Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actioncybercrime-service-ecosystemoperational-disruptionthreat-infrastructure-tracking

Operation PowerOFF Disrupts DDoS-for-Hire Services and Identifies 3 Million Accounts

Updated 2mo agoFirst seen Apr 16, 202611 sources

Authorities from 21 countries carried out a coordinated Operation PowerOFF crackdown against DDoS-for-hire infrastructure, dismantling booter services used to launch attacks against online marketplaces, telecommunications providers, and other internet-facing services. The action resulted in 53 domain takedowns, 4 arrests, and 25 search warrants, while investigators seized servers, infrastructure, and databases tied to the illegal platforms.

Data recovered during the operation helped investigators identify more than 3 million criminal user accounts, and law enforcement sent over 75,000 warning emails and letters to suspected users. Europol said the services lowered the barrier to launching disruptive attacks for motives ranging from curiosity and hacktivism to extortion and anti-competitive activity; prevention measures also included removing more than 100 URLs advertising booter services from search results, posting blockchain warning messages, and updating the Operation PowerOFF website as the international enforcement effort continues.

Share:
Operation PowerOFF Disrupts DDoS-for-Hire Services and Identifies 3 Million Accounts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 17, 20262mo ago

U.S. seizes eight booter domains and searches backend servers

On 2026-04-17, the U.S. Justice Department announced court-authorized cyber operations against major DDoS-for-hire services, including seizure of eight domains in the District of Alaska and searches of backend servers. The action, part of Operation PowerOFF, targeted services such as Vac Stresser and Mythical Stress that allegedly enabled attacks against schools, government agencies, gaming platforms, critical infrastructure, and individuals.

U.S. authorities conduct cyber operations as part of global crackdown on DDoS-for-hire services - DataBreaches.Net
Apr 16, 20262mo ago

Europol publicly announces latest Operation PowerOFF results

On 2026-04-16, Europol announced the results of the coordinated international crackdown, detailing arrests, domain seizures, warning notices, and investigative findings. The agency said the operation remained ongoing.

Apr 13, 20262mo ago

Prevention measures remove booter ads and issue warnings

As part of the same April 2026 enforcement effort, authorities removed more than 100 URLs advertising booter services from search engine results, posted blockchain warning messages, and updated the Operation PowerOFF website. These measures were intended to deter use of DDoS-for-hire platforms alongside the law-enforcement action.

Investigators identify millions of booter-service user accounts

Using seized infrastructure and recovered databases during the April 2026 operation, investigators identified more than 3 million criminal user accounts tied to DDoS-for-hire activity. Authorities also sent over 75,000 warning emails and letters to identified users.

Operation PowerOFF action week targets DDoS-for-hire ecosystem

On 2026-04-13, authorities from 21 countries carried out a coordinated Operation PowerOFF action week against DDoS-for-hire services and their users. The operation included 53 domain takedowns, 4 arrests, 25 search warrants, infrastructure and database seizures, and disruption of illegal booter services.

May 1, 20251y ago

Polish authorities arrest alleged booter administrators

In May 2025, authorities in Poland arrested alleged administrators of DDoS-for-hire platforms linked to thousands of attacks carried out between 2022 and 2025. This was cited as part of earlier Operation PowerOFF-related enforcement activity preceding the 2026 crackdown.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Malware
1 linked
Affected products
2 linked
Google SearchGoogle Search
Organizations
12 linked
Security AffairsCloudflareAkamai TechnologiesAmazon Web ServicesDigitaloceanShadowServer FoundationPayPalUnit 221BGoogleHydrolixEpieosRegistrar of Last Resort
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.