2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Operation PowerOFF Disrupts 53 DDoS Domains, Uncovers 3 Million Criminal Accounts


An international law enforcement campaign has dismantled 53 domains linked to commercial distributed denial-of-service (DDoS) operations and detained four individuals connected to those services. Authorities say the platforms were used by over 75,000 alleged cybercriminals.

Called Operation PowerOFF, the coordinated effort disabled access to the DDoS-for-hire platforms, removed key technical components that enabled the attacks, and secured databases containing in excess of 3 million accounts belonging to criminal users. Officials are notifying the implicated accounts via emails and letters, and investigators executed 25 search warrants as part of the operation.

The enforcement action drew participation from up to 21 countries, including Australia, Austria, Belgium, Brazil, Bulgaria, Denmark, Estonia, Finland, Germany, Japan, Latvia, Lithuania, Luxembourg, the Netherlands, Poland, Portugal, Sweden, Thailand, the United Kingdom, and the United States.

Europol explained that so-called booter services let customers launch DDoS campaigns against websites, servers, or networks. Those services rely on an underlying architecture of servers, databases and other technical components to function; by taking control of that infrastructure, law enforcement was able to disrupt the criminal ecosystem and reduce the risk to potential victims.

The agency also warned that DDoS-for-hire remains one of the most widespread and easy-to-access forms of cybercrime, enabling even people with little technical skill to execute powerful, damaging attacks against businesses and online services.

Europol noted that not all DDoS traffic stems from amateurs: well-funded and technically capable threat actors may leverage these services to enhance or customize their campaigns. Targets of DDoS attacks vary widely, and motivations range from mere curiosity and financial extortion to ideologically driven hacktivism and efforts to hinder competitors.

Some operators attempt to mask illicit intent by marketing their platforms as legitimate stress-testing tools, a tactic that can complicate investigations and help them avoid scrutiny from authorities.

Operation PowerOFF represents the latest phase in a sustained push to dismantle criminal DDoS-for-hire networks worldwide. In a related action, U.S. authorities announced in August 2025 the takedown of a DDoS botnet named RapperBot, which had been used to carry out disruptive attacks affecting victims in more than 80 countries since at least 2021.

First published on April 17, 2026.
Last updated on April 25, 2026.