Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption ID: td_2026_aisuru_family Mar 19, 2026 Malware and botnets USAO-AK and FBI Not established Completed
INTERPOL Operation Secure ID: td_2025_operation_secure Jun 11, 2025 Malware and botnets INTERPOL Not established Completed
Lumma Stealer disruption ID: td_2025_lumma May 13, 2025 Malware and botnets Microsoft DCU and DOJ International Completed
Operation Magnus (RedLine and META infostealers) ID: td_2024_operation_magnus Oct 28, 2024 Malware and botnets Dutch National Police Not established Completed
911 S5 botnet dismantlement ID: td_2024_911_s5 May 24, 2024 Malware and botnets FBI International Completed
IPStorm botnet dismantlement ID: td_2023_ipstorm Nov 1, 2023 Malware and botnets FBI Not established Completed
Operation Duck Hunt ID: td_2023_qakbot Aug 25, 2023 Malware and botnets FBI International Completed
FluBot disruption ID: td_2022_flubot Jun 1, 2022 Malware and botnets Dutch National Police Not established Completed
Operation Ladybird ID: td_2021_emotet Jan 26, 2021 Malware and botnets Dutch National Police and BKA International Completed
3ve ad-fraud botnet disruption ID: td_2018_3ve Nov 27, 2018 Malware and botnets FBI Not established Completed
Dridex/Bugat/Cridex disruption ID: td_2015_dridex Oct 13, 2015 Malware and botnets FBI and NCA Not established Completed
Operation Source / Beebone botnet disruption ID: td_2015_beebone Apr 8, 2015 Malware and botnets Dutch National Police Not established Completed
Simda botnet disruption ID: td_2015_simda Apr 1, 2015 Malware and botnets Not established Not established Completed
Ramnit botnet disruption ID: td_2015_ramnit Feb 24, 2015 Malware and botnets Not established Not established Completed
Operation Tovar ID: td_2014_gameover_zeus May 30, 2014 Malware and botnets FBI and NCA International Completed
ZeroAccess botnet disruption ID: td_2013_zeroaccess Dec 5, 2013 Malware and botnets FBI Not established Completed
Citadel botnet disruption ID: td_2013_citadel Jun 5, 2013 Malware and botnets FBI Not established Completed
Operation Ghost Click ID: td_2011_dnschanger Nov 8, 2011 Malware and botnets FBI Not established Completed
Coreflood botnet disruption ID: td_2011_coreflood Apr 13, 2011 Malware and botnets DOJ and FBI Not established Completed

Showing 1 to 19 of 19 takedowns

19 results

March 2026

Aisuru/KimWolf/JackSkid/Mossad IoT DDoS botnet disruption

Aisuru, KimWolf, JackSkid, and Mossad IoT DDoS botnets Malware and botnets

Lead
USAO-AK and FBI
Result
C2 infrastructure disrupted across multiple related botnet families.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

June 2025

INTERPOL Operation Secure

Infostealer malware infrastructure (26-country action) Malware and botnets

Lead
INTERPOL
Result
More than 20,000 malicious IPs/domains taken down; 41 servers seized.
Accountability
32 apprehended
Return status
Not established in the public record

May 2025

Lumma Stealer disruption

Lumma Stealer Malware and botnets

Lead
Microsoft DCU and DOJ
Result
Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.
Accountability
No individual outcomes recorded
Return status
Returned under the same operators

October 2024

Operation Magnus (RedLine and META infostealers)

RedLine Stealer and META Stealer Malware and botnets

Lead
Dutch National Police
Result
Servers seized; source code and backend databases obtained.
Accountability
1 charged
Return status
Not established in the public record

May 2024

911 S5 botnet dismantlement

911 S5 Malware and botnets

Lead
FBI
Result
23 domains and more than 70 servers seized; botnet infrastructure dismantled; approximately 30 million USD in assets seized or restrained.
Accountability
1 charged and 1 apprehended
Return status
Not established in the public record

November 2023

IPStorm botnet dismantlement

IPStorm Malware and botnets

Lead
FBI
Result
Botnet infrastructure dismantled in connection with the criminal prosecution.
Accountability
1 convicted
Return status
Not established in the public record

August 2023

Operation Duck Hunt

Qakbot Malware and botnets

Lead
FBI
Result
Botnet traffic redirected to FBI infrastructure; uninstaller delivered to approximately 700,000 infected computers; 52 servers seized; approximately 8.6 million USD in cryptocurrency seized.
Accountability
No individual outcomes recorded
Return status
Returned under the same operators

June 2022

FluBot disruption

FluBot Malware and botnets

Lead
Dutch National Police
Result
Infrastructure behind the malware was taken under control or disrupted through coordinated international measures.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

January 2021

Operation Ladybird

Emotet Malware and botnets

Lead
Dutch National Police and BKA
Result
Roughly 700 command-and-control servers taken over; infected machines redirected to law-enforcement infrastructure; a court-authorized uninstall module was delivered and triggered on 2021-04-25.
Accountability
2 apprehended
Return status
Returned on replacement infrastructure

November 2018

3ve ad-fraud botnet disruption

3ve ("Eve") Malware and botnets

Lead
FBI
Result
Botnet C2 and fraudulent ad-traffic infrastructure disrupted; sinkholing conducted with private-sector partners.
Accountability
8 charged
Return status
Not established in the public record

October 2015

Dridex/Bugat/Cridex disruption

Dridex (also known as Bugat/Cridex) Malware and botnets

Lead
FBI and NCA
Result
Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.
Accountability
1 charged and 1 apprehended
Return status
Not established in the public record

April 2015

Operation Source / Beebone botnet disruption

Beebone Malware and botnets

Lead
Dutch National Police
Result
Malicious domains were seized and sinkholed, allowing victim IP data to be supplied to ISPs and CERTs for remediation.
Accountability
No individual outcomes recorded
Return status
Not established in the public record
Simda botnet disruption

Simda Malware and botnets

Lead
Not established
Result
C2 servers were seized or disrupted by participating national authorities in a coordinated action.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

February 2015

Ramnit botnet disruption

Ramnit Malware and botnets

Lead
Not established
Result
Servers and domains supporting the botnet were taken under law-enforcement control and routed to a sinkhole.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

May 2014

Operation Tovar

Gameover Zeus botnet and CryptoLocker ransomware Malware and botnets

Lead
FBI and NCA
Result
Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.
Accountability
1 charged and 1 publicly wanted
Return status
Returned on replacement infrastructure

December 2013

ZeroAccess botnet disruption

ZeroAccess Malware and botnets

Lead
FBI
Result
Coordinated sinkholing and infrastructure disruption targeting ZeroAccess C2 servers.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

June 2013

Citadel botnet disruption

Citadel Malware and botnets

Lead
FBI
Result
Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

November 2011

Operation Ghost Click

DNSChanger Malware and botnets

Lead
FBI
Result
FBI seized rogue DNS servers and, with court authorization, substituted clean DNS servers to keep previously infected machines online during remediation.
Accountability
6 charged and 1 apprehended
Return status
Not established in the public record

April 2011

Coreflood botnet disruption

Coreflood Malware and botnets

Lead
DOJ and FBI
Result
US authorities seized Coreflood's command-and-control servers and a set of associated domains, then used civil/criminal process to substitute law-enforcement-controlled servers that instructed infected machines to stop the malware.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

Previous Page 1 of 1 Next

Filters

Filter takedowns