Skip to main content
Back to the takedown index

Operation PowerOFF

Operation PowerOFF May 2025 wave

May 2025, DDoS for hire
Led by Defense Criminal Investigative Service

Source linked. Verified August 23, 2026.

What was taken down?

Nine booter domains seized. DOJ put the running totals for the four-year effort at more than 75 domains seized and more than 11 defendants charged in Los Angeles and Anchorage. Alongside the seizures, HSI, DCIS and the Netherlands Police ran a search-engine advertising campaign aimed at deterring people looking for DDoS services.[1]

See what happened

What happened to the people?

Officials reported 4 apprehended.
Group accounted for: Partial

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

The Justice Department announced the court-authorized seizure of nine DDoS-for-hire domains, executed by the Defense Criminal Investigative Service's Cyber-West Resident Agency, while Poland's Central Cybercrime Bureau simultaneously announced the arrest of four administrators of such services. DOJ said several of those arrested had operated sites seized in earlier Central District of California operations.[1]

Announced May 7, 2025.

Date
May 2025
Target
9 booter and stresser services, booter stresser services
Activity
DDoS for hire
Operational lead
DCIS
Partners
USAO-CDCA, Policja, and 3 more[1]
Jurisdiction
United States, Poland, and Netherlands
Outcome
Nine booter domains seized. DOJ put the running totals for the four-year effort at more than 75 domains seized and more than 11 defendants charged in Los Angeles and Anchorage. Alongside the seizures, HSI, DCIS and the Netherlands Police ran a search-engine advertising campaign aimed at deterring people looking for DDoS services.
Status
Completed
Legal mechanism
Court-authorized seizure warrants supported by an affidavit filed in the Central District of California; separate Polish national process for the arrests
Group accounted for
Partial

Infrastructure

9 domains seized.

Identifier Recorded as Status Notes
Not published 9 domains Seized, United States Nine booter domains seized under court-authorized warrants, executed by DCIS's Cyber-West Resident Agency. None of the nine were named in the release.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

Four administrators arrested against nine seized domains, and no identities were published.

Nine services seized; four administrators arrested in Poland.

See the organizations and roles behind this action

DOJ said the effort was ongoing and aimed at targeting all known booter sites. The disposition of the four Polish arrests was not published in this release.[1]

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

What each part of this entry rests on

The audit recorded which sources carry which part of the record. These are those sources.

Official sources

  1. [1]
    Law Enforcement Seizes 9 DDoS-for-Hire Webpages as Part of Global Crackdown on ‘Booter’ and ‘Stresser’ DDoS Services

    United States Attorney's Office for the Central District of California, May 7, 2025, Source grade P1

    Supporting detail not recorded.

    Open source
Coverage note.
  • DOJ states the action was taken in conjunction with Operation PowerOFF, hence the parent link.
  • The release also lists the principal partners of Operation PowerOFF as a whole (Europol, USAO Alaska, CCIPS, FBI Anchorage and Los Angeles, HSI Columbus, BKA, NCA, Netherlands Police, Polish Central Cybercrime Bureau, Brazilian Federal Police, Japan's NPA, France's Police Nationale and others). That is a campaign-level list. Only the agencies the release ties to an act in this wave are carried as role rows.
  • DOJ says several of the administrators arrested in Poland had operated websites seized in previous Central District of California operations, but names neither the people nor the earlier services, so no resurgence row is proposed.
  • Poland's Central Cybercrime Bureau (CBZC) is recorded under the existing org_pl_police id; the corpus has no separate CBZC organization.
  • resurgence_class left null: the A-G scale is undefined in this dataset and was not guessed.