[Back to Dridex/Bugat/Cridex disruption](https://takedownindex.org/takedowns/dridex-bugat-cridex-disruption)

# Organizations and roles

October 2015, Malware and botnets
[Dridex/Bugat/Cridex disruption](https://takedownindex.org/takedowns/dridex-bugat-cridex-disruption)

Last reviewed August 21, 2026

The public record puts 2 organizations on this action. Operational lead: FBI and NCA. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.

## Why this page names organizations only

Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.

## Organizations and roles

| Emblem | Organization | Role | What the record says |
| --- | --- | --- | --- |
| | [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation), United States | Co-lead | Co-led the US side of the operation. |
| | [National Crime Agency](https://takedownindex.org/organizations/national-crime-agency), United Kingdom | Co-lead | Co-led the UK technical disruption. |

## Accountability

### Legal authority

Federal criminal charges; civil restraining order/injunction; UK technical action.

### Ongoing investigation

Group accounted for: Partial. Sole named alleged administrator charged and arrested; the Dridex family and related operators persisted in later forms.

This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.

Last reviewed August 21, 2026
