Skip to main content
Back to Lumma Stealer disruption

Organizations and roles

May 2025, Malware and botnets
Lumma Stealer disruption

Last reviewed August 21, 2026

The public record puts 5 organizations on this action. Operational lead: Microsoft DCU and DOJ. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.

Why this page names organizations only

Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.

Organizations and roles

Emblem Organization Role What the record says
Microsoft Digital Crimes Unit United States , United States Co-lead Obtained the civil court order and seized or sinkholed approximately 2,300 domains.
United States Department of Justice United States , United States Co-lead Seized the central command structure and the marketplaces selling the malware.
European Cybercrime Centre Coordinator Facilitated suspension of locally based infrastructure in Europe.
Cloudflare United States , United States Technical partner Blocked and disabled associated infrastructure.
Japan Cybercrime Control Center Japan , Japan Supporting Facilitated suspension of Japan-based infrastructure.

Accountability

Legal authority

US civil court order (Northern District of Georgia) plus DOJ criminal seizure process; Europol EC3 and Japan JC3 coordination

Ongoing investigation

Group accounted for: Partial. No arrests or charges accompanied the action, the developer was not apprehended, and the service resumed operating within days.

This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.

Last reviewed August 21, 2026