Skip to main content
Back to the takedown index

Operation PowerOFF

Operation PowerOFF December 2018 wave

December 2018, DDoS for hire
Led by Federal Bureau of Investigation

Source linked. Verified August 23, 2026.

What was taken down?

15 booter domains seized on 2018-12-19, among them critical-boot.com, ragebooter.com, downthem.org and quantumstress.net. The FBI had tested each service before the seizures and verified that the advertised DDoS capability worked.[1][2][3][4]

See what happened

What happened to the people?

Officials reported 3 charged.
3 charged named in the public record.
Group accounted for: Partial

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

The FBI seized the domains of 15 DDoS-for-hire services on 2018-12-19 under seizure warrants issued by the U.S. District Court for the Central District of California, and prosecutors in Los Angeles and Anchorage charged three defendants who ran Downthem, Ampnode and Quantum Stresser. DOJ later described this as the first US law-enforcement action against booter services.[1][2][3][4]

Announced December 20, 2018.

Date
December 2018
Target
15 booter and stresser services, booter stresser services
Activity
DDoS for hire
Operational lead
FBI
Jurisdiction
United States, United Kingdom, and Netherlands
Outcome
15 booter domains seized on 2018-12-19, among them critical-boot.com, ragebooter.com, downthem.org and quantumstress.net. The FBI had tested each service before the seizures and verified that the advertised DDoS capability worked.
Status
Completed
Legal mechanism
Federal seizure warrants issued by the U.S. District Court for the Central District of California; criminal complaints filed in the Central District of California and the District of Alaska
Group accounted for
Partial

Infrastructure

15 domains seized.

Identifier Recorded as Status Notes
Not published 15 domains Seized, United States 15 booter and stresser domains seized by the FBI on 2018-12-19 under seizure warrants issued by the U.S. District Court for the Central District of California. DOJ named four of them: critical-boot.com, ragebooter.com, downthem.org and quantumstress.net.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

3
charged

Named in the public record: 3 charged.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 3 charged. 3 charged named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.
Person Role Current public status
Alleged operator of the Quantum Stresser booter service Charged
Charging authority
United States Attorney's Office for the District of Alaska
Main charges
Aiding and abetting computer intrusions
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Segment not established
Sources
[1][2]
Alleged co-operator of the Downthem and Ampnode services ChargedSentenced
Charging authority
United States Attorney's Office for the Central District of California
Main charges
Conspiring to violate the Computer Fraud and Abuse Act; Unauthorized impairment of protected computers, damage affecting 10 or more protected computers during any 1-year period; aiding and abetting
Case number
2:19-cr-00036
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Five years probation
Segment
Segment not established
Sources
[1][3]
Alleged operator of the Downthem DDoS-for-hire service and the Ampnode attack-infrastructure service ChargedSentenced
Charging authority
United States Attorney's Office for the Central District of California
Main charges
Conspiring to violate the Computer Fraud and Abuse Act; Conspiracy; Unauthorized impairment of protected computers, damage affecting 10 or more protected computers during any 1-year period; aiding and abetting
Case number
2:19-cr-00036
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
24 months imprisonment on Counts 1 and 3, to run concurrently, followed by three years of supervised release
Segment
Segment not established
Sources
[1][4]

David Bukoski

Alleged operator of the Quantum Stresser booter service. Current public status: Charged.

Charging authority
United States Attorney's Office for the District of Alaska
Main charges
Aiding and abetting computer intrusions
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Segment not established
Sources
[1][2]

Juan Martinez

Alleged co-operator of the Downthem and Ampnode services. Current public status: Charged and Sentenced.

Charging authority
United States Attorney's Office for the Central District of California
Main charges
Conspiring to violate the Computer Fraud and Abuse Act; Unauthorized impairment of protected computers, damage affecting 10 or more protected computers during any 1-year period; aiding and abetting
Case number
2:19-cr-00036
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Five years probation
Segment
Segment not established
Sources
[1][3]

Matthew Gatrel

Alleged operator of the Downthem DDoS-for-hire service and the Ampnode attack-infrastructure service. Current public status: Charged and Sentenced.

Charging authority
United States Attorney's Office for the Central District of California
Main charges
Conspiring to violate the Computer Fraud and Abuse Act; Conspiracy; Unauthorized impairment of protected computers, damage affecting 10 or more protected computers during any 1-year period; aiding and abetting
Case number
2:19-cr-00036
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
24 months imprisonment on Counts 1 and 3, to run concurrently, followed by three years of supervised release
Segment
Segment not established
Sources
[1][4]

Rows expand to show charging authority, case identifiers, custody status, and sources.

Group accounted for: Partial

Three defendants charged against 15 seized services, so most operators were not publicly accounted for.

15 independent services with separate operators.

See the organizations and roles behind this action

Matthew Gatrel and Juan Martinez were prosecuted in United States v. Gatrel, No. 2:19-cr-00036-JAK (C.D. Cal.). Martinez was convicted on Count 3 and sentenced on 2021-12-09 to five years of probation; Gatrel was convicted on Counts 1 and 3 and sentenced on 2022-06-13 to 24 months in prison plus three years of supervised release. The outcome of the District of Alaska case against David Bukoski was not established from the sources located.[1][2][3][4]

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

What each part of this entry rests on

The audit recorded which sources carry which part of the record. These are those sources.

Official sources

  1. [1]
    Criminal Charges Filed in Los Angeles and Alaska in Conjunction with Seizures Of 15 Websites Offering DDoS-For-Hire Services

    United States Department of Justice, December 20, 2018, Source grade P1

    Supporting detail not recorded.

    Open source
  2. [2]
    Criminal Charges Filed in Alaska in Conjunction with the Seizure of Websites Offering DDoS-For-Hire Services

    United States Attorney's Office for the District of Alaska, December 20, 2018, Source grade P1

    Supporting detail not recorded.

    Open source
  3. [3]
    Judgment and Probation/Commitment Order as to Juan Martinez, United States v. Gatrel, No. 2:19-cr-00036-JAK (C.D. Cal.), Dkt. 266

    United States District Court for the Central District of California, December 13, 2021, Source grade P0

    Supporting detail not recorded.

    Open source
  4. [4]
    Judgment and Probation/Commitment Order as to Matthew Gatrel, United States v. Gatrel, No. 2:19-cr-00036-JAK (C.D. Cal.), Dkt. 315

    United States District Court for the Central District of California, June 13, 2022, Source grade P0

    Supporting detail not recorded.

    Open source
Coverage note.
  • The December 2018 DOJ release does not itself use the name Operation PowerOFF. The May 2023 DOJ release, which states that its own action was taken in conjunction with Operation PowerOFF, describes the late-2018 action as the first law-enforcement action in the same series: 'In the first law enforcement action targeting booters in late 2018, the Justice Department charged three defendants who facilitated DDoS-for hire services and seized 15 internet domains'. The parent link rests on that.
  • This is the wave the corpus's own coverage-gap note about a 'PowerOFF 2019' US wave was really referring to; no 2019 US wave was found in the DOJ press-release index.
  • reported_convicted_count left null: no authority published an aggregate conviction figure for this wave. The two convictions are carried as person_actions sourced to the court judgments.
  • DOJ credited assistance from the U.S. Attorney's Offices for the Eastern and Middle Districts of Pennsylvania, the Western District of Tennessee and the Northern District of Illinois, and from the National Cyber-Forensics and Training Alliance. Those bodies have no organization ids in this corpus and no role rows were invented for them.
  • resurgence_class left null: the A-G scale is undefined in this dataset and was not guessed.