Authorities from 21 countries carried out a coordinated Operation PowerOFF crackdown against DDoS-for-hire infrastructure, dismantling booter services used to launch attacks against online marketplaces, telecommunications providers, and other internet-facing services. The action resulted in 53 domain takedowns, 4 arrests, and 25 search warrants, while investigators seized servers, infrastructure, and databases tied to the illegal platforms.
Data recovered during the operation helped investigators identify more than 3 million criminal user accounts, and law enforcement sent over 75,000 warning emails and letters to suspected users. Europol said the services lowered the barrier to launching disruptive attacks for motives ranging from curiosity and hacktivism to extortion and anti-competitive activity; prevention measures also included removing more than 100 URLs advertising booter services from search results, posting blockchain warning messages, and updating the Operation PowerOFF website as the international enforcement effort continues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-17, the U.S. Justice Department announced court-authorized cyber operations against major DDoS-for-hire services, including seizure of eight domains in the District of Alaska and searches of backend servers. The action, part of Operation PowerOFF, targeted services such as Vac Stresser and Mythical Stress that allegedly enabled attacks against schools, government agencies, gaming platforms, critical infrastructure, and individuals.
On 2026-04-16, Europol announced the results of the coordinated international crackdown, detailing arrests, domain seizures, warning notices, and investigative findings. The agency said the operation remained ongoing.
As part of the same April 2026 enforcement effort, authorities removed more than 100 URLs advertising booter services from search engine results, posted blockchain warning messages, and updated the Operation PowerOFF website. These measures were intended to deter use of DDoS-for-hire platforms alongside the law-enforcement action.
Using seized infrastructure and recovered databases during the April 2026 operation, investigators identified more than 3 million criminal user accounts tied to DDoS-for-hire activity. Authorities also sent over 75,000 warning emails and letters to identified users.
On 2026-04-13, authorities from 21 countries carried out a coordinated Operation PowerOFF action week against DDoS-for-hire services and their users. The operation included 53 domain takedowns, 4 arrests, 25 search warrants, infrastructure and database seizures, and disruption of illegal booter services.
In May 2025, authorities in Poland arrested alleged administrators of DDoS-for-hire platforms linked to thousands of attacks carried out between 2022 and 2025. This was cited as part of earlier Operation PowerOFF-related enforcement activity preceding the 2026 crackdown.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceeuropol.europa.eu
Open sourceoperation-poweroff.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.