Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Operation Endgame wave 3 ID: td_2025_endgame_w3 Nov 10, 2025 Multi threat campaign Not established International Completed
INTERPOL Synergia III ID: td_2026_synergia_iii Jul 18, 2025 Multi threat campaign INTERPOL Not established Completed
Operation Endgame wave 2 ID: td_2025_endgame_w2 May 19, 2025 Multi threat campaign BKA International Completed
INTERPOL Synergia II ID: td_2024_synergia_ii Nov 5, 2024 Multi threat campaign INTERPOL Not established Completed
Operation Endgame wave 1 ID: td_2024_endgame_w1 May 27, 2024 Multi threat campaign French Gendarmerie, BKA, and Dutch National Police International Completed

Showing 1 to 5 of 5 takedowns

5 results

November 2025

Operation Endgame

Rhadamanthys, VenomRAT, Elysium botnet Multi threat campaign

Lead
Not established
Result
More than 1,000 servers disrupted; approximately 20 domains seized; access to several hundred thousand infected machines removed from operators.
Accountability
1 apprehended
Return status
Not established in the public record

July 2025

INTERPOL Synergia III

Heterogeneous malicious infrastructure Multi threat campaign

Lead
INTERPOL
Result
Approximately 45,000 malicious IPs targeted for disruption or takedown across the campaign period.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

May 2025

Operation Endgame

DanaBot, Bumblebee, Lactrodectus, Qakbot, HijackLoader, Trickbot, Warmcookie Multi threat campaign

Lead
BKA
Result
Approximately 300 servers disrupted worldwide; roughly 650 domains neutralized; approximately 3.5 million EUR in cryptocurrency seized during the wave.
Accountability
3 charged and 1 publicly wanted
Return status
Not established in the public record

November 2024

INTERPOL Synergia II

Heterogeneous malicious infrastructure (phishing, malware, ransomware C2) Multi threat campaign

Lead
INTERPOL
Result
More than 22,000 malicious IPs, domains, servers, and related infrastructure disrupted across the campaign.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

May 2024

Operation Endgame

IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, Trickbot Multi threat campaign

Lead
French Gendarmerie, BKA, and Dutch National Police
Result
More than 100 servers disrupted or taken down; more than 2,000 domains brought under law-enforcement control; 16 location searches.
Accountability
8 charged, 4 apprehended, and 8 publicly wanted
Return status
Not established in the public record

Previous Page 1 of 1 Next

Filters

Filter takedowns