What Happened to Operation PowerOFF?
Operation PowerOFF is an ongoing, coordinated international law enforcement initiative launched in July 2017 to dismantle the global Distributed Denial of Service (DDoS) for-hire ecosystem. It has involved seizing numerous 'booter' and 'stresser' domains, arresting operators, and exposing millions of criminal user accounts, with significant actions continuing into 2026 to disrupt services and deter potential cybercriminals.
Quick Answer
Operation PowerOFF is an ongoing international law enforcement operation that began in July 2017, targeting and dismantling DDoS-for-hire services used by cybercriminals worldwide. Coordinated by Europol and involving numerous countries, the operation has successfully seized dozens of illegal domains, made multiple arrests, and identified over 3 million user accounts associated with launching DDoS attacks. The latest major actions in April 2026 saw the takedown of 53 domains and four arrests, alongside proactive prevention campaigns to deter new offenders.
📊Key Facts
📅Complete Timeline9 events
Operation PowerOFF (ex Operation Vulcania) Commences
Europol initiates Operation PowerOFF, an ongoing international law enforcement effort aimed at dismantling criminal DDoS-for-hire infrastructure.
Initial Takedowns by FBI and Dutch Police
The FBI, in collaboration with the Dutch National Police Corps, closes 15 DDoS websites, marking an early success in the operation.
Major Expansion and 48 Domain Seizures
The FBI and U.S. Department of Justice announce a significant expansion of the operation, closing multiple DDoS-for-hire websites, seizing 48 domains, and leading to six arrests across the U.S.
27 DDoS Booters Shut Down Ahead of Christmas
Law enforcement agencies, as part of Operation PowerOFF, shut down 27 DDoS booter services in a proactive measure to prevent attacks during the holiday season.
RapperBot DDoS Botnet Takedown
The U.S. government announces the takedown of the RapperBot DDoS botnet, which had been used for large-scale attacks since 2021, as part of the ongoing Operation PowerOFF efforts.
Coordinated International Action Week
A major coordinated action week takes place, bringing together authorities from 21 countries to target the DDoS-for-hire ecosystem.
53 Domains Seized, 4 Arrests, 3 Million Accounts Exposed
Europol announces the results of the April 2026 action, including the seizure of 53 DDoS domains, four arrests, 25 search warrants, and access to databases containing over 3 million criminal user accounts.
Prevention Phase Launched with Warning Campaigns
As part of Operation PowerOFF, a prevention phase is launched, including sending over 75,000 warning messages to identified users and implementing targeted advertising campaigns to deter potential cybercriminals.
Europol Updates Confirm Ongoing Status
Europol's official page for Operation PowerOFF is updated, reiterating its ongoing status and continued efforts to dismantle DDoS-for-hire services.
Follow this story
Get an email when this timeline gets a major update.
🔍Deep Dive Analysis
Operation PowerOFF, initially known as Operation Vulcania, is a comprehensive and sustained international law enforcement effort against the pervasive threat of Distributed Denial of Service (DDoS) for-hire services. Launched in July 2017, the operation aims to dismantle the infrastructure of 'booter' and 'stresser' websites that allow individuals, often with minimal technical knowledge, to launch powerful DDoS attacks for a fee. These attacks can cripple businesses, disrupt essential services, and cause significant financial and reputational damage.
The motivation behind Operation PowerOFF stems from the growing accessibility and impact of DDoS attacks, which have become a prevalent form of cybercrime. These services lower the barrier to entry for cybercriminals, enabling attacks ranging from simple curiosity and financial extortion to hacktivism and disruption of competitors. Law enforcement agencies recognized the need for a coordinated global response due to the international nature of these criminal networks, with administrators, users, and victims often scattered across different countries.
Key turning points in the operation include its initial phase in 2018, where the FBI and Dutch National Police closed 15 DDoS websites. A significant expansion occurred in December 2022, with the FBI and Department of Justice announcing the closure of multiple DDoS-for-hire services, seizing 48 domains and leading to six arrests in the United States. The operation continued to gain momentum, with 27 DDoS booters shut down in December 2024 ahead of anticipated holiday attacks.
The consequences of Operation PowerOFF have been substantial, leading to the disruption of numerous criminal enterprises and the identification of a vast number of individuals involved in launching DDoS attacks. Beyond enforcement, the operation has also focused on prevention. As of April 2026, a major coordinated action involving 21 countries resulted in the seizure of 53 domains, four arrests, 25 search warrants, and the exposure of over 3 million criminal user accounts. Authorities have been sending warning emails and letters to identified users and launching advertising campaigns on search engines and YouTube to deter young people from engaging in these illegal activities.
As of September 8, 2026, Operation PowerOFF remains an ongoing initiative. Europol's official page for the operation was updated as recently as August 18, 2026, confirming its continuous efforts. The operation continues to combine enforcement measures, such as infrastructure takedowns and arrests, with proactive prevention strategies, including public awareness campaigns and direct warnings to users. This multi-faceted approach aims to not only disrupt existing DDoS-for-hire services but also to reduce the demand for such illicit tools and prevent future cyberattacks.
What If...?
Explore alternate histories. What if Operation PowerOFF made different choices?