Operation PowerOFF: Global Crackdown on the DDoS-for-Hire Ecosystem- 172
April 17,2026
The latest phase of Operation PowerOFF marks a significant escalation in the international effort to disrupt the commercial ecosystem behind DDoS-for-hire services, commonly known as “booter” platforms. Coordinated across more than 20 countries, this operation reflects a growing recognition among law enforcement agencies that the accessibility and commoditization of distributed denial-of-service attacks have transformed them into one of the most pervasive forms of cybercrime.
Rather than targeting isolated actors, the operation strikes at the infrastructure that enables large-scale abuse: domains, backend servers, user databases, and control panels that collectively sustain an underground market serving tens of thousands of users. Beyond technical disruption, authorities are increasingly shifting toward user-level deterrence, combining seizures and arrests with direct warning campaigns aimed at individuals who have engaged with these services.
This report outlines the scope, mechanics, and implications of Operation PowerOFF, situating it within a broader international campaign against DDoS botnets and related “stress-testing” services that blur the line between cybercrime facilitation and commercial exploitation of attack infrastructure.
An international law enforcement push, coordinated under “Operation PowerOFF,” has targeted the commercial ecosystem of DDoS-for-hire services at a significant scale.
In this action, authorities took down 53 domains linked to so-called “booter” or DDoS-for-hire platforms and arrested 4 individuals believed to be involved in their operation. These services were widely used, with investigators estimating more than 75,000 cybercriminal users relying on them to launch attacks. During the operation, law enforcement also gained access to backend systems and databases containing over 3 million user accounts, illustrating the sheer volume of customers and activity behind this underground market.
The disruption was not limited to takedowns. Authorities also issued around 25 search warrants and began sending warning notices directly to identified users, signaling a shift from purely infrastructure-focused action to user-level deterrence. The operation was coordinated across 21 countries, including major participants in Europe, North America, and Asia such as the U.S., U.K., Germany, Japan, Australia, Sweden, and others.

At the core of the targeted ecosystem are “DDoS-for-hire” or “booter” services—platforms that allow users with little or no technical skill to rent attack capacity and flood websites or online services with traffic. Europol described these infrastructures as composed of servers, databases, and control systems that make large-scale disruption easy to execute. The services are used for a wide range of motivations: financial extortion, ideological hacktivism, competitive disruption, or even curiosity-driven experimentation. Some operators also disguise their platforms as “stress-testing tools” to avoid scrutiny.
Authorities emphasized that the accessibility of these services has made distributed denial-of-service attacks one of the most widespread forms of cybercrime, but also noted that more advanced threat actors sometimes rely on them to amplify or customize their operations.
The Operation PowerOFF effort builds on a broader international campaign against this ecosystem. In parallel actions, U.S. authorities have also dismantled major infrastructure components, including the takedown of the RapperBot botnet, which had been used since at least 2021 to conduct large-scale attacks across more than 80 countries.
In another related operation, the U.S. Department of Justice moved against IoT-based DDoS botnet services, seizing infrastructure tied to at least 8 domains, including platforms such as “Vac Stresser” and “Mythical Stress,” both of which advertised the ability to launch thousands of attacks per day. These sites have since been replaced with seizure banners warning that DDoS activity is illegal and that users and operators may face investigation and prosecution.