Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
GRU DNS-hijacking router network disruption (APT28) ID: td_2026_gru_router_network Apr 1, 2026 State sponsored FBI Not established Completed
Raptor Train botnet disruption ID: td_2024_raptor_train Sep 1, 2024 State sponsored FBI International Completed
KV Botnet disruption ID: td_2024_kv_botnet Dec 1, 2023 State sponsored FBI 🇺🇸 United States Completed
Operation MEDUSA ID: td_2023_snake May 8, 2023 State sponsored FBI International Completed
Cyclops Blink disruption ID: td_2022_cyclops_blink Apr 6, 2022 State sponsored FBI Not established Completed
VPNFilter botnet disruption ID: td_2018_vpnfilter May 23, 2018 State sponsored FBI Not established Completed

Showing 1 to 6 of 6 takedowns

6 results

April 2026

GRU DNS-hijacking router network disruption (APT28)

GRU Military Unit 26165 SOHO router network State sponsored

Lead
FBI
Result
US-based component of the router network neutralized; operation explicitly limited to infrastructure within US judicial reach.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

September 2024

Raptor Train botnet disruption

Raptor Train State sponsored

Lead
FBI
Result
Control of the botnet infrastructure seized; malware disabled on compromised devices; operators' attempt to migrate the botnet was countered.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

December 2023

KV Botnet disruption

KV Botnet State sponsored

Lead
FBI
Result
Malware deleted from compromised routers; command-and-control connections severed; steps taken to prevent reinfection without affecting legitimate router functions.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

May 2023

Operation MEDUSA

Snake malware network State sponsored

Lead
FBI
Result
Snake implants on victim machines disabled by issuing commands that caused the malware to overwrite its own vital components; peer-to-peer network neutralized.
Accountability
No individual outcomes recorded
Return status
Later activity recorded, link to the original not established

April 2022

Cyclops Blink disruption

Cyclops Blink (attributed to Russia's GRU-linked Sandworm) State sponsored

Lead
FBI
Result
Malware copied for evidentiary purposes and then removed from compromised C2 devices under court authorization; device owners still needed to independently patch underlying vulnerabilities.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

May 2018

VPNFilter botnet disruption

VPNFilter (attributed to Russia-linked Sandworm) State sponsored

Lead
FBI
Result
Domain seized; infected-device contacts redirected to FBI-controlled infrastructure, allowing victim IP addresses to be passed to remediation partners such as Shadowserver.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

Previous Page 1 of 1 Next

Filters

Filter takedowns