Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Lumma Stealer disruption ID: td_2025_lumma May 13, 2025 Malware and botnets Microsoft DCU and DOJ International Completed
Operation Cronos wave 1 ID: td_2024_cronos_w1 Feb 19, 2024 Ransomware NCA and FBI International Completed

Showing 1 to 2 of 2 takedowns

2 results

May 2025

Lumma Stealer disruption

Lumma Stealer Malware and botnets

Lead
Microsoft DCU and DOJ
Result
Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.
Accountability
No individual outcomes recorded
Return status
Returned under the same operators

February 2024

Operation Cronos

LockBit Ransomware

Lead
NCA and FBI
Result
34 servers seized across eight countries; source code and affiliate data obtained; more than 1,000 decryption keys recovered; more than 200 cryptocurrency wallets frozen; approximately 14,000 rogue accounts closed; leak site taken over and operated by law enforcement.
Accountability
4 charged, 3 apprehended, 2 convicted, and 3 publicly wanted
Return status
Returned under the same operators

Previous Page 1 of 1 Next

Filters

Filter takedowns