[Back to the takedown index](https://takedownindex.org/takedowns)

# Phobos/8Base ransomware disruption

February 2025, Ransomware

Extended pass entry, last reviewed August 21, 2026

What was taken down?

More than 100 servers disrupted.

[See what happened](#what-happened)

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Partial

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

A multinational coalition disrupted more than 100 servers connected to the Phobos ransomware-as-a-service operation and the affiliated 8Base group, accompanied by arrests.

**Date:** February 2025

**Target:** Phobos and 8Base, ransomware group

**Activity:** Ransomware

**Operational lead:** Not established

**Partners**

Europol[[1]](#source-1)

- [European Union Agency for Law Enforcement Cooperation](https://takedownindex.org/organizations/european-union-agency-for-law-enforcement-cooperation), coordinator

**Jurisdiction:** Not established

**Outcome:** More than 100 servers disrupted.

**Status:** Completed

**Legal mechanism:** Coordinated national judicial/search-and-seizure authority.

**Group accounted for:** Partial

## People and accountability

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

The cited record does not say how large the group was or whether everyone involved has been identified.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/phobos-8base-ransomware-disruption/organizations)

## What happened afterward

Not established in the public record. No later activity is recorded against this entry.

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[Law enforcement disrupts Phobos ransomware and 8Base group](https://takedownindex.org/sources/europol-law-enforcement-disrupts-phobos-ransomware-and-8base-group)

Europol, February 10, 2025, Source grade P2

Establishes the disruption of more than 100 servers connected to Phobos/8Base.

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source\_quality capped at S2/P2 pending a dedicated verification pass.

Research context

## How this entry was checked

This entry came from a broader aggregation pass and has not been independently verified source by source. Its sources are graded no higher than P2 or S2, and most carry no address yet. Treat the figures as a research lead rather than a settled record.

Source review: Extended pass, not yet verified

Sources cited: 1

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Radar/Dispossessor ransomware disruption](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)
- [Operation Cronos wave 1](https://takedownindex.org/takedowns/operation-cronos-wave-1)
- [ALPHV/BlackCat disruption](https://takedownindex.org/takedowns/alphv-blackcat-disruption)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
