Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

105 takedowns indexed Across 99 jurisdictions
Last reviewed August 23, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Operation Stream / Kidflix Mar 10, 2025 Child sexual abuse material BLKA International Completed
BestMixer seizure May 22, 2019 Cryptocurrency laundering FIOD International Completed
Simda botnet disruption Apr 9, 2015 Malware and botnets Not established International Completed
Operation Onymous Nov 5, 2014 Darknet market FBI, HSI International Completed
Operation Tovar May 30, 2014 Malware and botnets FBI International Completed
ZeroAccess botnet disruption Dec 5, 2013 Malware and botnets Microsoft DCU International Completed

Showing 1 to 6 of 6 takedowns

6 results

March 2025

Operation Stream / Kidflix

Kidflix Child sexual abuse material

Lead
BLKA
Result
Server seized March 11, 2025; 79 arrests, 1,393 suspects identified, more than 3,000 devices seized, and 39 children protected as of announcement.
Accountability
79 apprehended
Return status
Not established in the public record

May 2019

BestMixer seizure

BestMixer.io Cryptocurrency laundering

Lead
FIOD
Result
Six servers were seized in the Netherlands and Luxembourg and BestMixer.io was taken offline.
Accountability
No individual outcomes recorded
Return status
Later activity recorded, link to the original not established

April 2015

Simda botnet disruption

Simda Malware and botnets

Lead
Not established
Result
C2 servers were seized or disrupted by participating national authorities in a coordinated action. 10 C2 servers seized in the Netherlands; additional servers taken down in US, Russia, Luxembourg, Poland
Accountability
No individual outcomes recorded
Return status
Later activity recorded, link to the original not established

November 2014

Operation Onymous

Silk Road 2.0 and additional Tor marketplaces Darknet market

Lead
FBI, HSI
Result
Silk Road 2.0 hidden service seized; dozens of additional onion services seized or disabled; servers seized across multiple countries.
Accountability
1 charged and 1 apprehended
Return status
Followed by a copycat service

May 2014

Operation Tovar

Gameover Zeus botnet and CryptoLocker ransomware Malware and botnets

Lead
FBI
Result
Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.
Accountability
1 charged and 1 publicly wanted
Return status
Returned on replacement infrastructure

December 2013

ZeroAccess botnet disruption

ZeroAccess Malware and botnets

Result
Microsoft obtained a US court order blocking traffic between US computers and 18 identified IP addresses, and took over control of 49 domains associated with the botnet's fraud; Europol's EC3 coordinated search warrants and seizures of servers behind the 18 IP addresses located in Europe.
Accountability
No individual outcomes recorded
Return status
Returned under the same operators

Previous Page 1 of 1 Next

Filters

Filter takedowns