Skip to main content
Back to the takedown index

Operation PowerOFF

Operation PowerOFF May 2023 wave

May 2023, DDoS for hire
Led by Federal Bureau of Investigation

Source linked. Verified August 23, 2026.

What was taken down?

13 booter domains seized, including cyberstress.org, which DOJ said was the same service previously run at cyberstress.us. The FBI had opened or renewed accounts with each service, paid in cryptocurrency and launched test attacks against FBI-controlled computers before the seizures.[1]

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Partial

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

Court-authorized seizure of 13 DDoS-for-hire domains, announced by the Justice Department on 2023-05-08 as the third wave of US law-enforcement action against booter services. The FBI said ten of the 13 were reincarnations of services taken down in the December 2022 sweep of 48 domains. DOJ announced the seizures alongside guilty pleas by four defendants charged in Los Angeles in late 2022.[1]

Announced May 8, 2023.

Date
May 2023
Target
13 booter and stresser services, booter stresser services
Activity
DDoS for hire
Operational lead
FBI
Partners
USAO-CDCA[1]
Jurisdiction
United States
Outcome
13 booter domains seized, including cyberstress.org, which DOJ said was the same service previously run at cyberstress.us. The FBI had opened or renewed accounts with each service, paid in cryptocurrency and launched test attacks against FBI-controlled computers before the seizures.
Status
Completed
Legal mechanism
Court-authorized seizure warrants supported by an affidavit filed in the Central District of California
Group accounted for
Partial

Infrastructure

13 domains seized.

Identifier Recorded as Status Notes
Not published 13 domains Seized, United States 13 booter domains seized under court-authorized seizure warrants. DOJ named one of them, cyberstress.org, and said ten of the 13 were reincarnations of services seized in the December 2022 sweep of 48 domains.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

No operator of the 13 newly seized services was publicly identified in this action.

13 independent services with separate operators; ten of them relaunches of services seized in December 2022.

See the organizations and roles behind this action

DOJ said investigations into booter services remained ongoing and that the four defendants who pleaded guilty were scheduled to be sentenced in summer 2023.[1]

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

What each part of this entry rests on

The audit recorded which sources carry which part of the record. These are those sources.

Official sources

  1. [1]
    Federal Authorities Seize 13 Internet Domains Associated with ‘Booter’ Websites that Offered DDoS Computer Attack Services

    United States Attorney's Office for the Central District of California, May 8, 2023, Source grade P1

    Supporting detail not recorded.

    Open source
Coverage note.
  • DOJ describes this action as 'the third wave of U.S. law enforcement actions against prominent booter services' and states it was taken in conjunction with Operation PowerOFF. The first wave was December 2018 (td_2018_poweroff_dec) and the second December 2022 (td_2022_poweroff_dec).
  • The four guilty pleas DOJ announced on the same day (Jeremiah Sam Evans Miller, Angel Manuel Colon Jr., Shamar Shattock and Cory Anthony Palmer) arise from charges filed in the December 2022 wave and belong to td_2022_poweroff_dec, where those people already exist. They are deliberately not carried here and not counted in this record's reported_convicted_count, to avoid double counting.
  • The existing resurgence record res_poweroff_dec2022_reincarnations describes exactly this relationship and is corrected in this batch to point its subsequent_takedown_id at this record.
  • resurgence_class left null: the A-G scale is undefined in this dataset and was not guessed.