More than 1,000 unauthorized World Cup streaming domains Piracy and IP
- Lead
- ICE-HSI and IPR Center
- Result
- More than 1,000 domains seized.
- Accountability
- No individual outcomes recorded
- Return status
- Not established in the public record
Public record database
The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.
| Takedown | Date | Category | Lead organization | Jurisdiction | Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column. |
|---|---|---|---|---|---|
| Operation Offsides (2026 FIFA World Cup streaming domains) ID: td_2026_operation_offsides | Jul 20, 2026 | Piracy and IP | ICE-HSI and IPR Center | Not established | Completed |
| Huione Group backend infrastructure seizure ID: td_2026_huione_backend | Jun 23, 2026 | Cryptocurrency laundering | FBI | Not established | Completed |
| CFAKE.com and SOCFAKE.com seizure ID: td_2026_cfake_socfake | Jun 12, 2026 | Child sexual abuse material | HSI | Not established | Completed |
| PowerOFF eight-domain action (April 2026, USAO Alaska wave) ID: td_2026_poweroff_apr_offsides | Apr 16, 2026 | DDoS for hire | USAO-AK | Not established | Completed |
| Operation PowerOFF April 2026 wave ID: td_2026_poweroff_apr | Apr 13, 2026 | DDoS for hire | Not established | International | Completed |
| GRU DNS-hijacking router network disruption (APT28) ID: td_2026_gru_router_network | Apr 1, 2026 | State sponsored | FBI | Not established | Completed |
| Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption ID: td_2026_aisuru_family | Mar 19, 2026 | Malware and botnets | USAO-AK and FBI | Not established | Completed |
| LeakBase seizure ID: td_2026_leakbase | Mar 4, 2026 | Fraud and stolen data | FBI | Not established | Completed |
| SocksEscort proxy network disruption ID: td_2026_socksescort | Mar 1, 2026 | Criminal hosting and proxies | FBI | Not established | Completed |
| Red Card 2.0 ID: td_2026_red_card_2 | Feb 18, 2026 | Fraud and stolen data | INTERPOL | Not established | Completed |
| Operation Endgame wave 3 ID: td_2025_endgame_w3 | Nov 10, 2025 | Multi threat campaign | Not established | International | Completed |
| Serengeti 2.0 ID: td_2025_serengeti_2 | Aug 22, 2025 | Fraud and stolen data | INTERPOL and AFRIPOL | Not established | Completed |
| INTERPOL Synergia III ID: td_2026_synergia_iii | Jul 18, 2025 | Multi threat campaign | INTERPOL | Not established | Completed |
| INTERPOL Operation Secure ID: td_2025_operation_secure | Jun 11, 2025 | Malware and botnets | INTERPOL | Not established | Completed |
| Operation Deep Sentinel ID: td_2025_archetyp | Jun 11, 2025 | Darknet market | BKA | International | Completed |
| Operation Endgame wave 2 ID: td_2025_endgame_w2 | May 19, 2025 | Multi threat campaign | BKA | International | Completed |
| Lumma Stealer disruption ID: td_2025_lumma | May 13, 2025 | Malware and botnets | Microsoft DCU and DOJ | International | Completed |
| Operation Stream / Kidflix ID: td_2025_kidflix | Apr 2, 2025 | Child sexual abuse material | BKA | Not established | Completed |
| Garantex disruption ID: td_2025_garantex | Mar 7, 2025 | Cryptocurrency laundering | USSS | Not established | Completed |
| Phobos/8Base ransomware disruption ID: td_2025_phobos_8base | Feb 10, 2025 | Ransomware | Not established | Not established | Completed |
| Cracked and Nulled forums takedown ID: td_2025_cracked_nulled | Jan 30, 2025 | Criminal hosting and proxies | FBI | Not established | Completed |
| HeartSender takedown ID: td_2025_heartsender | Jan 30, 2025 | Fraud and stolen data | FBI | Not established | Completed |
| BreachForums portal seizure (2025) ID: td_2025_breachforums | Jan 1, 2025 | Fraud and stolen data | Not established | International | Ongoing |
| Matrix encrypted messaging service takedown ID: td_2024_matrix | Dec 3, 2024 | Criminal communications | French Gendarmerie and Dutch National Police | Not established | Completed |
| Operation PowerOFF December 2024 wave ID: td_2024_poweroff_dec | Dec 1, 2024 | DDoS for hire | Not established | International | Completed |
Showing 1 to 25 of 104 takedowns
104 results
July 2026
More than 1,000 unauthorized World Cup streaming domains Piracy and IP
June 2026
Huione Group money-laundering backend Cryptocurrency laundering
CFAKE.com and SOCFAKE.com Child sexual abuse material
April 2026
Eight DDoS-for-hire booter domains DDoS for hire
53 booter and stresser domains DDoS for hire
GRU Military Unit 26165 SOHO router network State sponsored
March 2026
Aisuru, KimWolf, JackSkid, and Mossad IoT DDoS botnets Malware and botnets
LeakBase Fraud and stolen data
SocksEscort Criminal hosting and proxies
February 2026
Cross-border online fraud infrastructure Fraud and stolen data
November 2025
Rhadamanthys, VenomRAT, Elysium botnet Multi threat campaign
August 2025
Fraud infrastructure across 18 African countries Fraud and stolen data
July 2025
Heterogeneous malicious infrastructure Multi threat campaign
June 2025
Infostealer malware infrastructure (26-country action) Malware and botnets
Archetyp Market Darknet market
May 2025
DanaBot, Bumblebee, Lactrodectus, Qakbot, HijackLoader, Trickbot, Warmcookie Multi threat campaign
Lumma Stealer Malware and botnets
April 2025
Kidflix Child sexual abuse material
March 2025
Garantex Cryptocurrency laundering
February 2025
Phobos and 8Base Ransomware
January 2025
Cracked and Nulled Criminal hosting and proxies
HeartSender ("Saim Raza") Fraud and stolen data
BreachForums (further reconstituted) Fraud and stolen data
December 2024
Matrix Criminal communications
27 booter and stresser platforms DDoS for hire
Filter takedowns