Coverage

# How international are cybercrime takedowns?

The record spans dozens of jurisdictions, and the shape of that map says as much about publishing habits as about enforcement.

Computed from the published tables at the August 23, 2026 research cutoff. Last reviewed August 23, 2026.

99 jurisdictions appear across the geographic scope of 105 counted incidents, producing 550 country mentions in total. 76 incidents touch more than one country, and only 29 are confined to a single jurisdiction.

That is the headline, and it is true. The rest of this page is about why you should not read it as a map of where enforcement happens.

## Where the record concentrates

| Jurisdiction | Incidents |
| --- | --- |
| US | 75 |
| NL | 44 |
| DE | 43 |
| GB | 36 |
| FR | 25 |
| CA | 19 |
| AU | 18 |
| EU | 15 |

A short list of countries carries most of the record, and they are the countries whose agencies publish detailed releases in English on stable domains. That is the mechanism producing this distribution, and it is not the same mechanism as those countries doing the most enforcement.

## What the map misses

The corpus is built from public sources, so anything not publicly announced cannot enter it. Infrastructure disconnected quietly at police request, provider-compelled shutdowns without a release, and sealed matters are structurally invisible to this method, in every jurisdiction.

Language compounds it. 11 of 413 cited sources are in a language other than English, and national actions are frequently reached through an English-language coordination release rather than the domestic announcement that documents them properly. Actions in Africa, South and Southeast Asia, the Middle East and Latin America appear largely through international sweeps rather than nationally led operations, which understates what those national agencies do on their own.

Source depth runs the same way. Only 53 of the cited sources are court documents. The rest are prosecutor and agency releases, which state conclusions without the underlying evidence, because dockets sit behind fees or national systems that block automated access while press releases are free and indexable.

## The record thins going backwards

5 counted incidents predate 2013, against 59 from 2020 onward. Some of that is real growth in enforcement activity. Much of it is not: pre-2013 releases are frequently delinked and reachable only through archives, so the early record is thin because the sources decayed rather than because less happened. Several well-known actions from that period are absent for exactly this reason, and their absence is documented rather than hidden.

## How to use the geography

Country counts here are safe for describing this corpus and unsafe for describing the world. Saying "99 jurisdictions appear in the Internet Takedown Index" is accurate. Saying a given country leads global cybercrime enforcement, or that another does little, is not something this data can support in either direction.

All 10 of these limitations are recorded in the dataset's own [coverage gaps](https://takedownindex.org/about/coverage-gaps) table, each with the reason it exists and the search that would begin to close it. The same discipline applied to missing values generally is in [unknown is not zero](https://takedownindex.org/research/unknown-is-not-zero).

Every figure above is derived from the published tables and can be recomputed from them. [Download the data](https://takedownindex.org/data), then read the [counting rules](https://takedownindex.org/about/counting-incidents) and the [known limitations](https://takedownindex.org/about/known-limitations) before citing any of it.
