Public record database

# Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions

Last reviewed August 20, 2026

Filters

| Takedown | Date | Category | Lead organization | Jurisdiction | Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column. |
| --- | --- | --- | --- | --- | --- |
| [Operation Offsides (2026 FIFA World Cup streaming domains)](https://takedownindex.org/takedowns/operation-offsides-2026-fifa-world-cup-streaming-domains)ID: td\_2026\_operation\_offsides | Jul 20, 2026 | Piracy and IP | ICE-HSI and IPR Center | Not established | Completed |
| [Huione Group backend infrastructure seizure](https://takedownindex.org/takedowns/huione-group-backend-infrastructure-seizure)ID: td\_2026\_huione\_backend | Jun 23, 2026 | Cryptocurrency laundering | FBI | Not established | Completed |
| [CFAKE.com and SOCFAKE.com seizure](https://takedownindex.org/takedowns/cfake-com-and-socfake-com-seizure)ID: td\_2026\_cfake\_socfake | Jun 12, 2026 | Child sexual abuse material | HSI | Not established | Completed |
| [PowerOFF eight-domain action (April 2026, USAO Alaska wave)](https://takedownindex.org/takedowns/poweroff-eight-domain-action-april-2026-usao-alaska-wave)ID: td\_2026\_poweroff\_apr\_offsides | Apr 16, 2026 | DDoS for hire | USAO-AK | Not established | Completed |
| [Operation PowerOFF April 2026 wave](https://takedownindex.org/takedowns/operation-poweroff-april-2026-wave)ID: td\_2026\_poweroff\_apr | Apr 13, 2026 | DDoS for hire | Not established | International | Completed |
| [GRU DNS-hijacking router network disruption (APT28)](https://takedownindex.org/takedowns/gru-dns-hijacking-router-network-disruption-apt28)ID: td\_2026\_gru\_router\_network | Apr 1, 2026 | State sponsored | FBI | Not established | Completed |
| [Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption](https://takedownindex.org/takedowns/aisuru-kimwolf-jackskid-mossad-iot-ddos-botnet-disruption)ID: td\_2026\_aisuru\_family | Mar 19, 2026 | Malware and botnets | USAO-AK and FBI | Not established | Completed |
| [LeakBase seizure](https://takedownindex.org/takedowns/leakbase-seizure)ID: td\_2026\_leakbase | Mar 4, 2026 | Fraud and stolen data | FBI | Not established | Completed |
| [SocksEscort proxy network disruption](https://takedownindex.org/takedowns/socksescort-proxy-network-disruption)ID: td\_2026\_socksescort | Mar 1, 2026 | Criminal hosting and proxies | FBI | Not established | Completed |
| [Red Card 2.0](https://takedownindex.org/takedowns/red-card-2-0)ID: td\_2026\_red\_card\_2 | Feb 18, 2026 | Fraud and stolen data | INTERPOL | Not established | Completed |
| [Operation Endgame wave 3](https://takedownindex.org/takedowns/operation-endgame-wave-3)ID: td\_2025\_endgame\_w3 | Nov 10, 2025 | Multi threat campaign | Not established | International | Completed |
| [Serengeti 2.0](https://takedownindex.org/takedowns/serengeti-2-0)ID: td\_2025\_serengeti\_2 | Aug 22, 2025 | Fraud and stolen data | INTERPOL and AFRIPOL | Not established | Completed |
| [INTERPOL Synergia III](https://takedownindex.org/takedowns/interpol-synergia-iii)ID: td\_2026\_synergia\_iii | Jul 18, 2025 | Multi threat campaign | INTERPOL | Not established | Completed |
| [INTERPOL Operation Secure](https://takedownindex.org/takedowns/interpol-operation-secure)ID: td\_2025\_operation\_secure | Jun 11, 2025 | Malware and botnets | INTERPOL | Not established | Completed |
| [Operation Deep Sentinel](https://takedownindex.org/takedowns/operation-deep-sentinel)ID: td\_2025\_archetyp | Jun 11, 2025 | Darknet market | BKA | International | Completed |
| [Operation Endgame wave 2](https://takedownindex.org/takedowns/operation-endgame-wave-2)ID: td\_2025\_endgame\_w2 | May 19, 2025 | Multi threat campaign | BKA | International | Completed |
| [Lumma Stealer disruption](https://takedownindex.org/takedowns/lumma-stealer-disruption)ID: td\_2025\_lumma | May 13, 2025 | Malware and botnets | Microsoft DCU and DOJ | International | Completed |
| [Operation Stream / Kidflix](https://takedownindex.org/takedowns/operation-stream-kidflix)ID: td\_2025\_kidflix | Apr 2, 2025 | Child sexual abuse material | BKA | Not established | Completed |
| [Garantex disruption](https://takedownindex.org/takedowns/garantex-disruption)ID: td\_2025\_garantex | Mar 7, 2025 | Cryptocurrency laundering | USSS | Not established | Completed |
| [Phobos/8Base ransomware disruption](https://takedownindex.org/takedowns/phobos-8base-ransomware-disruption)ID: td\_2025\_phobos\_8base | Feb 10, 2025 | Ransomware | Not established | Not established | Completed |
| [Cracked and Nulled forums takedown](https://takedownindex.org/takedowns/cracked-and-nulled-forums-takedown)ID: td\_2025\_cracked\_nulled | Jan 30, 2025 | Criminal hosting and proxies | FBI | Not established | Completed |
| [HeartSender takedown](https://takedownindex.org/takedowns/heartsender-takedown)ID: td\_2025\_heartsender | Jan 30, 2025 | Fraud and stolen data | FBI | Not established | Completed |
| [BreachForums portal seizure (2025)](https://takedownindex.org/takedowns/breachforums-portal-seizure-2025)ID: td\_2025\_breachforums | Jan 1, 2025 | Fraud and stolen data | Not established | International | Ongoing |
| [Matrix encrypted messaging service takedown](https://takedownindex.org/takedowns/matrix-encrypted-messaging-service-takedown)ID: td\_2024\_matrix | Dec 3, 2024 | Criminal communications | French Gendarmerie and Dutch National Police | Not established | Completed |
| [Operation PowerOFF December 2024 wave](https://takedownindex.org/takedowns/operation-poweroff-december-2024-wave)ID: td\_2024\_poweroff\_dec | Dec 1, 2024 | DDoS for hire | Not established | International | Completed |

Showing 1 to 25 of 104 takedowns

Rows per page102550

104 results

July 2026

[Operation Offsides (2026 FIFA World Cup streaming domains)](https://takedownindex.org/takedowns/operation-offsides-2026-fifa-world-cup-streaming-domains)

More than 1,000 unauthorized World Cup streaming domains Piracy and IP

**Lead:** ICE-HSI and IPR Center

**Result:** More than 1,000 domains seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

June 2026

[Huione Group backend infrastructure seizure](https://takedownindex.org/takedowns/huione-group-backend-infrastructure-seizure)

Huione Group money-laundering backend Cryptocurrency laundering

**Lead:** FBI

**Result:** Cloud-computing account and associated backend infrastructure seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[CFAKE.com and SOCFAKE.com seizure](https://takedownindex.org/takedowns/cfake-com-and-socfake-com-seizure)

CFAKE.com and SOCFAKE.com Child sexual abuse material

**Lead:** HSI

**Result:** Domains seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

April 2026

[Operation PowerOFF](https://takedownindex.org/takedowns/poweroff-eight-domain-action-april-2026-usao-alaska-wave)

Eight DDoS-for-hire booter domains DDoS for hire

**Lead:** USAO-AK

**Result:** Eight domains seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[Operation PowerOFF](https://takedownindex.org/takedowns/operation-poweroff-april-2026-wave)

53 booter and stresser domains DDoS for hire

**Lead:** Not established

**Result:** 53 domains seized; more than three million criminal accounts exposed; more than 75,000 warning messages sent to users.

**Accountability:** 4 apprehended

**Return status:** Not established in the public record

[GRU DNS-hijacking router network disruption (APT28)](https://takedownindex.org/takedowns/gru-dns-hijacking-router-network-disruption-apt28)

GRU Military Unit 26165 SOHO router network State sponsored

**Lead:** FBI

**Result:** US-based component of the router network neutralized; operation explicitly limited to infrastructure within US judicial reach.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

March 2026

[Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption](https://takedownindex.org/takedowns/aisuru-kimwolf-jackskid-mossad-iot-ddos-botnet-disruption)

Aisuru, KimWolf, JackSkid, and Mossad IoT DDoS botnets Malware and botnets

**Lead:** USAO-AK and FBI

**Result:** C2 infrastructure disrupted across multiple related botnet families.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[LeakBase seizure](https://takedownindex.org/takedowns/leakbase-seizure)

LeakBase Fraud and stolen data

**Lead:** FBI

**Result:** Site infrastructure and database seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[SocksEscort proxy network disruption](https://takedownindex.org/takedowns/socksescort-proxy-network-disruption)

SocksEscort Criminal hosting and proxies

**Lead:** FBI

**Result:** Several dozen domains seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

February 2026

[Red Card 2.0](https://takedownindex.org/takedowns/red-card-2-0)

Cross-border online fraud infrastructure Fraud and stolen data

**Lead:** INTERPOL

**Result:** Fraud-related infrastructure disrupted across participating countries.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

November 2025

[Operation Endgame](https://takedownindex.org/takedowns/operation-endgame-wave-3)

Rhadamanthys, VenomRAT, Elysium botnet Multi threat campaign

**Lead:** Not established

**Result:** More than 1,000 servers disrupted; approximately 20 domains seized; access to several hundred thousand infected machines removed from operators.

**Accountability:** 1 apprehended

**Return status:** Not established in the public record

August 2025

[Serengeti 2.0](https://takedownindex.org/takedowns/serengeti-2-0)

Fraud infrastructure across 18 African countries Fraud and stolen data

**Lead:** INTERPOL and AFRIPOL

**Result:** More than 11,000 malicious infrastructures disrupted.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

July 2025

[INTERPOL Synergia III](https://takedownindex.org/takedowns/interpol-synergia-iii)

Heterogeneous malicious infrastructure Multi threat campaign

**Lead:** INTERPOL

**Result:** Approximately 45,000 malicious IPs targeted for disruption or takedown across the campaign period.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

June 2025

[INTERPOL Operation Secure](https://takedownindex.org/takedowns/interpol-operation-secure)

Infostealer malware infrastructure (26-country action) Malware and botnets

**Lead:** INTERPOL

**Result:** More than 20,000 malicious IPs/domains taken down; 41 servers seized.

**Accountability:** 32 apprehended

**Return status:** Not established in the public record

[Operation Deep Sentinel](https://takedownindex.org/takedowns/operation-deep-sentinel)

Archetyp Market Darknet market

**Lead:** BKA

**Result:** Server infrastructure seized by Dutch police; marketplace taken offline and replaced with seizure notice; approximately 7.8 million EUR in assets seized.

**Accountability:** 8 apprehended

**Return status:** Later activity recorded, link to the original not established

May 2025

[Operation Endgame](https://takedownindex.org/takedowns/operation-endgame-wave-2)

DanaBot, Bumblebee, Lactrodectus, Qakbot, HijackLoader, Trickbot, Warmcookie Multi threat campaign

**Lead:** BKA

**Result:** Approximately 300 servers disrupted worldwide; roughly 650 domains neutralized; approximately 3.5 million EUR in cryptocurrency seized during the wave.

**Accountability:** 3 charged and 1 publicly wanted

**Return status:** Not established in the public record

[Lumma Stealer disruption](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Lumma Stealer Malware and botnets

**Lead:** Microsoft DCU and DOJ

**Result:** Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.

**Accountability:** No individual outcomes recorded

**Return status:** Returned under the same operators

April 2025

[Operation Stream / Kidflix](https://takedownindex.org/takedowns/operation-stream-kidflix)

Kidflix Child sexual abuse material

**Lead:** BKA

**Result:** Server infrastructure and extensive evidentiary material seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

March 2025

[Garantex disruption](https://takedownindex.org/takedowns/garantex-disruption)

Garantex Cryptocurrency laundering

**Lead:** USSS

**Result:** Domains seized by US authorities; parallel infrastructure/fund actions in Germany and Finland.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

February 2025

[Phobos/8Base ransomware disruption](https://takedownindex.org/takedowns/phobos-8base-ransomware-disruption)

Phobos and 8Base Ransomware

**Lead:** Not established

**Result:** More than 100 servers disrupted.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

January 2025

[Cracked and Nulled forums takedown](https://takedownindex.org/takedowns/cracked-and-nulled-forums-takedown)

Cracked and Nulled Criminal hosting and proxies

**Lead:** FBI

**Result:** Forum infrastructure seized; sites taken offline.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[HeartSender takedown](https://takedownindex.org/takedowns/heartsender-takedown)

HeartSender ("Saim Raza") Fraud and stolen data

**Lead:** FBI

**Result:** 39 domains and associated servers seized.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[BreachForums portal seizure (2025)](https://takedownindex.org/takedowns/breachforums-portal-seizure-2025)

BreachForums (further reconstituted) Fraud and stolen data

**Lead:** Not established

**Result:** Portal infrastructure seized and replaced with a law-enforcement notice.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

December 2024

[Matrix encrypted messaging service takedown](https://takedownindex.org/takedowns/matrix-encrypted-messaging-service-takedown)

Matrix Criminal communications

**Lead:** French Gendarmerie and Dutch National Police

**Result:** Server infrastructure seized; service taken offline.

**Accountability:** No individual outcomes recorded

**Return status:** Not established in the public record

[Operation PowerOFF](https://takedownindex.org/takedowns/operation-poweroff-december-2024-wave)

27 booter and stresser platforms DDoS for hire

**Lead:** Not established

**Result:** 27 platforms taken offline and domains seized.

**Accountability:** 3 apprehended

**Return status:** Not established in the public record

[Previous](https://takedownindex.org/takedowns.md?page=1)Page 1 of 5[Next](https://takedownindex.org/takedowns.md?page=2)

## Filters

Filter takedowns
