Skip to main content

Public record database

Takedown Index

The Internet Takedown Index documents law enforcement seizures, sinkholes, takeovers, and shutdowns of criminal internet infrastructure. Every entry traces to a cited source.

104 takedowns indexed Across 37 jurisdictions
Last reviewed August 20, 2026
Takedown Date Category Lead organization Jurisdiction Status Derived from the recorded end date. A date in the past reads Completed, no date reads Ongoing. The dataset carries no separate status column.
Wall Street Market / Silkkitie (Valhalla) shutdown ID: td_2019_wall_street_market May 3, 2019 Darknet market BKA and Tulli Not established Completed
3ve ad-fraud botnet disruption ID: td_2018_3ve Nov 27, 2018 Malware and botnets FBI Not established Completed
Operation Trojan Shield ID: td_2021_anom Oct 1, 2018 Criminal communications FBI and AFP International Completed
VPNFilter botnet disruption ID: td_2018_vpnfilter May 23, 2018 State sponsored FBI Not established Completed
Amaq propaganda infrastructure takedown ID: td_2018_amaq Apr 27, 2018 Terrorism and extremism Belgian Federal Prosecutor Not established Completed
Webstresser.org takedown ID: td_2018_webstresser Apr 24, 2018 DDoS for hire Dutch National Police and NCA International Completed
Backpage.com seizure ID: td_2018_backpage Apr 6, 2018 Trafficking and exploitation FBI Not established Completed
Welcome to Video seizure ID: td_2019_welcome_to_video Mar 5, 2018 Child sexual abuse material IRS-CI and HSI International Completed
BTC-e disruption ID: td_2017_btc_e Jul 25, 2017 Cryptocurrency laundering FBI Not established Completed
AlphaBay seizure ID: td_2017_alphabay Jul 4, 2017 Darknet market FBI and DEA International Completed
Hansa covert takeover and shutdown ID: td_2017_hansa Jun 20, 2017 Darknet market Dutch National Police International Completed
Avalanche network takedown ID: td_2016_avalanche Nov 30, 2016 Criminal hosting and proxies Verden Public Prosecutor International Completed
Kickass Torrents takedown ID: td_2016_kickass_torrents Jul 20, 2016 Piracy and IP HSI Not established Completed
Dridex/Bugat/Cridex disruption ID: td_2015_dridex Oct 13, 2015 Malware and botnets FBI and NCA Not established Completed
Darkode forum takedown ID: td_2015_darkode Jul 15, 2015 Criminal hosting and proxies FBI Not established Completed
Operation Source / Beebone botnet disruption ID: td_2015_beebone Apr 8, 2015 Malware and botnets Dutch National Police Not established Completed
Simda botnet disruption ID: td_2015_simda Apr 1, 2015 Malware and botnets Not established Not established Completed
Ramnit botnet disruption ID: td_2015_ramnit Feb 24, 2015 Malware and botnets Not established Not established Completed
Operation Pacifier / Playpen ID: td_2015_playpen Feb 20, 2015 Child sexual abuse material FBI Not established Completed
Operation Babylon ID: td_2015_operation_babylon Jan 1, 2015 Child sexual abuse material Polizia Postale Not established Completed
Operation Onymous ID: td_2014_operation_onymous Nov 5, 2014 Darknet market FBI International Completed
Operation Tovar ID: td_2014_gameover_zeus May 30, 2014 Malware and botnets FBI and NCA International Completed
ZeroAccess botnet disruption ID: td_2013_zeroaccess Dec 5, 2013 Malware and botnets FBI Not established Completed
Silk Road seizure ID: td_2013_silk_road Oct 1, 2013 Darknet market FBI International Completed
Citadel botnet disruption ID: td_2013_citadel Jun 5, 2013 Malware and botnets FBI Not established Completed

Showing 76 to 100 of 104 takedowns

104 results

May 2019

Wall Street Market / Silkkitie (Valhalla) shutdown

Wall Street Market and Silkkitie/Valhalla Darknet market

Lead
BKA and Tulli
Result
Wall Street Market infrastructure was seized; Silkkitie/Valhalla infrastructure was separately taken down by Finnish Customs.
Accountability
3 apprehended
Return status
Not established in the public record

November 2018

3ve ad-fraud botnet disruption

3ve ("Eve") Malware and botnets

Lead
FBI
Result
Botnet C2 and fraudulent ad-traffic infrastructure disrupted; sinkholing conducted with private-sector partners.
Accountability
8 charged
Return status
Not established in the public record

October 2018

Operation Trojan Shield

ANOM Criminal communications

Lead
FBI and AFP
Result
Law enforcement operated the platform itself from inception; more than 27 million messages collected from roughly 12,000 devices across more than 300 criminal syndicates; network shut down at the action week.
Accountability
9 charged
Return status
Later activity recorded, link to the original not established

May 2018

VPNFilter botnet disruption

VPNFilter (attributed to Russia-linked Sandworm) State sponsored

Lead
FBI
Result
Domain seized; infected-device contacts redirected to FBI-controlled infrastructure, allowing victim IP addresses to be passed to remediation partners such as Shadowserver.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

April 2018

Amaq propaganda infrastructure takedown

Amaq (Islamic State propaganda distribution infrastructure) Terrorism and extremism

Lead
Belgian Federal Prosecutor
Result
Web/media distribution infrastructure disrupted.
Accountability
No individual outcomes recorded
Return status
Returned on replacement infrastructure
Operation PowerOFF

Webstresser.org DDoS for hire

Lead
Dutch National Police and NCA
Result
Service infrastructure seized in the Netherlands, the United States, and Germany; domain taken offline and replaced with a seizure notice.
Accountability
6 apprehended
Return status
Followed by a successor service
Backpage.com seizure

Backpage.com Trafficking and exploitation

Lead
FBI
Result
Site infrastructure and domains seized; replaced with a law-enforcement seizure notice.
Accountability
2 charged and 1 convicted
Return status
Not established in the public record

March 2018

Welcome to Video seizure

Welcome to Video Child sexual abuse material

Lead
IRS-CI and HSI
Result
Server seized in South Korea and site taken offline; approximately eight terabytes of material and roughly 250,000 videos secured; Bitcoin transaction analysis used to identify users.
Accountability
1 charged, 1 apprehended, and 1 convicted
Return status
Later activity recorded, link to the original not established

July 2017

BTC-e disruption

BTC-e Cryptocurrency laundering

Lead
FBI
Result
Exchange infrastructure disabled.
Accountability
1 apprehended and 1 convicted
Return status
Not established in the public record
Operation Bayonet

AlphaBay Darknet market

Lead
FBI and DEA
Result
Marketplace servers and hidden service seized; site taken offline; assets and cryptocurrency frozen in multiple jurisdictions.
Accountability
1 charged and 1 apprehended
Return status
Followed by a successor service

June 2017

Operation Bayonet

Hansa Market Darknet market

Lead
Dutch National Police
Result
Full covert takeover of the marketplace; servers seized in the Netherlands, Germany, and Lithuania; user credentials and transaction data collected; site replaced with seizure notice.
Accountability
2 apprehended
Return status
Not established in the public record

November 2016

Avalanche network takedown

Avalanche Criminal hosting and proxies

Lead
Verden Public Prosecutor
Result
More than 800,000 domains seized, sinkholed, or blocked; 39 servers seized; 37 premises searched.
Accountability
5 apprehended
Return status
Later activity recorded, link to the original not established

July 2016

Kickass Torrents takedown

Kickass Torrents (KAT) Piracy and IP

Lead
HSI
Result
Domains seized.
Accountability
1 apprehended
Return status
Not established in the public record

October 2015

Dridex/Bugat/Cridex disruption

Dridex (also known as Bugat/Cridex) Malware and botnets

Lead
FBI and NCA
Result
Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.
Accountability
1 charged and 1 apprehended
Return status
Not established in the public record

July 2015

Darkode forum takedown

Darkode Criminal hosting and proxies

Lead
FBI
Result
Forum infrastructure was seized and taken offline; a seizure notice replaced the site.
Accountability
28 apprehended
Return status
Not established in the public record

April 2015

Operation Source / Beebone botnet disruption

Beebone Malware and botnets

Lead
Dutch National Police
Result
Malicious domains were seized and sinkholed, allowing victim IP data to be supplied to ISPs and CERTs for remediation.
Accountability
No individual outcomes recorded
Return status
Not established in the public record
Simda botnet disruption

Simda Malware and botnets

Lead
Not established
Result
C2 servers were seized or disrupted by participating national authorities in a coordinated action.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

February 2015

Ramnit botnet disruption

Ramnit Malware and botnets

Lead
Not established
Result
Servers and domains supporting the botnet were taken under law-enforcement control and routed to a sinkhole.
Accountability
No individual outcomes recorded
Return status
Not established in the public record
Operation Pacifier / Playpen

Playpen Child sexual abuse material

Lead
FBI
Result
Server seized and covertly operated by the FBI for approximately two weeks under a search warrant before permanent shutdown.
Accountability
1 convicted
Return status
Not established in the public record

January 2015

Operation Babylon

Unnamed Tor CSAM/illicit-market hidden service Child sexual abuse material

Lead
Polizia Postale
Result
Tor hidden service shut down; approximately 14,000 associated bitcoin wallets seized in connection with the administrator's residence search.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

November 2014

Operation Onymous

Silk Road 2.0 and additional Tor marketplaces Darknet market

Lead
FBI
Result
Silk Road 2.0 hidden service seized; dozens of additional onion services seized or disabled; servers seized across multiple countries.
Accountability
1 charged and 1 apprehended
Return status
Not established in the public record

May 2014

Operation Tovar

Gameover Zeus botnet and CryptoLocker ransomware Malware and botnets

Lead
FBI and NCA
Result
Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.
Accountability
1 charged and 1 publicly wanted
Return status
Returned on replacement infrastructure

December 2013

ZeroAccess botnet disruption

ZeroAccess Malware and botnets

Lead
FBI
Result
Coordinated sinkholing and infrastructure disruption targeting ZeroAccess C2 servers.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

October 2013

Silk Road seizure

Silk Road Darknet market

Lead
FBI
Result
Hidden service and servers seized; site replaced with seizure banner; approximately 173,991 BTC ultimately seized across 2013 and later actions.
Accountability
1 charged, 1 apprehended, and 1 convicted
Return status
Returned under a new name

June 2013

Citadel botnet disruption

Citadel Malware and botnets

Lead
FBI
Result
Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.
Accountability
No individual outcomes recorded
Return status
Not established in the public record

Previous Page 4 of 5 Next

Filters

Filter takedowns