to_video","slug":"welcome-to-video-seizure","record_kind":"incident","name":"Welcome to Video seizure","aliases":[],"started_on":"2018-03-05","ended_on":"2018-03-05","announced_on":"2019-10-16","activity_type":"csam","secondary_activity_types":["crypto_laundering"],"target_name":"Welcome to Video","target_type":"tor_hidden_service","summary":"IRS Criminal Investigation, Homeland Security Investigations, the UK National Crime Agency, and Korean National Police seized the server operating the Welcome to Video darknet site and arrested its operator in South Korea, with Bitcoin tracing identifying hundreds of users worldwide.","technical_outcome":"Server seized in South Korea and site taken offline; approximately eight terabytes of material and roughly 250,000 videos secured; Bitcoin transaction analysis used to identify users.","later_status":"Operator convicted in South Korea and separately indicted in the District of Columbia; 337 users arrested and charged across at least 12 countries; 23 children identified and rescued.","legal_mechanism":"Korean judicial process for the server seizure; US indictment and forfeiture (District of Columbia); mutual legal assistance","geographic_scope":["KR","US","GB","DE","SA","AE","CZ","CA","IE","ES"],"reported_charged_count":337,"reported_apprehended_count":337,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":1,"estimated_group_size_max":1,"group_size_basis":"A single operator ran the site, per US and Korean charging documents.","group_completeness":"likely_complete","completeness_basis":"The sole identified operator was arrested, convicted in South Korea, and separately indicted in the United States, and the server was seized. No official statement closes the roster absolutely.","resurgence_class":"F","confidence":"high","notes":["The 337 arrested users are a customer population and are strictly separate from the single core operator.","The action date of 2018-03-05 and the announcement date of 2019-10-16 are more than 19 months apart and are deliberately kept distinct.","Only the operator is carried as a named person record; individually prosecuted users are a deliberate named-person gap."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2018_webstresser","slug":"webstresser-org-takedown","record_kind":"incident","name":"Webstresser.org takedown","aliases":["Operation Power Off 2018"],"started_on":"2018-04-24","ended_on":"2018-04-25","announced_on":"2018-04-25","activity_type":"ddos_for_hire","secondary_activity_types":[],"target_name":"Webstresser.org","target_type":"booter_stresser_service","summary":"Dutch and UK-led international action seizing the infrastructure of Webstresser.org, then the world's largest DDoS-for-hire service, with administrator arrests in four countries.","technical_outcome":"Service infrastructure seized in the Netherlands, the United States, and Germany; domain taken offline and replaced with a seizure notice.","later_status":"Follow-on measures taken against users of the service in multiple countries.","legal_mechanism":"Dutch and UK judicial process; international arrest warrants; Europol coordination","geographic_scope":["NL","GB","HR","CA","RS","DE","US","EU"],"reported_charged_count":null,"reported_apprehended_count":6,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":6,"estimated_group_size_max":null,"group_size_basis":"Six administrators reported arrested across the United Kingdom, Croatia, Canada, and Serbia.","group_completeness":"likely_complete","completeness_basis":"The administrative team was reported arrested and the infrastructure seized, though the full roster was not officially confirmed as closed and administrators were not comprehensively named.","resurgence_class":"E","confidence":"high","notes":["The service had roughly 136,000 registered users and had been used in more than four million attacks. Users are a separate population from the six administrators."],"parent_reference_id":"um_operation_poweroff","parent_slug":"operation-poweroff"},{"reference_id":"td_2022_poweroff_dec","slug":"operation-poweroff-december-2022-wave","record_kind":"incident","name":"Operation PowerOFF December 2022 wave","aliases":[],"started_on":"2022-12-13","ended_on":"2022-12-14","announced_on":"2022-12-14","activity_type":"ddos_for_hire","secondary_activity_types":[],"target_name":"48 booter and stresser services","target_type":"booter_stresser_services","summary":"FBI-led seizure of 48 DDoS-for-hire domains with charges against six US-based defendants, coordinated with UK and Dutch partners.","technical_outcome":"48 domains seized and redirected to seizure notices.","later_status":"Multiple defendants pleaded guilty in subsequent years.","legal_mechanism":"US seizure warrants and criminal complaints (Central District of California and District of Alaska); Europol coordination","geographic_scope":["US","GB","NL","PL"],"reported_charged_count":6,"reported_apprehended_count":7,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"48 independent services with separate operators.","group_completeness":"partial","completeness_basis":"Six defendants were charged against 48 seized services, so most operators were not publicly accounted for.","resurgence_class":"E","confidence":"high","notes":["Named defendants were published by DOJ but are not carried as person records in this pass. Documented named-person gap."],"parent_reference_id":"um_operation_poweroff","parent_slug":"operation-poweroff"},{"reference_id":"td_2024_poweroff_dec","slug":"operation-poweroff-december-2024-wave","record_kind":"incident","name":"Operation PowerOFF December 2024 wave","aliases":[],"started_on":"2024-12-01","ended_on":"2024-12-11","announced_on":"2024-12-11","activity_type":"ddos_for_hire","secondary_activity_types":[],"target_name":"27 booter and stresser platforms","target_type":"booter_stresser_services","summary":"Europol-coordinated wave taking down 27 DDoS-for-hire platforms ahead of the holiday attack season, with arrests in France and Germany.","technical_outcome":"27 platforms taken offline and domains seized.","later_status":"Prosecutions ongoing.","legal_mechanism":"National judicial process across 15 countries; Europol coordination","geographic_scope":["FR","DE","NL","US","PL","EU"],"reported_charged_count":null,"reported_apprehended_count":3,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"27 independent services with separate operators.","group_completeness":"partial","completeness_basis":"Three arrests across 27 seized platforms leaves most operators unaccounted for.","resurgence_class":"E","confidence":"high","notes":[],"parent_reference_id":"um_operation_poweroff","parent_slug":"operation-poweroff"},{"reference_id":"td_2026_poweroff_apr","slug":"operation-poweroff-april-2026-wave","record_kind":"incident","name":"Operation PowerOFF April 2026 wave","aliases":[],"started_on":"2026-04-13","ended_on":"2026-04-16","announced_on":"2026-04-16","activity_type":"ddos_for_hire","secondary_activity_types":[],"target_name":"53 booter and stresser domains","target_type":"booter_stresser_services","summary":"Multinational wave seizing 53 DDoS-for-hire domains across 21 countries, accompanied by arrests and a large-scale user-warning campaign.","technical_outcome":"53 domains seized; more than three million criminal accounts exposed; more than 75,000 warning messages sent to users.","later_status":"Prosecutions ongoing as of the cutoff.","legal_mechanism":"National judicial process across participating states; Europol coordination","geographic_scope":["EU","US","GB"],"reported_charged_count":null,"reported_apprehended_count":4,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"53 independent services with separate operators.","group_completeness":"partial","completeness_basis":"Four arrests across 53 seized domains leaves most operators unaccounted for.","resurgence_class":"G","confidence":"medium","notes":[],"parent_reference_id":"um_operation_poweroff","parent_slug":"operation-poweroff"},{"reference_id":"td_2023_snake","slug":"operation-medusa","record_kind":"incident","name":"Operation MEDUSA","aliases":["Snake malware disruption"],"started_on":"2023-05-08","ended_on":"2023-05-08","announced_on":"2023-05-09","activity_type":"state_sponsored","secondary_activity_types":["botnet_malware"],"target_name":"Snake malware network","target_type":"state_espionage_implant_network","summary":"The FBI executed a court-authorized operation using a purpose-built tool called PERSEUS to command Snake implants, attributed to Russian FSB Center 16, to overwrite their own components on infected machines worldwide.","technical_outcome":"Snake implants on victim machines disabled by issuing commands that caused the malware to overwrite its own vital components; peer-to-peer network neutralized.","later_status":"No arrests. US officials expressed confidence the network could not be readily reconstituted.","legal_mechanism":"Rule 41 search warrant, Eastern District of New York","geographic_scope":["US","GB","CA","AU","NZ"],"reported_charged_count":0,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"State intelligence unit rather than a finite criminal operator group.","group_completeness":"not_applicable","completeness_basis":"The operator is a state intelligence service. A criminal operator roster is not a meaningful denominator.","resurgence_class":"F","confidence":"high","notes":["Snake had been in use for roughly twenty years across more than 50 countries.","Charged and apprehended counts of 0 are explicitly established by DOJ."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_kv_botnet","slug":"kv-botnet-disruption","record_kind":"incident","name":"KV Botnet disruption","aliases":["Volt Typhoon router botnet takedown"],"started_on":"2023-12-01","ended_on":"2024-01-31","announced_on":"2024-01-31","activity_type":"state_sponsored","secondary_activity_types":["botnet_malware"],"target_name":"KV Botnet","target_type":"compromised_soho_router_network","summary":"Court-authorized FBI operation deleting malware from hundreds of end-of-life US small office and home office routers compromised by the PRC state-sponsored actor tracked as Volt Typhoon, and severing their connection to the botnet.","technical_outcome":"Malware deleted from compromised routers; command-and-control connections severed; steps taken to prevent reinfection without affecting legitimate router functions.","later_status":"Ongoing investigation. Routers remain vulnerable to reinfection if not replaced or patched.","legal_mechanism":"Rule 41 search and seizure warrants, Western District of Pennsylvania","geographic_scope":["US"],"reported_charged_count":0,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"State-sponsored actor rather than a finite criminal operator group.","group_completeness":"not_applicable","completeness_basis":"State-sponsored infrastructure disruption. No criminal operator roster applies.","resurgence_class":"G","confidence":"high","notes":["Reinfection risk was explicitly acknowledged by authorities, so no claim of permanent eradication is recorded."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_raptor_train","slug":"raptor-train-botnet-disruption","record_kind":"incident","name":"Raptor Train botnet disruption","aliases":["Flax Typhoon botnet takedown"],"started_on":"2024-09-01","ended_on":"2024-09-18","announced_on":"2024-09-18","activity_type":"state_sponsored","secondary_activity_types":["botnet_malware"],"target_name":"Raptor Train","target_type":"compromised_iot_device_network","summary":"Court-authorized DOJ and FBI operation seizing control of a botnet of consumer devices operated by the PRC-linked company Integrity Technology Group, tracked as Flax Typhoon, with French assistance.","technical_outcome":"Control of the botnet infrastructure seized; malware disabled on compromised devices; operators' attempt to migrate the botnet was countered.","later_status":"Integrity Technology Group later sanctioned by OFAC in a separate action.","legal_mechanism":"Court-authorized seizure and Rule 41 process, Western District of Pennsylvania","geographic_scope":["US","FR"],"reported_charged_count":0,"reported_apprehended_count":0,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"State-linked contractor company rather than a finite criminal operator group.","group_completeness":"not_applicable","completeness_basis":"State-sponsored infrastructure disruption.","resurgence_class":"G","confidence":"high","notes":["More than 200,000 consumer devices including routers, IP cameras, DVRs, and network attached storage were affected.","The OFAC designation of Integrity Technology Group is a separate action and is not counted as a charge."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"um_operation_bayonet","slug":"operation-bayonet","record_kind":"umbrella_campaign","name":"Operation Bayonet","aliases":[],"started_on":"2017-06-20","ended_on":"2017-07-20","announced_on":"2017-07-20","activity_type":"darknet_market","secondary_activity_types":[],"target_name":"AlphaBay and Hansa","target_type":"campaign","summary":"Joint US and Dutch campaign that seized AlphaBay and simultaneously ran Hansa covertly to capture migrating users.","technical_outcome":"See child incidents.","later_status":"See child incidents.","legal_mechanism":"See child incidents.","geographic_scope":["US","NL","TH","LT","DE","CA"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not applicable at campaign level.","group_completeness":"not_applicable","completeness_basis":"Campaign-level record. See child incidents.","resurgence_class":"G","confidence":"high","notes":["Excluded from incident totals. Children: td_2017_alphabay, td_2017_hansa."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"um_operation_cronos","slug":"operation-cronos","record_kind":"umbrella_campaign","name":"Operation Cronos","aliases":[],"started_on":"2024-02-19","ended_on":null,"announced_on":"2024-02-20","activity_type":"ransomware","secondary_activity_types":[],"target_name":"LockBit","target_type":"campaign","summary":"Ongoing NCA-led international task force against the LockBit ransomware operation, comprising the February 2024 infrastructure seizure and subsequent charging, sanctions, and disclosure actions.","technical_outcome":"See child incidents.","later_status":"Task force remained active through the cutoff.","legal_mechanism":"See child incidents.","geographic_scope":["GB","US","EU","AU","JP","CA"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not applicable at campaign level.","group_completeness":"not_applicable","completeness_basis":"Campaign-level record.","resurgence_class":"G","confidence":"high","notes":["Excluded from incident totals. Child in this pass: td_2024_cronos_w1.","The May 2024 Khoroshev unsealing and sanctions are recorded as person_actions against the wave 1 incident rather than as a separate infrastructure incident, because no new infrastructure action was involved."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"um_operation_endgame","slug":"operation-endgame","record_kind":"umbrella_campaign","name":"Operation Endgame","aliases":[],"started_on":"2024-05-27","ended_on":null,"announced_on":"2024-05-30","activity_type":"multi_threat_campaign","secondary_activity_types":["botnet_malware","ransomware"],"target_name":"Malware dropper and initial-access ecosystem","target_type":"campaign","summary":"Recurring French, German, and Dutch-initiated campaign against the malware dropper, loader, and initial-access ecosystem, executed in distinct dated waves.","technical_outcome":"See child incidents.","later_status":"Active through the cutoff.","legal_mechanism":"See child incidents.","geographic_scope":["FR","DE","NL","DK","GB","US","EU"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not applicable at campaign level.","group_completeness":"not_applicable","completeness_basis":"Campaign-level record.","resurgence_class":"G","confidence":"high","notes":["Excluded from incident totals. Children: td_2024_endgame_w1, td_2025_endgame_w2, td_2025_endgame_w3."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"um_operation_poweroff","slug":"operation-poweroff","record_kind":"umbrella_campaign","name":"Operation PowerOFF","aliases":["Operation Power Off"],"started_on":"2018-04-24","ended_on":null,"announced_on":"2018-04-25","activity_type":"ddos_for_hire","secondary_activity_types":[],"target_name":"DDoS-for-hire ecosystem","target_type":"campaign","summary":"Long-running recurring international campaign against booter and stresser services, executed in distinct dated waves since 2018.","technical_outcome":"See child incidents.","later_status":"Active through the cutoff.","legal_mechanism":"See child incidents.","geographic_scope":["NL","GB","US","DE","PL","EU"],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Not applicable at campaign level.","group_completeness":"not_applicable","completeness_basis":"Campaign-level record.","resurgence_class":"G","confidence":"high","notes":["Excluded from incident totals. Children in this pass: td_2018_webstresser, td_2022_poweroff_dec, td_2024_poweroff_dec, td_2026_poweroff_apr.","Additional waves in 2019, 2023, and May 2025 were identified but not fully verified in this pass. Recorded as a coverage gap."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2011_coreflood","slug":"coreflood-botnet-disruption","record_kind":"incident","name":"Coreflood botnet disruption","aliases":[],"started_on":"2011-04-13","ended_on":"2011-04-13","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Coreflood","target_type":"botnet","summary":"DOJ/FBI used a civil complaint, criminal seizure warrants for command servers, and a temporary restraining order to seize and disable the Coreflood botnet, which had been used for banking and identity fraud.","technical_outcome":"US authorities seized Coreflood's command-and-control servers and a set of associated domains, then used civil/criminal process to substitute law-enforcement-controlled servers that instructed infected machines to stop the malware.","later_status":null,"legal_mechanism":"Civil complaint; criminal seizure warrants; temporary restraining order and injunctive relief (D. Conn.)","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":"No individual operator was publicly charged in the seizure action itself; the case proceeded as an infrastructure-disruption operation.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2011_dnschanger","slug":"operation-ghost-click","record_kind":"incident","name":"Operation Ghost Click","aliases":[],"started_on":"2011-11-08","ended_on":"2011-11-08","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"DNSChanger","target_type":"botnet","summary":"FBI-led operation dismantled a rogue-DNS botnet that had redirected infected computers to fraudulent advertising infrastructure; six Estonian nationals were charged.","technical_outcome":"FBI seized rogue DNS servers and, with court authorization, substituted clean DNS servers to keep previously infected machines online during remediation.","later_status":null,"legal_mechanism":"Criminal complaint (SDNY); court-authorized substitute DNS infrastructure","geographic_scope":[],"reported_charged_count":7,"reported_apprehended_count":6,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":"Six defendants charged; only one (based in the US at the time) was reported apprehended promptly, with others pursued through Estonian authorities.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2012_megaupload","slug":"megaupload-seizure","record_kind":"incident","name":"Megaupload seizure","aliases":[],"started_on":"2012-01-19","ended_on":"2012-01-19","announced_on":null,"activity_type":"piracy_ip","secondary_activity_types":[],"target_name":"Megaupload","target_type":"file_hosting_service","summary":"DOJ indicted Megaupload and associated individuals for criminal copyright infringement and money laundering, seizing 18 domains and coordinating searches and arrests, including in New Zealand.","technical_outcome":"18 domains were seized; servers in multiple countries were taken offline or frozen pending the case.","later_status":"The United States prosecution remains pending as to Kim Dotcom. New Zealand’s High Court rejected his judicial-review challenge in [2025] NZHC 2634, and the Court of Appeal dismissed his appeal on 2026-07-01 in [2026] NZCA 284; a potential Supreme Court route remained. Co-defendant Andrus Nomm pleaded guilty in 2015; Mathias Ortmann and Bram van der Kolk entered New Zealand guilty pleas and were sentenced there.","legal_mechanism":"Federal criminal indictment (E.D. Va.); domain seizure warrants; New Zealand search/arrest warrants","geographic_scope":[],"reported_charged_count":7,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":"Seven individuals indicted, including Kim Dotcom; extradition proceedings from New Zealand were protracted and not fully resolved for years.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2013_citadel","slug":"citadel-botnet-disruption","record_kind":"incident","name":"Citadel botnet disruption","aliases":[],"started_on":"2013-06-05","ended_on":"2013-06-05","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Citadel","target_type":"botnet","summary":"FBI Cyber Division coordinated with Microsoft's separate civil legal action to disrupt more than a thousand Citadel botnets used for banking fraud.","technical_outcome":"Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.","later_status":null,"legal_mechanism":"FBI criminal process combined with a parallel Microsoft civil action (E.D.N.Y./W.D.N.C. civil orders for the Microsoft side)","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":"Framed publicly as an infrastructure-disruption operation rather than a personnel-capture operation.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2013_zeroaccess","slug":"zeroaccess-botnet-disruption","record_kind":"incident","name":"ZeroAccess botnet disruption","aliases":[],"started_on":"2013-12-05","ended_on":"2013-12-05","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"ZeroAccess","target_type":"botnet","summary":"A coalition led by Europol, the FBI, and Microsoft disrupted the ZeroAccess click-fraud and cryptomining botnet.","technical_outcome":"Coordinated sinkholing and infrastructure disruption targeting ZeroAccess C2 servers.","later_status":null,"legal_mechanism":"Coordinated law-enforcement/civil technical action; exact statutory basis by jurisdiction not fully public.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_ramnit","slug":"ramnit-botnet-disruption","record_kind":"incident","name":"Ramnit botnet disruption","aliases":[],"started_on":"2015-02-24","ended_on":"2015-02-24","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Ramnit","target_type":"botnet","summary":"A Europol-supported coalition of European national police and security-industry partners disrupted Ramnit botnet infrastructure, which Europol estimated had infected roughly 3.2 million computers.","technical_outcome":"Servers and domains supporting the botnet were taken under law-enforcement control and routed to a sinkhole.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority; exact statute per country not publicly detailed.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Europol estimated approximately 3.2 million infected computers.","group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_simda","slug":"simda-botnet-disruption","record_kind":"incident","name":"Simda botnet disruption","aliases":[],"started_on":"2015-04-09","ended_on":"2015-04-09","announced_on":"2015-04-13","activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Simda","target_type":"botnet","summary":"An INTERPOL-coordinated operation with national police and private security firms targeted command-and-control servers of the Simda botnet, which affected systems in more than 190 countries.","technical_outcome":"C2 servers were seized or disrupted by participating national authorities in a coordinated action. 10 C2 servers seized in the Netherlands; additional servers taken down in US, Russia, Luxembourg, Poland","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Reported to affect systems in more than 190 countries.","group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_beebone","slug":"operation-source-beebone-botnet-disruption","record_kind":"incident","name":"Operation Source / Beebone botnet disruption","aliases":[],"started_on":"2015-04-08","ended_on":"2015-04-08","announced_on":"2015-04-09","activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Beebone","target_type":"botnet","summary":"A Dutch-led action supported by Europol EC3/J-CAT, the FBI, and security-industry partners seized and sinkholed domains used by the polymorphic Beebone downloader botnet.","technical_outcome":"Malicious domains were seized and sinkholed, allowing victim IP data to be supplied to ISPs and CERTs for remediation.","later_status":null,"legal_mechanism":"Dutch judicial/search-and-seizure authority; coordinated with US process for domains hosted there.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_playpen","slug":"operation-pacifier-playpen","record_kind":"incident","name":"Operation Pacifier / Playpen","aliases":[],"started_on":"2015-02-20","ended_on":"2015-03-04","announced_on":null,"activity_type":"csam","secondary_activity_types":[],"target_name":"Playpen","target_type":"csam_platform","summary":"FBI seized the Playpen Tor hidden-service server and, under court authorization, continued operating it for a limited period as an investigative technique (a Network Investigative Technique) to identify users, before shutting it down.","technical_outcome":"Server seized and covertly operated by the FBI for approximately two weeks under a search warrant before permanent shutdown.","later_status":null,"legal_mechanism":"Federal search warrant (E.D. Va.) authorizing an NIT; subsequent criminal prosecutions nationwide.","geographic_scope":[],"reported_charged_count":3,"reported_apprehended_count":3,"reported_convicted_count":3,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"FBI later described Playpen as having more than 150,000 users.","group_completeness":"likely_complete","completeness_basis":"Creator/lead administrator and co-administrators were identified and prosecuted; downstream user prosecutions are a separate, much larger population.","resurgence_class":null,"confidence":null,"notes":["The FBI's continued covert operation of a seized CSAM site as an investigative technique was legally and ethically controversial and generated substantial subsequent litigation over the scope of the NIT warrant."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_operation_babylon","slug":"operation-babylon","record_kind":"incident","name":"Operation Babylon","aliases":[],"started_on":"2015-07-29","ended_on":"2015-07-29","announced_on":"2015-07-31","activity_type":"csam","secondary_activity_types":[],"target_name":"Unnamed Tor CSAM/illicit-market hidden service","target_type":"csam_platform","summary":"Italian State Police (Polizia Postale) and the National Centre for Combating Online Child Pornography shut a Tor hidden service used to exchange CSAM and host illicit-market activity, supported by Europol.","technical_outcome":"Tor hidden service shut down; approximately 14,000 associated bitcoin wallets seized in connection with the administrator's residence search.","later_status":null,"legal_mechanism":"Italian judicial search/seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":"Final charging disposition of the administrator was not established in the reviewed source.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_darkode","slug":"darkode-forum-takedown","record_kind":"incident","name":"Darkode forum takedown","aliases":["Operation Shrouded Horizon"],"started_on":"2015-07-15","ended_on":"2015-07-15","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"Darkode","target_type":"cybercrime_forum","summary":"FBI and international partners across around 20 countries seized the Darkode cybercrime forum, an invite-only English-language marketplace for malware and hacking tools/services, with numerous arrests announced the same day.","technical_outcome":"Forum infrastructure was seized and taken offline; a seizure notice replaced the site.","later_status":null,"legal_mechanism":"Federal criminal process (W.D. Pa.); coordinated international arrest warrants.","geographic_scope":[],"reported_charged_count":12,"reported_apprehended_count":28,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":"Roughly two dozen defendants were charged across multiple countries; the broader membership was not fully accounted for.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2019_wall_street_market","slug":"wall-street-market-silkkitie-valhalla-shutdown","record_kind":"incident","name":"Wall Street Market / Silkkitie (Valhalla) shutdown","aliases":[],"started_on":"2019-05-03","ended_on":"2019-05-03","announced_on":null,"activity_type":"darknet_market","secondary_activity_types":[],"target_name":"Wall Street Market and Silkkitie/Valhalla","target_type":"darknet_market","summary":"German federal police/prosecutors shut down Wall Street Market, then reportedly serving more than a million users, and arrested three alleged administrators; Finnish Customs separately closed Silkkitie/Valhalla in the same coordinated period.","technical_outcome":"Wall Street Market infrastructure was seized; Silkkitie/Valhalla infrastructure was separately taken down by Finnish Customs.","later_status":null,"legal_mechanism":"German judicial search/seizure authority; Finnish Customs enforcement authority.","geographic_scope":[],"reported_charged_count":4,"reported_apprehended_count":4,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Reported to have served more than one million users.","group_completeness":"partial","completeness_basis":"Three alleged German administrators arrested (not individually named in the sources reviewed for this pass); a US-based moderator was separately charged. Reported as an aggregate count rather than named person records, consistent with the project's rule against placeholder person records.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2019_deepdotweb","slug":"deepdotweb-domain-seizure","record_kind":"incident","name":"DeepDotWeb domain seizure","aliases":[],"started_on":"2019-05-07","ended_on":"2019-05-07","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"DeepDotWeb","target_type":"referral_portal","summary":"FBI seized the clearnet domain of DeepDotWeb, a portal that referred users to darknet markets in exchange for kickbacks, and two alleged administrators were arrested abroad (Israel and France).","technical_outcome":"Clearnet domain seized pursuant to US court order.","later_status":null,"legal_mechanism":"US court seizure order; indictment alleging money-laundering conspiracy (W.D. Pa.)","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":2,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Both alleged administrators were arrested internationally in a coordinated action.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_darkmarket","slug":"darkmarket-shutdown","record_kind":"incident","name":"DarkMarket shutdown","aliases":[],"started_on":"2021-01-12","ended_on":"2021-01-12","announced_on":null,"activity_type":"darknet_market","secondary_activity_types":[],"target_name":"DarkMarket","target_type":"darknet_market","summary":"German authorities seized DarkMarket server infrastructure and arrested the alleged operator near the German-Danish border; Europol reported roughly 500,000 users and more than 2,400 sellers.","technical_outcome":"Servers seized; site taken offline.","later_status":null,"legal_mechanism":"German judicial search/seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Europol reported approximately 500,000 users and more than 2,400 sellers.","group_completeness":"likely_complete","completeness_basis":"The single alleged operator was arrested; exact German charge counts were not made public in English-language material.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_monopoly_market","slug":"monopoly-market-seizure","record_kind":"incident","name":"Monopoly Market seizure","aliases":[],"started_on":"2021-12-01","ended_on":"2021-12-01","announced_on":null,"activity_type":"darknet_market","secondary_activity_types":[],"target_name":"Monopoly Market","target_type":"darknet_market","summary":"German authorities seized Monopoly Market's server infrastructure; the seizure was not publicly disclosed at the time and instead formed the intelligence basis for a later multinational operation against vendors and buyers.","technical_outcome":"Server infrastructure covertly seized and monitored before public disclosure.","later_status":"Operator Milomir Desnica arrested in Austria in November 2022, extradited to the United States June 23, 2023, pleaded guilty November 8, 2023, and was sentenced February 15, 2024 to 168 months.","legal_mechanism":"German judicial search/seizure authority.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"No operator arrest was announced in connection with the infrastructure seizure itself.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_operation_spector","slug":"operation-spector","record_kind":"incident","name":"Operation SpecTor","aliases":[],"started_on":"2023-05-02","ended_on":"2023-05-02","announced_on":null,"activity_type":"darknet_market","secondary_activity_types":[],"target_name":"Multiple darknet-market vendors and buyers (Monopoly Market intelligence)","target_type":"darknet_market","summary":"A Europol-coordinated multinational operation used intelligence from the covert 2021 Monopoly Market seizure to conduct a large sweep of darknet-market vendors and buyers across Europe, the US, UK, and Brazil.","technical_outcome":"Operation SpecTor was a follow-on enforcement sweep based on the December 2021 Monopoly server seizure; no separate new Monopoly infrastructure seizure occurred on May 2, 2023.","later_status":null,"legal_mechanism":"National arrest warrants across participating jurisdictions.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":288,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":"Operation targeted a cross-section of vendors and buyers rather than a single bounded operator group.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2020_weleakinfo","slug":"weleakinfo-seizure","record_kind":"incident","name":"WeLeakInfo seizure","aliases":[],"started_on":"2020-01-16","ended_on":"2020-01-16","announced_on":"2020-01-16","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"WeLeakInfo","target_type":"stolen_data_marketplace","summary":"A multinational operation including US, UK, Netherlands, and Germany seized the WeLeakInfo domain, a subscription service selling access to breached personal data.","technical_outcome":"Domain seized and replaced with a law-enforcement notice.","later_status":null,"legal_mechanism":"US domain seizure warrant; coordinated with UK/NL/DE authorities.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":2,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2018_vpnfilter","slug":"vpnfilter-botnet-disruption","record_kind":"incident","name":"VPNFilter botnet disruption","aliases":[],"started_on":"2018-05-23","ended_on":"2018-05-23","announced_on":null,"activity_type":"state_sponsored","secondary_activity_types":[],"target_name":"VPNFilter (attributed to Russia-linked Sandworm)","target_type":"botnet","summary":"A W.D. Pennsylvania court authorized the FBI to seize a domain used in VPNFilter's command-and-control and reinfection mechanism, targeting malware that had compromised networking devices worldwide.","technical_outcome":"Domain seized; infected-device contacts redirected to FBI-controlled infrastructure, allowing victim IP addresses to be passed to remediation partners such as Shadowserver.","later_status":null,"legal_mechanism":"Court-authorized domain seizure (W.D. Pa.)","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_cyclops_blink","slug":"cyclops-blink-disruption","record_kind":"incident","name":"Cyclops Blink disruption","aliases":[],"started_on":"2022-03-18","ended_on":"2022-04-06","announced_on":"2022-04-06","activity_type":"state_sponsored","secondary_activity_types":[],"target_name":"Cyclops Blink (attributed to Russia's GRU-linked Sandworm)","target_type":"botnet","summary":"A court-authorized DOJ/FBI operation copied and removed GRU/Sandworm malware from compromised firewall devices functioning as C2 nodes, severing thousands of downstream bots from those nodes.","technical_outcome":"Malware copied for evidentiary purposes and then removed from compromised C2 devices under court authorization; device owners still needed to independently patch underlying vulnerabilities.","later_status":null,"legal_mechanism":"Court-authorized remote remediation (Rule 41-type warrant).","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_rsocks","slug":"rsocks-proxy-botnet-disruption","record_kind":"incident","name":"RSOCKS proxy botnet disruption","aliases":[],"started_on":"2022-06-16","ended_on":"2022-06-16","announced_on":"2022-06-16","activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"RSOCKS","target_type":"residential_proxy_botnet","summary":"FBI, working with USAO Southern District of California and DOJ CCIPS, disrupted a malicious residential-proxy botnet operators claimed encompassed millions of hacked devices, after undercover purchases mapped its backend infrastructure.","technical_outcome":"Backend infrastructure mapped via undercover technical purchases; disruption of the proxy-selling service followed.","later_status":null,"legal_mechanism":"Federal search-warrant process (S.D. Cal.), publicly unsealed.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_flubot","slug":"flubot-disruption","record_kind":"incident","name":"FluBot disruption","aliases":[],"started_on":null,"ended_on":null,"announced_on":"2022-06-01","activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"FluBot","target_type":"android_malware","summary":"A Dutch Police-centered international operation involving 11 countries, supported by Europol/J-CAT, took control of and disrupted infrastructure behind the FluBot Android SMS-phishing malware.","technical_outcome":"Infrastructure behind the malware was taken under control or disrupted through coordinated international measures.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority across 11 countries.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_ipstorm","slug":"ipstorm-botnet-dismantlement","record_kind":"incident","name":"IPStorm botnet dismantlement","aliases":[],"started_on":"2023-11-01","ended_on":"2023-11-01","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"IPStorm","target_type":"botnet","summary":"DOJ/FBI announced dismantlement of the IPStorm botnet, which had infected tens of thousands of computers and network devices across several continents, alongside developer Sergei Makinin's guilty plea.","technical_outcome":"Botnet infrastructure dismantled in connection with the criminal prosecution.","later_status":null,"legal_mechanism":"Federal criminal prosecution and guilty plea; DOJ CCIPS.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Sole developer identified, prosecuted, and pleaded guilty.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_chipmixer","slug":"chipmixer-takedown","record_kind":"incident","name":"ChipMixer takedown","aliases":[],"started_on":"2023-03-15","ended_on":"2023-03-15","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"ChipMixer","target_type":"cryptocurrency_mixer","summary":"US and German authorities cooperated to seize ChipMixer server infrastructure and charge its alleged operator, disrupting a cryptocurrency-mixing service used to launder criminal proceeds.","technical_outcome":"Server infrastructure seized in Germany; associated domains seized by US authorities.","later_status":null,"legal_mechanism":"US seizure warrant; German judicial search/seizure authority; federal criminal charges.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_ragnar_locker","slug":"ragnar-locker-disruption","record_kind":"incident","name":"Ragnar Locker disruption","aliases":[],"started_on":"2023-10-20","ended_on":"2023-10-20","announced_on":null,"activity_type":"ransomware","secondary_activity_types":[],"target_name":"Ragnar Locker","target_type":"ransomware_group","summary":"A French-led international operation, with infrastructure seizures in the Netherlands, Germany, and Sweden, disrupted the Ragnar Locker ransomware group.","technical_outcome":"Ransomware infrastructure seized across multiple European jurisdictions; leak site taken down.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":"Alleged principal developer/administrator arrested in Paris (not publicly named in sources reviewed); five additional suspects interviewed. Recorded as an aggregate count since no name is available, consistent with the project's rule against placeholder person records.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_alphv_blackcat","slug":"alphv-blackcat-disruption","record_kind":"incident","name":"ALPHV/BlackCat disruption","aliases":[],"started_on":"2023-12-19","ended_on":"2023-12-19","announced_on":null,"activity_type":"ransomware","secondary_activity_types":[],"target_name":"ALPHV/BlackCat","target_type":"ransomware_group","summary":"DOJ/FBI announced a disruption of the ALPHV/BlackCat ransomware-as-a-service operation and offered an FBI-developed decryption capability to more than 500 victims.","technical_outcome":"Leak-site and negotiation infrastructure disrupted; decryption keys/tooling provided to victims.","later_status":null,"legal_mechanism":"Court-authorized technical operation; federal criminal process.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":"No core-operator arrests were announced in the initial disruption; the group reasserted control of some infrastructure shortly afterward.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_nemesis","slug":"nemesis-market-seizure","record_kind":"incident","name":"Nemesis Market seizure","aliases":[],"started_on":"2024-03-20","ended_on":"2024-03-20","announced_on":"2024-03-21","activity_type":"darknet_market","secondary_activity_types":[],"target_name":"Nemesis Market","target_type":"darknet_market","summary":"German BKA seized the server infrastructure of Nemesis Market, a darknet marketplace for drugs and cybercrime services.","technical_outcome":"Server infrastructure seized; site taken offline.","later_status":null,"legal_mechanism":"German judicial search/seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_operation_magnus","slug":"operation-magnus-redline-and-meta-infostealers","record_kind":"incident","name":"Operation Magnus (RedLine and META infostealers)","aliases":[],"started_on":"2024-10-28","ended_on":"2024-10-28","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"RedLine Stealer and META Stealer","target_type":"infostealer_malware","summary":"Dutch-led Operation Magnus, coordinated with Eurojust, Europol, FBI, and other partners, took down the infrastructure of the RedLine and META infostealer malware families.","technical_outcome":"Servers seized; source code and backend databases obtained.","later_status":null,"legal_mechanism":"Dutch judicial search/seizure authority; coordinated international warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2020_safe_inet","slug":"safe-inet-insorg-vpn-takedown","record_kind":"incident","name":"Safe-Inet / Insorg VPN takedown","aliases":[],"started_on":"2020-12-22","ended_on":"2020-12-22","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"Safe-Inet (also known as Insorg)","target_type":"bulletproof_vpn_service","summary":"A multinational coalition took offline Safe-Inet, a VPN service heavily marketed to and used by cybercriminals to anonymize attacks.","technical_outcome":"VPN service infrastructure and associated domains taken offline.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_doublevpn","slug":"doublevpn-takedown","record_kind":"incident","name":"DoubleVPN takedown","aliases":[],"started_on":"2021-06-30","ended_on":"2021-06-30","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"DoubleVPN","target_type":"bulletproof_vpn_service","summary":"A Dutch-led coalition took offline DoubleVPN, a VPN service marketed on cybercrime forums and used to anonymize criminal network intrusions and ransomware attacks.","technical_outcome":"Servers and domains seized.","later_status":null,"legal_mechanism":"Dutch judicial search/seizure authority; coordinated international warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_vpnlab","slug":"vpnlab-net-takedown","record_kind":"incident","name":"VPNLab.net takedown","aliases":[],"started_on":"2022-01-18","ended_on":"2022-01-18","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"VPNLab.net","target_type":"bulletproof_vpn_service","summary":"A German/international coalition seized VPNLab.net, a VPN service used by cybercriminals including ransomware affiliates to anonymize their operations.","technical_outcome":"Servers seized in a coordinated multi-country operation.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_lolekhosted","slug":"lolekhosted-seizure","record_kind":"incident","name":"LolekHosted seizure","aliases":[],"started_on":"2023-08-08","ended_on":"2023-08-08","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"LolekHosted.net","target_type":"bulletproof_hosting","summary":"A federal court in the Middle District of Florida issued a warrant for DOJ/FBI to seize LolekHosted.net, a bulletproof-hosting service tied to NetWalker ransomware attacks and other cybercrime.","technical_outcome":"Domain and associated hosting infrastructure seized.","later_status":null,"legal_mechanism":"Federal seizure warrant (M.D. Fla.)","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_matrix","slug":"matrix-encrypted-messaging-service-takedown","record_kind":"incident","name":"Matrix encrypted messaging service takedown","aliases":[],"started_on":"2024-12-03","ended_on":"2024-12-03","announced_on":null,"activity_type":"criminal_communications","secondary_activity_types":[],"target_name":"Matrix","target_type":"encrypted_messaging_service","summary":"A French-Dutch joint operation took down Matrix, an encrypted messaging service used by organized-crime groups.","technical_outcome":"Server infrastructure seized; service taken offline.","later_status":null,"legal_mechanism":"French/Dutch joint-investigation-team judicial authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_ispoof","slug":"ispoof-takedown","record_kind":"incident","name":"iSpoof takedown","aliases":[],"started_on":"2022-11-23","ended_on":"2022-11-23","announced_on":null,"activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"iSpoof","target_type":"spoofing_as_a_service","summary":"London's Metropolitan Police led a takedown of iSpoof, a caller-ID spoofing-as-a-service platform used to facilitate telephone fraud; Europol reported around 142 arrests connected to the operation.","technical_outcome":"Platform infrastructure seized; service taken offline.","later_status":null,"legal_mechanism":"UK judicial search/seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":142,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_labhost","slug":"labhost-phishing-as-a-service-takedown","record_kind":"incident","name":"LabHost phishing-as-a-service takedown","aliases":[],"started_on":"2024-04-18","ended_on":"2024-04-18","announced_on":null,"activity_type":"phishing","secondary_activity_types":[],"target_name":"LabHost","target_type":"phishing_as_a_service","summary":"London Metropolitan Police led a multinational operation involving 19 countries against LabHost, a phishing-as-a-service platform.","technical_outcome":"Platform infrastructure seized; service taken offline.","later_status":null,"legal_mechanism":"UK judicial search/seizure authority; coordinated international warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_heartsender","slug":"heartsender-takedown","record_kind":"incident","name":"HeartSender takedown","aliases":[],"started_on":"2025-01-30","ended_on":"2025-01-30","announced_on":null,"activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"HeartSender (\"Saim Raza\")","target_type":"cybercrime_tooling_marketplace","summary":"DOJ/FBI seized 39 domains and associated servers used to sell phishing kits and other fraud-enabling tools through the HeartSender operation.","technical_outcome":"39 domains and associated servers seized.","later_status":null,"legal_mechanism":"Federal seizure warrant.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_cracked_nulled","slug":"cracked-and-nulled-forums-takedown","record_kind":"incident","name":"Cracked and Nulled forums takedown","aliases":[],"started_on":"2025-01-30","ended_on":"2025-01-30","announced_on":null,"activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"Cracked and Nulled","target_type":"cybercrime_forum","summary":"A DOJ-led multinational coalition seized the Cracked and Nulled cybercrime forums, which sold stolen data, hacking tools, and malware.","technical_outcome":"Forum infrastructure seized; sites taken offline.","later_status":null,"legal_mechanism":"Federal seizure warrant; coordinated international judicial authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_phobos_8base","slug":"phobos-8base-ransomware-disruption","record_kind":"incident","name":"Phobos/8Base ransomware disruption","aliases":[],"started_on":null,"ended_on":null,"announced_on":"2025-02-11","activity_type":"ransomware","secondary_activity_types":[],"target_name":"Phobos and 8Base","target_type":"ransomware_group","summary":"A multinational coalition disrupted more than 100 servers connected to the Phobos ransomware-as-a-service operation and the affiliated 8Base group, accompanied by arrests.","technical_outcome":"27 servers linked to the criminal network were taken down in the February 2025 action; the prior \u003e100 figure was not supported by the official release located.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":4,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_garantex","slug":"garantex-disruption","record_kind":"incident","name":"Garantex disruption","aliases":[],"started_on":"2025-03-07","ended_on":"2025-03-07","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"Garantex","target_type":"cryptocurrency_exchange","summary":"US Secret Service and DOJ seized domains associated with Garantex, a cryptocurrency exchange the US had previously sanctioned, while German and Finnish authorities took parallel action against infrastructure and funds.","technical_outcome":"Domains seized by US authorities; parallel infrastructure/fund actions in Germany and Finland.","later_status":null,"legal_mechanism":"US seizure warrant; German and Finnish judicial authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2021_boystown","slug":"boystown-csam-platform-takedown","record_kind":"incident","name":"Boystown CSAM platform takedown","aliases":[],"started_on":"2021-05-03","ended_on":"2021-05-03","announced_on":null,"activity_type":"csam","secondary_activity_types":[],"target_name":"Boystown and associated Tor chat services","target_type":"csam_platform","summary":"A German BKA-led task force, with Europol and law enforcement in Australia, Canada, the Netherlands, Sweden, and the US, seized Boystown and related Tor chat services, which Europol described as having approximately 400,000 registered users.","technical_outcome":"Dark-web platform and associated chat infrastructure taken offline.","later_status":null,"legal_mechanism":"German judicial search/seizure authority; coordinated international warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":4,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Europol reported approximately 400,000 registered users.","group_completeness":"likely_complete","completeness_basis":"Four principal suspects (three alleged administrators and one member) were arrested.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_kidflix","slug":"operation-stream-kidflix","record_kind":"incident","name":"Operation Stream / Kidflix","aliases":[],"started_on":"2025-03-10","ended_on":"2025-03-23","announced_on":"2025-04-02","activity_type":"csam","secondary_activity_types":[],"target_name":"Kidflix","target_type":"csam_platform","summary":"German authorities led an extensive international investigation that seized Kidflix infrastructure; Europol described the platform as one of the world's largest child-sexual-exploitation platforms, with nearly two million users before shutdown.","technical_outcome":"Server seized March 11, 2025; 79 arrests, 1,393 suspects identified, more than 3,000 devices seized, and 39 children protected as of announcement.","later_status":null,"legal_mechanism":"German judicial search/seizure authority; coordinated international warrants across dozens of countries.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":79,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"Europol reported nearly two million users.","group_completeness":"unknown","completeness_basis":"Numerous suspects were identified and arrested internationally, but a final worldwide charging total was not established as fixed in the reviewed sources.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_cfake_socfake","slug":"cfake-com-and-socfake-com-seizure","record_kind":"incident","name":"CFAKE.com and SOCFAKE.com seizure","aliases":[],"started_on":"2026-06-12","ended_on":"2026-06-12","announced_on":null,"activity_type":"csam","secondary_activity_types":[],"target_name":"CFAKE.com and SOCFAKE.com","target_type":"deepfake_generation_service","summary":"HSI New Jersey seized domains associated with services alleged to create and distribute non-consensual sexual deepfake imagery, supported by HSI Rome and DHS forensic capabilities.","technical_outcome":"Domains seized.","later_status":null,"legal_mechanism":"US seizure warrant.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2010_operation_in_our_sites","slug":"operation-in-our-sites-initial-phase","record_kind":"incident","name":"Operation In Our Sites (initial phase)","aliases":[],"started_on":"2010-06-30","ended_on":"2010-06-30","announced_on":null,"activity_type":"piracy_ip","secondary_activity_types":[],"target_name":"Nine domains offering pirated first-run films","target_type":"piracy_website","summary":"ICE HSI and the National IPR Center began Operation In Our Sites with seizure warrants against nine domains offering pirated first-run movies, growing into a recurring enforcement program; DOJ reported 761 seized domains by May 2012.","technical_outcome":"Domains seized and replaced with law-enforcement notices; program continued with additional waves.","later_status":null,"legal_mechanism":"Federal seizure warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2016_kickass_torrents","slug":"kickass-torrents-takedown","record_kind":"incident","name":"Kickass Torrents takedown","aliases":[],"started_on":"2016-07-20","ended_on":"2016-07-20","announced_on":null,"activity_type":"piracy_ip","secondary_activity_types":[],"target_name":"Kickass Torrents (KAT)","target_type":"piracy_website","summary":"DOJ/HSI/IRS-CI filed a criminal complaint, seized domains, and coordinated the arrest of alleged operator Artem Vaulin in Poland, disrupting the Kickass Torrents piracy site.","technical_outcome":"Domains seized.","later_status":null,"legal_mechanism":"Federal criminal complaint; domain seizure warrants; Polish arrest warrant.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Alleged sole primary operator arrested in Poland.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_iptv_action","slug":"european-illegal-iptv-enforcement-action","record_kind":"incident","name":"European illegal IPTV enforcement action","aliases":[],"started_on":"2024-11-27","ended_on":"2024-11-27","announced_on":null,"activity_type":"piracy_ip","secondary_activity_types":[],"target_name":"Multiple illegal IPTV networks","target_type":"illegal_streaming_network","summary":"Europol announced a major European illegal-IPTV enforcement action involving 102 identified suspects, 11 arrests, and more than 112 searches across participating countries.","technical_outcome":"IPTV distribution infrastructure disrupted across multiple countries.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":11,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_operation_offsides","slug":"operation-offsides-2026-fifa-world-cup-streaming-domains","record_kind":"incident","name":"Operation Offsides (2026 FIFA World Cup streaming domains)","aliases":[],"started_on":"2026-06-26","ended_on":"2026-07-20","announced_on":"2026-07-20","activity_type":"piracy_ip","secondary_activity_types":[],"target_name":"More than 1,000 unauthorized World Cup streaming domains","target_type":"illegal_streaming_network","summary":"During the 2026 FIFA World Cup, DOJ announced the seizure of more than 1,000 domains allegedly used to stream World Cup matches without authorization.","technical_outcome":"More than 1,000 domains seized. More than 1,000 domains across three U.S. seizure actions; nearly 400 announced June 26","later_status":null,"legal_mechanism":"Federal seizure warrants; coordinated with ICE HSI and the National IPR Center.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2018_amaq","slug":"amaq-propaganda-infrastructure-takedown","record_kind":"incident","name":"Amaq propaganda infrastructure takedown","aliases":[],"started_on":"2018-04-25","ended_on":"2018-04-26","announced_on":"2018-04-27","activity_type":"terrorism_extremism","secondary_activity_types":[],"target_name":"Amaq (Islamic State propaganda distribution infrastructure)","target_type":"terrorist_propaganda_infrastructure","summary":"A Belgian/EU coalition targeted the Islamic State's Amaq propaganda infrastructure, including its web and media distribution mechanisms.","technical_outcome":"Web/media distribution infrastructure disrupted.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2019_is_web_infrastructure","slug":"islamic-state-web-infrastructure-takedown","record_kind":"excluded_candidate","name":"Islamic State web infrastructure takedown","aliases":[],"started_on":"2019-11-21","ended_on":"2019-11-24","announced_on":"2019-11-25","activity_type":"terrorism_extremism","secondary_activity_types":[],"target_name":"Islamic State web/media infrastructure","target_type":"terrorist_propaganda_infrastructure","summary":"A renewed EU judicial/law-enforcement operation again targeted Islamic State web infrastructure, building on the 2018 Amaq action.","technical_outcome":"More than 26,000 items of Islamic State-supporting content were referred to nine online service providers for terms-of-service evaluation/removal; the located official source does not establish a government seizure or takeover of infrastructure.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_synergia_ii","slug":"interpol-synergia-ii","record_kind":"incident","name":"INTERPOL Synergia II","aliases":[],"started_on":null,"ended_on":null,"announced_on":"2024-11-05","activity_type":"multi_threat_campaign","secondary_activity_types":[],"target_name":"Heterogeneous malicious infrastructure (phishing, malware, ransomware C2)","target_type":"multi_threat_infrastructure","summary":"INTERPOL's Synergia II campaign coordinated more than 90 countries against heterogeneous malicious infrastructure, reporting more than 22,000 malicious infrastructures disrupted.","technical_outcome":"More than 22,000 malicious IP addresses or servers taken down; 59 servers and 43 electronic devices seized.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority in each participating country.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":41,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_synergia_iii","slug":"interpol-synergia-iii","record_kind":"incident","name":"INTERPOL Synergia III","aliases":[],"started_on":"2025-07-18","ended_on":"2026-01-31","announced_on":"2026-03-13","activity_type":"multi_threat_campaign","secondary_activity_types":[],"target_name":"Heterogeneous malicious infrastructure","target_type":"multi_threat_infrastructure","summary":"INTERPOL's Synergia III campaign ran from July 2025 through January 2026, targeting roughly 45,000 malicious IPs with participation from 72 countries.","technical_outcome":"Approximately 45,000 malicious IPs targeted for disruption or takedown across the campaign period.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority in each participating country.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":94,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_operation_secure","slug":"interpol-operation-secure","record_kind":"incident","name":"INTERPOL Operation Secure","aliases":[],"started_on":null,"ended_on":null,"announced_on":"2025-06-11","activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Infostealer malware infrastructure (26-country action)","target_type":"infostealer_malware","summary":"INTERPOL's Operation Secure reported more than 20,000 malicious IPs/domains taken down, 41 servers seized, and 32 arrests across a 26-country infostealer crackdown.","technical_outcome":"More than 20,000 malicious IP addresses and domains taken down; 41 servers seized; 32 arrests; more than 216,000 victims notified or identified.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority across 26 countries.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":32,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2025_serengeti_2","slug":"serengeti-2-0","record_kind":"incident","name":"Serengeti 2.0","aliases":[],"started_on":null,"ended_on":null,"announced_on":"2025-08-22","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"Fraud infrastructure across 18 African countries","target_type":"multi_threat_infrastructure","summary":"A joint INTERPOL/AFRIPOL operation across 18 African countries plus the UK disrupted more than 11,000 malicious infrastructures connected to online fraud.","technical_outcome":"11,432 malicious infrastructures dismantled; approximately USD 97.4 million recovered; 88,000 victims identified across 18 African countries and the United Kingdom.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority across participating countries.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":1209,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_red_card_2","slug":"red-card-2-0","record_kind":"incident","name":"Red Card 2.0","aliases":[],"started_on":"2025-12-08","ended_on":"2026-01-30","announced_on":"2026-02-18","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"Cross-border online fraud infrastructure","target_type":"multi_threat_infrastructure","summary":"An INTERPOL-coordinated operation, Red Card 2.0, targeted cross-border online-fraud infrastructure and networks.","technical_outcome":"Fraud-related infrastructure disrupted across participating countries. 1,442 malicious IPs, domains, servers and related infrastructure taken down; 2,341 devices seized","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":651,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2019_bestmixer","slug":"bestmixer-seizure","record_kind":"incident","name":"BestMixer seizure","aliases":[],"started_on":"2019-05-22","ended_on":"2019-05-22","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"BestMixer.io","target_type":"cryptocurrency_mixer","summary":"Dutch FIOD, supported by Europol, seized BestMixer.io in what Europol described as the first law-enforcement action of its kind against a cryptocurrency-mixing service.","technical_outcome":"Six servers were seized in the Netherlands and Luxembourg and BestMixer.io was taken offline.","later_status":null,"legal_mechanism":"Dutch judicial search/seizure authority (FIOD).","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_sinbad","slug":"sinbad-cryptocurrency-mixer-seizure","record_kind":"incident","name":"Sinbad cryptocurrency mixer seizure","aliases":[],"started_on":"2023-11-27","ended_on":"2023-11-27","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"Sinbad","target_type":"cryptocurrency_mixer","summary":"Dutch, Finnish, and US authorities seized the infrastructure of Sinbad, a cryptocurrency mixer later described in DOJ proceedings against mixer operators as a laundering tool for criminal proceeds including funds linked to North Korea-attributed hacks.","technical_outcome":"Mixer infrastructure and domains seized.","later_status":null,"legal_mechanism":"Coordinated national judicial/search-and-seizure authority (Netherlands, Finland, US).","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_huione_backend","slug":"huione-group-backend-infrastructure-seizure","record_kind":"incident","name":"Huione Group backend infrastructure seizure","aliases":[],"started_on":"2026-06-23","ended_on":"2026-06-23","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"Huione Group money-laundering backend","target_type":"cloud_hosting_backend","summary":"DOJ seized a cloud-computing account alleged to host backend infrastructure used by Huione Group subsidiaries to facilitate laundering of proceeds from cyber-scam operations.","technical_outcome":"Cloud-computing account and associated backend infrastructure seized.","later_status":null,"legal_mechanism":"US seizure warrant.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":["Notable because the action targeted a cloud-hosting account rather than a conventional public-facing domain."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_socksescort","slug":"socksescort-proxy-network-disruption","record_kind":"incident","name":"SocksEscort proxy network disruption","aliases":[],"started_on":"2026-03-11","ended_on":"2026-03-11","announced_on":"2026-03-12","activity_type":"criminal_hosting_proxy","secondary_activity_types":[],"target_name":"SocksEscort","target_type":"residential_proxy_botnet","summary":"A US DOJ-led international operation seized several dozen US-registered domains belonging to SocksEscort, a residential-proxy network exploiting home routers and facilitating fraud.","technical_outcome":"Several dozen domains seized. 34 domains and 23 servers seized/taken down across seven countries per Europol","later_status":null,"legal_mechanism":"Court-authorized international action; federal seizure warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_leakbase","slug":"leakbase-seizure","record_kind":"incident","name":"LeakBase seizure","aliases":[],"started_on":"2026-03-03","ended_on":"2026-03-04","announced_on":"2026-03-04","activity_type":"fraud_stolen_data","secondary_activity_types":[],"target_name":"LeakBase","target_type":"stolen_data_marketplace","summary":"DOJ/FBI seized LeakBase, a stolen-data marketplace, preserving user accounts, posts, private messages, and IP logs as evidence.","technical_outcome":"Site infrastructure and database seized.","later_status":null,"legal_mechanism":"Federal seizure warrant.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_aisuru_family","slug":"aisuru-kimwolf-jackskid-mossad-iot-ddos-botnet-disruption","record_kind":"incident","name":"Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption","aliases":[],"started_on":"2026-03-19","ended_on":"2026-03-19","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Aisuru, KimWolf, JackSkid, and Mossad IoT DDoS botnets","target_type":"iot_ddos_botnet","summary":"US, German, Canadian, Dutch, and private-sector partners disrupted command-and-control infrastructure associated with four related IoT DDoS botnets.","technical_outcome":"C2 infrastructure disrupted across multiple related botnet families.","later_status":"Jacob Butler, alleged administrator of the KimWolf component, was charged in the District of Alaska on 2026-04-10 and arrested in Canada on 2026-05-20 pursuant to an extradition warrant. The complaint was unsealed May 21; extradition/prosecution remained pending at the cutoff.","legal_mechanism":"Coordinated national judicial/search-and-seizure authority; USAO Alaska-led US component.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_poweroff_apr_offsides","slug":"poweroff-eight-domain-action-april-2026-usao-alaska-wave","record_kind":"incident_component","name":"PowerOFF eight-domain action (April 2026, USAO Alaska wave)","aliases":[],"started_on":"2026-04-16","ended_on":"2026-04-16","announced_on":null,"activity_type":"ddos_for_hire","secondary_activity_types":[],"target_name":"Eight DDoS-for-hire booter domains","target_type":"ddos_for_hire_platform","summary":"USAO Alaska and partner agencies seized eight domains as part of the recurring Operation PowerOFF campaign against DDoS-for-hire services.","technical_outcome":"Eight domains seized.","later_status":null,"legal_mechanism":"Federal seizure warrants.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"unknown","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":["This appears to be a distinct US-domestic wave reported alongside the larger 2026-04-13 Europol-coordinated 53-domain/21-country PowerOFF wave already recorded as td_2026_poweroff_apr; recorded separately here pending confirmation of whether these are the same action reported with different domain counts by different sources or genuinely separate waves."],"parent_reference_id":"um_operation_poweroff","parent_slug":"operation-poweroff"},{"reference_id":"td_2018_backpage","slug":"backpage-com-seizure","record_kind":"incident","name":"Backpage.com seizure","aliases":[],"started_on":"2018-04-06","ended_on":"2018-04-06","announced_on":null,"activity_type":"trafficking_exploitation","secondary_activity_types":[],"target_name":"Backpage.com","target_type":"classified_ads_platform","summary":"DOJ/FBI seized Backpage.com, a classified-advertising platform DOJ alleged was used to facilitate prostitution and sex trafficking, and indicted founders and executives.","technical_outcome":"Site infrastructure and domains seized; replaced with a law-enforcement seizure notice.","later_status":"Michael Lacey was sentenced to 60 months, Scott Spear to 120 months, and John “Jed” Brunst to 120 months on 2024-08-28. Carl Ferrer and Dan Hyer had pleaded guilty; Hyer was later sentenced to time served in September 2025. James Larkin died before trial. Appeals and forfeiture proceedings continued.","legal_mechanism":"Federal indictment; seizure warrant.","geographic_scope":[],"reported_charged_count":7,"reported_apprehended_count":null,"reported_convicted_count":5,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Founders and senior executives were indicted and prosecuted.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2018_3ve","slug":"3ve-ad-fraud-botnet-disruption","record_kind":"incident","name":"3ve ad-fraud botnet disruption","aliases":[],"started_on":"2018-11-27","ended_on":"2018-11-27","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"3ve (\"Eve\")","target_type":"ad_fraud_botnet","summary":"DOJ/FBI, working with a coalition of technology and security companies including Google, White Ops, and others, disrupted the 3ve digital-advertising-fraud botnet and unsealed related indictments.","technical_outcome":"Botnet C2 and fraudulent ad-traffic infrastructure disrupted; sinkholing conducted with private-sector partners.","later_status":null,"legal_mechanism":"Federal indictment; coordinated technical sinkholing operation.","geographic_scope":[],"reported_charged_count":8,"reported_apprehended_count":3,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":null,"resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2026_gru_router_network","slug":"gru-dns-hijacking-router-network-disruption-apt28","record_kind":"incident","name":"GRU DNS-hijacking router network disruption (APT28)","aliases":[],"started_on":"2026-04-07","ended_on":"2026-04-07","announced_on":"2026-04-07","activity_type":"state_sponsored","secondary_activity_types":[],"target_name":"GRU Military Unit 26165 SOHO router network","target_type":"state_sponsored_botnet","summary":"DOJ/FBI national-security cyber investigators conducted a court-authorized technical operation neutralizing the US portion of a GRU Military Unit 26165 network of compromised SOHO routers used to redirect DNS traffic to GRU-controlled resolvers.","technical_outcome":"US-based component of the router network neutralized; operation explicitly limited to infrastructure within US judicial reach.","later_status":null,"legal_mechanism":"Court-authorized technical operation (Rule 41-type warrant).","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"not_applicable","completeness_basis":"State-sponsored operation; action was explicitly scoped to infrastructure within US jurisdiction rather than a personnel-capture effort.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2020_cityxguide","slug":"cityxguide-seizure","record_kind":"incident","name":"CityXGuide seizure","aliases":[],"started_on":"2020-06-19","ended_on":"2020-06-19","announced_on":"2020-06-19","activity_type":"trafficking_exploitation","secondary_activity_types":[],"target_name":"CityXGuide","target_type":"classified_ads_platform","summary":"US federal investigators seized CityXGuide, a classified-advertising site used to facilitate prostitution and sex trafficking, and charged its owner.","technical_outcome":"Site infrastructure seized and taken offline.","later_status":"Wilhan Martono pleaded guilty on 2021-08-24 and was sentenced on 2022-11-14 to 97 months in prison and forfeiture exceeding USD 15 million. DOJ releases conflict on whether his arrest occurred June 17 or June 19, 2020.","legal_mechanism":"Federal seizure warrant; 28-count federal indictment (N.D. Tex.)","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Sole named owner/operator was charged.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2017_btc_e","slug":"btc-e-disruption","record_kind":"incident","name":"BTC-e disruption","aliases":[],"started_on":"2017-07-25","ended_on":"2017-07-25","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"BTC-e","target_type":"cryptocurrency_exchange","summary":"US DOJ/FBI/IRS and international partners dismantled the BTC-e cryptocurrency exchange while alleged operator Alexander Vinnik was arrested in Greece; criminal money-laundering and unlicensed-money-service charges followed.","technical_outcome":"Exchange infrastructure disabled.","later_status":"Alexander Vinnik pleaded guilty on 2024-05-03. Before sentencing, the United States released him in a prisoner exchange; he arrived in Moscow on 2025-02-13.","legal_mechanism":"Federal criminal indictment; Greek arrest warrant at US request.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Sole named principal operator arrested, extradited (to France, then repatriated), and ultimately convicted in US proceedings.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_bitzlato","slug":"bitzlato-operation-cryptostorm","record_kind":"incident","name":"Bitzlato / Operation Cryptostorm","aliases":[],"started_on":"2023-01-18","ended_on":"2023-01-18","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"Bitzlato","target_type":"cryptocurrency_exchange","summary":"French authorities dismantled Bitzlato's digital infrastructure while US and European partners seized cryptocurrency and other assets; founder Anatoly Legkodymov was charged with operating an unlicensed money-transmitting business and arrested in Miami.","technical_outcome":"Digital infrastructure dismantled in France; assets seized.","later_status":"Anatoly Legkodymov pleaded guilty on 2023-12-06 to operating an unlicensed money-transmitting business and agreed to dissolve Bitzlato and relinquish claims to approximately USD 23 million in seized assets. No later official sentencing release was located in this pass.","legal_mechanism":"French judicial process; US federal criminal complaint.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Sole named founder charged and arrested; later pleaded guilty.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2022_z_library","slug":"z-library-domain-seizure","record_kind":"incident","name":"Z-Library domain seizure","aliases":[],"started_on":"2022-11-03","ended_on":"2022-11-16","announced_on":null,"activity_type":"piracy_ip","secondary_activity_types":[],"target_name":"Z-Library","target_type":"piracy_website","summary":"FBI (E.D.N.Y.), with Argentine authorities and DOJ/CCIPS support, seized approximately 249 interrelated Z-Library domains and charged two Russian nationals with criminal copyright infringement, wire fraud, and money laundering.","technical_outcome":"Approximately 249 interrelated domains seized.","later_status":null,"legal_mechanism":"Federal seizure warrant (E.D.N.Y.); criminal complaint.","geographic_scope":[],"reported_charged_count":2,"reported_apprehended_count":2,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Both named alleged operators charged and arrested in a coordinated action.","resurgence_class":null,"confidence":null,"notes":["Z-Library reportedly continued through replacement infrastructure after this action; treated here as a known regeneration case pending a linked resurgence record with a confirmed subsequent seizure date."],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2023_kingdom_market","slug":"kingdom-market-seizure","record_kind":"incident","name":"Kingdom Market seizure","aliases":[],"started_on":"2023-12-01","ended_on":"2023-12-01","announced_on":null,"activity_type":"darknet_market","secondary_activity_types":[],"target_name":"Kingdom Market","target_type":"darknet_market","summary":"FBI/HSI and US prosecutors, with international partners, shut Kingdom Market's online infrastructure; official filings described more than 25,000 illicit listings. Alleged administrator Alan Bill was arrested in Newark, New Jersey.","technical_outcome":"Online infrastructure shut down.","later_status":"Alan Bill was arrested on 2023-12-15, pleaded guilty on 2026-01-27, and was sentenced on 2026-05-07 (announced May 8) to 200 months in prison.","legal_mechanism":"Federal indictment; seizure process.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":"More than 25,000 illicit listings reported.","group_completeness":"partial","completeness_basis":"Sole named alleged administrator arrested; broader vendor population not addressed.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2015_dridex","slug":"dridex-bugat-cridex-disruption","record_kind":"incident","name":"Dridex/Bugat/Cridex disruption","aliases":[],"started_on":"2015-10-13","ended_on":"2015-10-13","announced_on":null,"activity_type":"botnet_malware","secondary_activity_types":[],"target_name":"Dridex (also known as Bugat/Cridex)","target_type":"banking_trojan_botnet","summary":"FBI/DOJ and UK NCA, with international partners, sinkholed and disrupted infrastructure for the Dridex banking-malware botnet; alleged administrator Andrey Ghinkul was federally charged and arrested in Cyprus at US request.","technical_outcome":"Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.","later_status":"Andrey Ghinkul was extradited from Cyprus to the United States in February 2016, pleaded guilty on 2017-02-08, and was sentenced on 2018-12-06 to time served.","legal_mechanism":"Federal criminal charges; civil restraining order/injunction; UK technical action.","geographic_scope":[],"reported_charged_count":1,"reported_apprehended_count":1,"reported_convicted_count":1,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"partial","completeness_basis":"Sole named alleged administrator charged and arrested; the Dridex family and related operators persisted in later forms.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_samourai_wallet","slug":"samourai-wallet-seizure","record_kind":"incident","name":"Samourai Wallet seizure","aliases":[],"started_on":"2024-04-24","ended_on":"2024-04-24","announced_on":null,"activity_type":"crypto_laundering","secondary_activity_types":[],"target_name":"Samourai Wallet","target_type":"cryptocurrency_mixing_service","summary":"USAO SDNY/IRS-CI/FBI, with Icelandic authorities, arrested the founders of Samourai Wallet, a cryptocurrency-mixing service; Icelandic authorities seized web servers and a US warrant seized domain/app infrastructure.","technical_outcome":"Web servers seized in Iceland; domain/app infrastructure seized in the US.","later_status":"Keonne Rodriguez and William Lonergan Hill pleaded guilty on 2025-07-30. Rodriguez was sentenced on 2025-11-06 to five years; Hill was sentenced on 2025-11-19 to four years. Each also received three years of supervised release and a USD 250,000 fine.","legal_mechanism":"Federal criminal complaint (S.D.N.Y.); US seizure warrant; Icelandic judicial cooperation.","geographic_scope":[],"reported_charged_count":2,"reported_apprehended_count":2,"reported_convicted_count":2,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"likely_complete","completeness_basis":"Both named founders reported arrested; individual names were not established in the source reviewed for this pass, so recorded as an aggregate count rather than placeholder person records.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null},{"reference_id":"td_2024_radar_dispossessor","slug":"radar-dispossessor-ransomware-disruption","record_kind":"incident","name":"Radar/Dispossessor ransomware disruption","aliases":[],"started_on":"2024-08-12","ended_on":"2024-08-12","announced_on":null,"activity_type":"ransomware","secondary_activity_types":[],"target_name":"Radar (also known as Dispossessor)","target_type":"ransomware_group","summary":"FBI Cleveland/DOJ, with UK NCA and German authorities, disabled or seized domains, servers, and IP infrastructure in the US, UK, and Germany connected to the Radar/Dispossessor ransomware group.","technical_outcome":"Domains, servers, and IP infrastructure disabled or seized across three countries.","later_status":null,"legal_mechanism":"Federal seizure warrant; coordinated UK/German judicial authority.","geographic_scope":[],"reported_charged_count":null,"reported_apprehended_count":null,"reported_convicted_count":null,"reported_fugitive_count":null,"estimated_group_size_min":null,"estimated_group_size_max":null,"group_size_basis":null,"group_completeness":"remaining_members","completeness_basis":"The alleged operator, known only by the alias 'Brain,' was identified as believed to be in Europe; no arrest was announced.","resurgence_class":null,"confidence":null,"notes":[],"parent_reference_id":null,"parent_slug":null}]}