Skip to main content
Back to Operation Tovar

Organizations and roles

May 2014, Malware and botnets
Operation Tovar

Last reviewed August 21, 2026

The public record puts 7 organizations on this action. Operational lead: FBI and NCA. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.

Why this page names organizations only

Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.

Organizations and roles

Emblem Organization Role What the record says
Federal Bureau of Investigation United States , United States Operational lead Led the technical disruption and the multinational coordination.
National Crime Agency United Kingdom , United Kingdom Co-lead Led the UK component of the disruption and victim notification.
European Cybercrime Centre Coordinator Coordinated European participation.
United States Attorney's Office for the Western District of Pennsylvania United States , United States Charging Filed the indictment against Evgeniy Bogachev.
CrowdStrike United States , United States Technical partner Participated in the technical disruption.
Secureworks United States , United States Technical partner Provided technical analysis of the peer-to-peer network and supported the sinkhole.
The Shadowserver Foundation Netherlands , Netherlands Technical partner Operated sinkhole infrastructure and victim notification.

Accountability

Legal authority

US civil and criminal court orders (Western District of Pennsylvania) authorizing redirection and sinkholing; parallel foreign judicial process

Ongoing investigation

Group accounted for: Partial. The named leader was charged but never apprehended; the wider group was never publicly identified or accounted for.

This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.

Last reviewed August 21, 2026