📌 cybercrimeEvent7 views3 min read

What Happened to Operation PowerOFF?

Operation PowerOFF is an ongoing, coordinated international law enforcement initiative launched in July 2017 to dismantle the global Distributed Denial of Service (DDoS) for-hire ecosystem. It has involved seizing numerous 'booter' and 'stresser' domains, arresting operators, and exposing millions of criminal user accounts, with significant actions continuing into 2026 to disrupt services and deter potential cybercriminals.

Share:
⚡

Quick Answer

Operation PowerOFF is an ongoing international law enforcement operation that began in July 2017, targeting and dismantling DDoS-for-hire services used by cybercriminals worldwide. Coordinated by Europol and involving numerous countries, the operation has successfully seized dozens of illegal domains, made multiple arrests, and identified over 3 million user accounts associated with launching DDoS attacks. The latest major actions in April 2026 saw the takedown of 53 domains and four arrests, alongside proactive prevention campaigns to deter new offenders.

📊Key Facts

Operation Start Date
July 2017
Europol
Domains Seized (as of April 2026)
53
The Hacker News
Arrests (as of April 2026)
4
Europol
Criminal User Accounts Exposed
Over 3 million
The Hacker News
Participating Countries (as of April 2026)
21
Europol
Warning Messages Sent (as of April 2026)
Over 75,000
FastNetMon

📅Complete Timeline9 events

1
July 2017Major

Operation PowerOFF (ex Operation Vulcania) Commences

Europol initiates Operation PowerOFF, an ongoing international law enforcement effort aimed at dismantling criminal DDoS-for-hire infrastructure.

2
2018Major

Initial Takedowns by FBI and Dutch Police

The FBI, in collaboration with the Dutch National Police Corps, closes 15 DDoS websites, marking an early success in the operation.

3
December 14, 2022Critical

Major Expansion and 48 Domain Seizures

The FBI and U.S. Department of Justice announce a significant expansion of the operation, closing multiple DDoS-for-hire websites, seizing 48 domains, and leading to six arrests across the U.S.

4
December 11, 2024Major

27 DDoS Booters Shut Down Ahead of Christmas

Law enforcement agencies, as part of Operation PowerOFF, shut down 27 DDoS booter services in a proactive measure to prevent attacks during the holiday season.

5
August 2025Major

RapperBot DDoS Botnet Takedown

The U.S. government announces the takedown of the RapperBot DDoS botnet, which had been used for large-scale attacks since 2021, as part of the ongoing Operation PowerOFF efforts.

6
April 13, 2026Critical

Coordinated International Action Week

A major coordinated action week takes place, bringing together authorities from 21 countries to target the DDoS-for-hire ecosystem.

7
April 17, 2026Critical

53 Domains Seized, 4 Arrests, 3 Million Accounts Exposed

Europol announces the results of the April 2026 action, including the seizure of 53 DDoS domains, four arrests, 25 search warrants, and access to databases containing over 3 million criminal user accounts.

8
April 17, 2026Critical

Prevention Phase Launched with Warning Campaigns

As part of Operation PowerOFF, a prevention phase is launched, including sending over 75,000 warning messages to identified users and implementing targeted advertising campaigns to deter potential cybercriminals.

9
August 18, 2026Major

Europol Updates Confirm Ongoing Status

Europol's official page for Operation PowerOFF is updated, reiterating its ongoing status and continued efforts to dismantle DDoS-for-hire services.

Follow this story

Get an email when this timeline gets a major update.

🔍Deep Dive Analysis

Operation PowerOFF, initially known as Operation Vulcania, is a comprehensive and sustained international law enforcement effort against the pervasive threat of Distributed Denial of Service (DDoS) for-hire services. Launched in July 2017, the operation aims to dismantle the infrastructure of 'booter' and 'stresser' websites that allow individuals, often with minimal technical knowledge, to launch powerful DDoS attacks for a fee. These attacks can cripple businesses, disrupt essential services, and cause significant financial and reputational damage.

The motivation behind Operation PowerOFF stems from the growing accessibility and impact of DDoS attacks, which have become a prevalent form of cybercrime. These services lower the barrier to entry for cybercriminals, enabling attacks ranging from simple curiosity and financial extortion to hacktivism and disruption of competitors. Law enforcement agencies recognized the need for a coordinated global response due to the international nature of these criminal networks, with administrators, users, and victims often scattered across different countries.

Key turning points in the operation include its initial phase in 2018, where the FBI and Dutch National Police closed 15 DDoS websites. A significant expansion occurred in December 2022, with the FBI and Department of Justice announcing the closure of multiple DDoS-for-hire services, seizing 48 domains and leading to six arrests in the United States. The operation continued to gain momentum, with 27 DDoS booters shut down in December 2024 ahead of anticipated holiday attacks.

The consequences of Operation PowerOFF have been substantial, leading to the disruption of numerous criminal enterprises and the identification of a vast number of individuals involved in launching DDoS attacks. Beyond enforcement, the operation has also focused on prevention. As of April 2026, a major coordinated action involving 21 countries resulted in the seizure of 53 domains, four arrests, 25 search warrants, and the exposure of over 3 million criminal user accounts. Authorities have been sending warning emails and letters to identified users and launching advertising campaigns on search engines and YouTube to deter young people from engaging in these illegal activities.

As of September 8, 2026, Operation PowerOFF remains an ongoing initiative. Europol's official page for the operation was updated as recently as August 18, 2026, confirming its continuous efforts. The operation continues to combine enforcement measures, such as infrastructure takedowns and arrests, with proactive prevention strategies, including public awareness campaigns and direct warnings to users. This multi-faceted approach aims to not only disrupt existing DDoS-for-hire services but also to reduce the demand for such illicit tools and prevent future cyberattacks.

What If...?

Explore alternate histories. What if Operation PowerOFF made different choices?

Explore Scenarios
Building relationship map...

❓People Also Ask

What is Operation PowerOFF?
Operation PowerOFF is an ongoing international law enforcement initiative coordinated by Europol, targeting and dismantling 'booter' and 'stresser' services that offer Distributed Denial of Service (DDoS) attacks for hire. It involves seizing illegal domains, arresting operators, and deterring users.
When did Operation PowerOFF start?
Operation PowerOFF officially began in July 2017, initially known as Operation Vulcania. It has been an ongoing effort since its inception, with various phases of enforcement and prevention.
Which countries are involved in Operation PowerOFF?
Numerous countries are involved, including Australia, Austria, Belgium, Brazil, Bulgaria, Denmark, Estonia, Finland, Germany, Japan, Latvia, Lithuania, Luxembourg, the Netherlands, Poland, Portugal, Sweden, Thailand, the U.K., and the U.S., among others, with Europol coordinating efforts.
What are the consequences for users of DDoS-for-hire services?
Users of DDoS-for-hire services are subject to investigation, prosecution, and other law enforcement actions. Authorities have seized databases containing millions of user accounts and are sending warning messages and letters to identified individuals.
Is Operation PowerOFF still active in 2026?
Yes, Operation PowerOFF is still very active. Major actions occurred in April 2026, including domain seizures and arrests, and Europol's official page was updated in August 2026, confirming its ongoing status and continued efforts.