Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Phobos/8Base ransomware disruption ID: td_2025_phobos_8base Feb 10, 2025 Ransomware Not established Not established Completed
Radar/Dispossessor ransomware disruption ID: td_2024_radar_dispossessor Aug 12, 2024 Ransomware FBI Not established Completed
Operation Cronos wave 1 ID: td_2024_cronos_w1 Feb 19, 2024 Ransomware NCA and FBI International Completed
ALPHV/BlackCat disruption ID: td_2023_alphv_blackcat Dec 19, 2023 Ransomware FBI Not established Completed
Ragnar Locker disruption ID: td_2023_ragnar_locker Oct 20, 2023 Ransomware French Gendarmerie Not established Completed
Hive ransomware infiltration and seizure ID: td_2023_hive Jul 1, 2022 Ransomware FBI International Completed
NetWalker ransomware disruption ID: td_2021_netwalker Jan 27, 2021 Ransomware FBI International Completed

Showing 1 to 7 of 7 takedowns

7 results

February 2025

Phobos/8Base ransomware disruption

Phobos and 8Base Ransomware

Lead
Not established
Result
More than 100 servers disrupted.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

August 2024

Radar/Dispossessor ransomware disruption

Radar (also known as Dispossessor) Ransomware

Lead
FBI
Result
Domains, servers, and IP infrastructure disabled or seized across three countries.
Accountability
1 publicly wanted
Return status
Not established in the public record

February 2024

Operation Cronos

LockBit Ransomware

Lead
NCA and FBI
Result
34 servers seized across eight countries; source code and affiliate data obtained; more than 1,000 decryption keys recovered; more than 200 cryptocurrency wallets frozen; approximately 14,000 rogue accounts closed; leak site taken over and operated by law enforcement.
Accountability
4 charged, 3 apprehended, 2 convicted, and 3 publicly wanted
Return status
Returned under the same operators

December 2023

ALPHV/BlackCat disruption

ALPHV/BlackCat Ransomware

Lead
FBI
Result
Leak-site and negotiation infrastructure disrupted; decryption keys/tooling provided to victims.
Accountability
No individual outcomes recorded
Return status
Returned under the same operators

October 2023

Ragnar Locker disruption

Ragnar Locker Ransomware

Lead
French Gendarmerie
Result
Ransomware infrastructure seized across multiple European jurisdictions; leak site taken down.
Accountability
1 apprehended
Return status
Not established in the public record

July 2022

Hive ransomware infiltration and seizure

Hive Ransomware

Lead
FBI
Result
Covert access to the Hive network for approximately seven months; more than 300 decryption keys provided to victims under active attack and more than 1,000 additional keys distributed to previous victims; leak site and payment site seized; servers seized in Germany and the Netherlands.
Accountability
No individual outcomes recorded
Return status
Returned under a new name

January 2021

NetWalker ransomware disruption

NetWalker Ransomware

Lead
FBI
Result
Dark-web victim communication and leak resources seized and taken offline; approximately 454,530 USD in cryptocurrency seized.
Accountability
1 charged
Return status
Not established in the public record

Previous Page 1 of 1 Next

Filters

Filter takedowns