Skip to main content

Infrastructure

What law enforcement actually seizes

Domains, servers, wallets, accounts and devices, counted by what the records say was acted on.

Computed from the published tables at the August 23, 2026 research cutoff. Last reviewed August 23, 2026.

"Seized" covers a lot of different objects. The index records 186 individual infrastructure items across 97 takedown records, each with the kind of asset it was and the verb the source attached to it. Read together they show what an enforcement action physically removes, which is rarely the thing the headline implies.

What gets acted on

Asset Items
Domains 59
Servers 53
Command and control 19
Crypto wallets 15
Onion services 14
Malware installations 5
IP addresses 4
Bank accounts 3
Databases 3
User accounts 3
Admin panels 2
Hosting accounts 2
Other 4

Domains and servers together account for most of it. That distinction matters more than it looks: a domain is a registration, and replacing one costs whatever the next registrar charges. A server can hold the panel, the database, the builder and the keys, and taking it means an operator has to rebuild rather than re-point.

What the verb tells you

Action Items
Seized 122
Disabled 24
Taken over 13
Remediated 6
Sinkholed 5
Frozen 4
Searched 4
Blocked 3
Redirected 2
Copied 1
Not established 2

Seizure is the default verb of the corpus by a wide margin. The interesting ones are rarer. A covert takeover means the service kept running under someone else's control for a period before it stopped. Sinkholing redirects infected machines to a controlled server rather than removing anything. Remediation means reaching into devices that belong to victims, which carries a different legal authority from taking a criminal's box.

Counts are not always counts

113 of the 186 items carry a quantity. The other 73 record that something was acted on without the source establishing how much, and those are stored as unknown rather than as one or as zero.

Where a quantity exists it carries a qualifier alongside it, because "48 domains" and "more than 48 domains" are different claims and press releases use both. Only 30 items name the specific asset. The rest are aggregate: a count of servers, not a list of them.

The records with nothing

9 counted incidents record no infrastructure item at all. That does not mean nothing was taken. It means the source documenting the action did not describe the assets in terms this index could record, which happens most often with aggregate multinational sweeps that report a total and move on. Those records are excluded from the counts above rather than scored as zero.

Every figure above is derived from the published tables and can be recomputed from them. Download the data, then read the counting rules and the known limitations before citing any of it.