[Back to the takedown index](https://takedownindex.org/takedowns)

[Operation PowerOFF](https://takedownindex.org/takedowns/operation-poweroff)

# Operation PowerOFF May 2023 wave

May 2023, [DDoS for hire](https://takedownindex.org/takedowns/categories/ddos-for-hire)
Led by [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation)

Source linked. Verified August 23, 2026.

What was taken down?

13 booter domains seized, including cyberstress.org, which DOJ said was the same service previously run at cyberstress.us. The FBI had opened or renewed accounts with each service, paid in cryptocurrency and launched test attacks against FBI-controlled computers before the seizures.[[1]](#source-1)

[See what happened](#what-happened)

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Partial

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

Court-authorized seizure of 13 DDoS-for-hire domains, announced by the Justice Department on 2023-05-08 as the third wave of US law-enforcement action against booter services. The FBI said ten of the 13 were reincarnations of services taken down in the December 2022 sweep of 48 domains. DOJ announced the seizures alongside guilty pleas by four defendants charged in Los Angeles in late 2022.[[1]](#source-1)

Announced May 8, 2023.

**Date:** May 2023

**Target:** 13 booter and stresser services, booter stresser services

**Activity:** DDoS for hire

**Operational lead:** FBI

**Partners**

USAO-CDCA[[1]](#source-1)

- [United States Attorney's Office for the Central District of California](https://takedownindex.org/organizations/united-states-attorney-s-office-for-the-central-district-of-california), prosecuting

**Jurisdiction:** United States

**Outcome:** 13 booter domains seized, including cyberstress.org, which DOJ said was the same service previously run at cyberstress.us. The FBI had opened or renewed accounts with each service, paid in cryptocurrency and launched test attacks against FBI-controlled computers before the seizures.

**Status:** Completed

**Legal mechanism:** Court-authorized seizure warrants supported by an affidavit filed in the Central District of California

**Group accounted for:** Partial

### Infrastructure

13 domains seized.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | 13 domains | Seized, United States | 13 booter domains seized under court-authorized seizure warrants. DOJ named one of them, cyberstress.org, and said ten of the 13 were reincarnations of services seized in the December 2022 sweep of 48 domains.[[1]](#source-1) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

No operator of the 13 newly seized services was publicly identified in this action.

13 independent services with separate operators; ten of them relaunches of services seized in December 2022.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/operation-poweroff-may-2023-wave/organizations)

## What happened afterward

DOJ said investigations into booter services remained ongoing and that the four defendants who pleaded guilty were scheduled to be sentenced in summer 2023.[[1]](#source-1)

Not established in the public record. No later activity is recorded against this entry.

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### What each part of this entry rests on

The audit recorded which sources carry which part of the record. These are those sources.

- Identity, dates and counts, [[1]](#source-1) [Federal Authorities Seize 13 Internet Domains Associated with ‘Booter’ Websites that Offered DDoS Computer Attack Services](https://takedownindex.org/sources/united-states-attorney-s-office-for-the-central-district-of-california-federal-a)
- Agencies and roles, [[1]](#source-1) [Federal Authorities Seize 13 Internet Domains Associated with ‘Booter’ Websites that Offered DDoS Computer Attack Services](https://takedownindex.org/sources/united-states-attorney-s-office-for-the-central-district-of-california-federal-a)
- Cases and status, [[1]](#source-1) [Federal Authorities Seize 13 Internet Domains Associated with ‘Booter’ Websites that Offered DDoS Computer Attack Services](https://takedownindex.org/sources/united-states-attorney-s-office-for-the-central-district-of-california-federal-a)

### Official sources

1.
[Federal Authorities Seize 13 Internet Domains Associated with ‘Booter’ Websites that Offered DDoS Computer Attack Services](https://takedownindex.org/sources/united-states-attorney-s-office-for-the-central-district-of-california-federal-a)

United States Attorney's Office for the Central District of California, May 8, 2023, Source grade P1

Supporting detail not recorded.

[Open source](https://www.justice.gov/usao-cdca/pr/federal-authorities-seize-13-internet-domains-associated-booter-websites-offered-ddos)

Coverage note.
- DOJ describes this action as 'the third wave of U.S. law enforcement actions against prominent booter services' and states it was taken in conjunction with Operation PowerOFF. The first wave was December 2018 (td\_2018\_poweroff\_dec) and the second December 2022 (td\_2022\_poweroff\_dec).
- The four guilty pleas DOJ announced on the same day (Jeremiah Sam Evans Miller, Angel Manuel Colon Jr., Shamar Shattock and Cory Anthony Palmer) arise from charges filed in the December 2022 wave and belong to td\_2022\_poweroff\_dec, where those people already exist. They are deliberately not carried here and not counted in this record's reported\_convicted\_count, to avoid double counting.
- The existing resurgence record res\_poweroff\_dec2022\_reincarnations describes exactly this relationship and is corrected in this batch to point its subsequent\_takedown\_id at this record.
- resurgence\_class left null: the A-G scale is undefined in this dataset and was not guessed.

Research context

## How this entry was checked

Source linked

Every claim in this entry traces to a source the audit opened and read. Nothing on the record needed changing.

Verified: August 23, 2026

Sources cited: 1

Research cutoff: August 23, 2026

Limitations recorded against this entry

- DOJ describes the seizures as happening 'this week' and does not give an exact seizure date, so started\_on and ended\_on use the announcement date of 2023-05-08.
- Only one of the 13 domains (cyberstress.org) was named, so the infrastructure row carries the aggregate count.
- No Europol or other international release for this wave was located; the record therefore names no international partner.

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Operation Cookie Monster](https://takedownindex.org/takedowns/operation-cookie-monster)
- [BreachForums shutdown following administrator arrest](https://takedownindex.org/takedowns/breachforums-shutdown-following-administrator-arrest)
- [ChipMixer takedown](https://takedownindex.org/takedowns/chipmixer-takedown)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about/corrections-and-updates)
