Europol Just Warned 75,000 People They're Under Investigation for DDoS Attacks — Here's How the Whole Criminal Industry Works
On April 13, 2026, law enforcement from 21 countries seized 53 domains, arrested 4 people, and sent 75,000 warning emails to identified users of DDoS-for-hire platforms. They found 3 million criminal user accounts on seized servers. Operation PowerOFF has been running since 2018.
You can buy a DDoS attack for $45. A month-long subscription. Three target IPs. Forty-minute attack windows. That's the Mythical Stress pricing tier the FBI documented when they went undercover, paid for the service, and then seized the domain as part of the global law enforcement operation that just dropped its latest results.
On April 13, 2026, Europol coordinated a joint action week involving 21 countries. Results: 53 domains taken down, 4 arrests, 25 search warrants executed, and — the number that matters most — over 75,000 warning emails and letters sent to identified users of DDoS-for-hire platforms.
Not operators. Users. People who paid for attacks.
Law enforcement got those 75,000 names from the seized infrastructure. The databases they pulled off confiscated servers contained over 3 million criminal user accounts. They're working through that list. The 75,000 who got warnings this week are the beginning. But this phase of PowerOFF is doing something none of the previous phases did in this way: it's going after teenagers on Google and sending warnings into the blockchain itself.
What Operation PowerOFF Actually Is
PowerOFF is not a single raid. It's a persistent, multi-year international law enforcement campaign against the commercial DDoS-for-hire industry that has been running since 2018. Each phase adds more countries, more seizures, more arrests, more users contacted.
The operation traces back to the takedown of Webstresser.org in 2018 — at the time, the world's largest DDoS-for-hire platform. Webstresser had 136,000 registered users. It had been used to launch over 4 million attacks. Taking it down required coordination across multiple jurisdictions and set the template for what PowerOFF would become.
The history of phases runs like this:
2018: The FBI closes 15 DDoS-for-hire websites, then expands to close 48 domains total following the Webstresser takedown. Six people arrested across Florida, Texas, Hawaii, and New York. Cloudflare, PayPal, and DigitalOcean all provide information to assist the seizures. One seized service — Quantum — had launched 50,000 attacks. Law enforcement begins placing counter-ads on Google targeting people searching for DDoS-for-hire tools, an anti-marketing campaign that continues today.
December 2022: 48 domains seized. Six arrests. A major coordinated push that marks the operation's escalation.
2023: 13 more booter sites seized. Ten of them are linked to domains already taken down in the December 2022 sweep — operators just registered new domains. The whack-a-mole problem becomes undeniable and shapes every subsequent phase.
December 2024: 15 countries take 27 more platforms offline, including zdstresser.net and orbitalstress.net. Three people arrested in France and Germany. Dstat.cc, described as one of the largest DDoS platforms of its kind, seized alongside two suspects. The Dutch police specifically identified approximately 200 suspects from seized data, and prosecuted four men aged 22 to 26. The most prolific of them, a 26-year-old from Barneveld, was suspected of conducting 4,169 DDoS attacks on his own.
May 2025: Polish police arrest four people for running six platforms — Cfxapi, Cfxsecurity, neostress, jetstress, quickdown, and zapcut — that operated from 2022 to 2025 and charged as little as €10 per attack.
March 2026: Authorities disrupt four major botnet networks — Aisuru, KimWolf, JackSkid, and Mossad — that operators had been using as the attack infrastructure behind their services.
April 13, 2026: The current phase. 21 countries. 53 domains. 4 arrests. 75,000 warnings. 3 million user accounts on seized servers. And a new prevention architecture that goes beyond anything the previous phases attempted.
Where This Cycle Is Different
The enforcement actions — domain seizures, arrests, server confiscation — have been consistent across every PowerOFF phase. What's genuinely new in April 2026 is the explicit prevention layer.
Europol announced that the operation is now "entering its prevention phase" with three specific mechanisms:
Google and search engine ads targeting young people: When someone searches for "buy DDoS attack," "cheap stresser," or similar queries in participating countries, they see law enforcement warnings instead of vendor listings. This isn't new — PowerOFF has run counter-advertising since 2018. What's new is the explicit framing around youth targeting. The UK's National Crime Agency put it plainly through their National Cyber Crime Unit: "We know that Booter services are an attractive entry-level cyber crime, and users can go on to even more serious offending. Therefore, tackling this threat doesn't just involve arresting offenders, it includes steering people away from straying into cyber crime."
The pipeline observation matters. DDoS-for-hire is genuinely low-barrier. Teenagers with a gaming grudge or a competitive rivalry get curious, find a booter service, spend $20, and run their first attack. For some of those teenagers, it's the beginning of a criminal trajectory. Law enforcement data consistently shows that people arrested for serious cybercrime started with something trivial. The ad campaign is explicitly trying to intercept that trajectory before it begins.
Removal of 100+ URLs from search results: Beyond running ads, authorities worked with search platforms to remove over 100 URLs advertising DDoS-for-hire services from search results entirely. You can't just buy your way to visibility on these searches anymore — the products themselves are less visible.
On-chain blockchain warnings tied to illicit payments: This is the genuinely new capability. Europol described adding "on-chain warning messages tied to illicit payments" as part of the prevention phase. Most booter services accept cryptocurrency — Bitcoin primarily, with some accepting Monero for payment anonymity. When investigators trace cryptocurrency flows from seized infrastructure through blockchain analytics, they can identify wallets used for payments. Law enforcement is now annotating those wallets on-chain — essentially tagging criminal payment wallets in public blockchain records so that anyone who interacts with them sees a warning. The mechanism is public because the blockchain is public. A warning embedded in a Bitcoin transaction output to a criminal wallet becomes permanently visible to anyone who inspects that wallet's transaction history.
The International Cyber Offender Prevention Network (InterCOP) coordinated the country participation for the prevention campaign, enabling smaller jurisdictions to join enforcement actions that would otherwise be beyond their unilateral capacity.
How the Business Model Works
The phrase "DDoS-for-hire" understates how organized this has become. These are subscription services with tiered pricing, customer support, YouTube tutorials, and SLA-style guarantees.
The FBI documented the Mythical Stress pricing structure when they went undercover:
- Entry tier: $45/month. Three target IPs. Attack windows of 40 minutes.
- Top tier: $950/month. Attacks lasting up to 500 hours. Up to 90 victim IPs simultaneously.
One platform seized in this operation boasted of having been used to launch over 142 million attacks.
These platforms call themselves "stressers" or "booters" — the stress-tester framing is deliberate. The implication is that you're testing your own server's resilience. There is no verification of identity, no verification that you own the target IP. You pay, you enter any IP address you want, and the attack starts. Kaspersky found over 700 ads for DDoS-for-hire services on dark web forums in 2023 alone. The entry price for daily access starts around $20.
The private sector involvement in building the intelligence that makes these takedowns possible is also worth noting. The May 2025 phase of PowerOFF listed Akamai, Amazon Web Services, Cloudflare, Digital Ocean, Flashpoint, Google, PayPal, and the University of Cambridge as assistance providers. These companies have visibility into attack traffic patterns that law enforcement doesn't — when a wave of attacks hits their infrastructure, the traffic signatures, source patterns, and timing help investigators connect attacks back to specific booter services.
The Technical Stack Behind a $45 Attack
Understanding why these services are hard to kill requires understanding what you're actually buying access to.
The botnet layer: The attack traffic comes from compromised devices — routers, IoT cameras, smart TVs, home computers, anything internet-facing with inadequate security that has been silently infected with malware. The device owner has no idea their hardware is participating in attacks. Nokia's security research found the number of IoT devices used in DDoS attacks grew fivefold in recent years, from 200,000 to 1 million compromised devices, now accounting for roughly 40% of all DDoS attack traffic.
Command and control: A C2 server sits at the center of each botnet. When a customer initiates an attack from the booter's web panel, the C2 server transmits instructions to every infected device in the network simultaneously. Each device starts flooding the target with traffic. The C2 infrastructure typically sits in jurisdictions with weak enforcement, uses fast-flux hosting (constantly rotating IP addresses), and chains proxies to obscure the real location. This is why server seizures — physical and virtual — are a critical component of each PowerOFF phase rather than just domain takedowns.
Amplification: Raw botnet traffic is only so effective. The amplification techniques are what turn cheap infrastructure into attacks capable of overwhelming serious targets.
DNS amplification is the most common. The attacker sends a small DNS query to open resolvers, but spoofs the source IP to be the victim's address. The DNS server replies — with a response 28 to 54 times larger than the query — directly to the victim. The attacker's own traffic is small. The traffic hitting the victim is enormous. The open resolver is an innocent third party that doesn't know it's being weaponized.
NTP amplification works the same way. The attacker abuses the monlist command in Network Time Protocol servers, which returns a list of recent connections — a response up to 206 times larger than the request. Spoofed source IP. Massive traffic floods the victim. The NTP server never knows it was used as a weapon.
Combined with a botnet generating the initial requests across thousands of infected devices simultaneously, these multipliers turn modest infrastructure into something generating hundreds of gigabits per second of traffic. In October 2024, Cloudflare mitigated the largest DDoS attack ever recorded — 7.3 Tbps, delivering 37.4 terabytes of traffic in under a minute.
Layer 7 attacks: Beyond volumetric floods, modern booters offer application layer attacks targeting the web application itself. A Slowloris attack opens thousands of connections to a web server and holds them open by sending partial HTTP requests, never completing them. The server keeps each connection alive waiting for completion. Eventually it hits its connection limit and legitimate users get refused. No volume flooding required — a relatively small number of requests can take down an unprotected server. Application layer DDoS attacks increased 82% year-over-year per Imperva's threat data, partly because they're harder to filter since the traffic looks like legitimate HTTP requests.
Multi-vector attacks: High-end booter tiers combine Layer 4 volumetric floods with Layer 7 application attacks and switch between them mid-session. When defenders tune rate limiting to block the flood, the attack shifts to application-layer. When they tune for application attack, the flood resumes. The most expensive plans on seized platforms include multi-vector capabilities as a feature.
What Europol Actually Seized
The technical infrastructure behind these services is what makes the seized databases possible. When law enforcement raids a booter service, they get:
- The backend servers running the web panel and attack orchestration
- The customer database: usernames, emails, payment records, target IP histories
- The attack logs: every IP that was targeted, at what time, by which paying customer, from which subscription tier
- Cryptocurrency transaction records tracing payments back to wallets
- The botnet command infrastructure: the C2 servers, the infected device lists, the attack command queues
The 3 million user account number comes from exactly this. Europol's analytical team cross-referenced records across multiple seized platforms, performed crypto-tracing to link payment wallets to identities, and performed geolocation analysis to identify where users are physically located. That work produced actionable intelligence passed to national law enforcement agencies in each of the 21 participating countries.
The on-chain warning mechanism is an extension of this crypto-tracing capability. When investigators identify a wallet that received payments for DDoS attacks through seized transaction logs, they can trace that wallet's history on the public blockchain. The warning messages are then embedded in small Bitcoin transactions to those wallets — permanently tagging them in blockchain records. Anyone who later receives funds from or sends funds to these wallets encounters the warning.
The DOJ specifically named eight seized domains in its statement for this phase: Vac Stresser, Mythical Stress, Quantum-stress, Stresse, Unknownstresser, dreams-stresser, and others. These are gone. Their databases are now in law enforcement hands.
The Whack-a-Mole Problem
Every serious analysis of Operation PowerOFF asks the same question: does this actually work? The December 2022 seizure of 48 domains was followed in early 2023 by the discovery that 10 of 13 newly seized domains were the same operators running the same services under new names. Cyberstress.us became cyberstress.org. Same platform, new domain, back in business within weeks.
This is the structural challenge. The economics of running a booter service are favorable enough that new operators appear to replace seized ones. The technical barrier to spinning up a new service is low — the infrastructure components are commoditized, the scripts are available, and the customer base is already primed.
What makes the customer-targeting approach in the April 2026 phase significant is that it attacks this dynamic from the demand side. Going after operators produces whack-a-mole. Going after customers threatens the economic base.
Frank Tutty of the UK National Crime Agency's National Cyber Crime Unit articulated the pipeline problem directly: DDoS-for-hire is "an attractive entry-level cyber crime, and users can go on to even more serious offending." The warning letters going to 75,000 identified users are not primarily about prosecuting those specific individuals. They're about disrupting a criminal development pipeline. If paying for a DDoS attack carries a real risk of a letter from law enforcement — or prosecution — the pool of casual users shrinks. And without the casual user base providing revenue, the economics of running a commercial platform become harder.
The 3 million accounts on seized servers mean 75,000 warnings is genuinely just the start. The remaining 2.9 million are being processed. What changes behavior is not the warning letter — it's knowing the letter is possible. That 3 million number being public changes the risk calculation for anyone who has used these services and hasn't received a letter yet.
The Dutch precedent from the December 2024 phase is instructive. Police there identified approximately 200 suspects from seized data and began prosecutions. Four men were charged. The 26-year-old from Barneveld who ran 4,169 attacks didn't need to be a platform operator to face prosecution — he was a customer. That's the enforcement model being scaled up.
The Geopolitical Layer
DDoS-for-hire doesn't exist purely as criminal enterprise. There's a hacktivist dimension that makes the ecosystem harder to analyze cleanly.
Cyble's threat intelligence data showed a 140% increase in DDoS attacks targeting Israeli entities in the period after September 2025, with up to 40 daily attacks at peak tension. These attacks used commercially available DDoS-for-hire services. The perpetrators weren't sophisticated state-sponsored actors — they were individuals and small groups using the same $45/month subscription model that gaming communities use to knock opponents offline.
The NoName057(16) group — a pro-Russian hacktivist collective — has openly used DDoS-for-hire infrastructure for attacks on Ukrainian and NATO-aligned targets throughout the conflict. The Killnet group did the same. The availability of cheap, effective DDoS-as-a-service has lowered the barrier to coordinated cyberattacks to the point that non-state political actors can run sustained campaigns against government infrastructure.
This is a separate problem from the criminal-enterprise side of DDoS-for-hire, but it uses the same infrastructure. Taking down booter platforms disrupts both. It's why the operation draws participation from 21 countries across three continents — the DDoS problem is genuinely global, and the motivations behind attacks range from gaming disputes to geopolitical conflicts.
The DDoS-as-Smokescreen Problem
One detail that gets buried in the operational reporting: DDoS attacks are increasingly used as a distraction layer for more sophisticated intrusions.
The pattern is established in incident reports: a targeted organization experiences a volumetric DDoS attack that floods network operations, consumes security team attention, and creates noise in security event logs. While the NOC is dealing with the flood, a quieter attack is happening on the application layer — credential stuffing, API exploitation, or data exfiltration through channels that are harder to see against the noise of the DDoS traffic.
The booter services make this easier. An attacker doesn't need to develop DDoS capability independently — they rent it for $45, point it at a target to create chaos, and use that chaos as cover for the actual objective. From the defender's side, this means DDoS mitigation isn't just about keeping the service online. It's about maintaining the ability to detect and respond to other threats while under volumetric attack.
What This Means for Developers and Infrastructure Operators
If you run anything internet-facing, DDoS mitigation is not optional. The platforms taken down in this operation collectively launched hundreds of millions of attacks. Most of those attacks hit targets that weren't high-profile government systems — they hit small sites, individual servers, gaming communities, and APIs that someone somewhere wanted offline for $45.
Upstream filtering is the first line. Your hosting provider or CDN needs to absorb volumetric attacks before they reach your infrastructure. Cloudflare, AWS Shield, Azure DDoS Protection, and similar services sit upstream and can handle terabit-scale floods. If you're directly exposed with a residential or small datacenter connection, a sufficiently large volumetric attack saturates your upstream link before any on-premise mitigation applies.
Rate limiting at the application layer. Against Layer 7 attacks, upstream filters pass traffic that looks legitimate. Rate limiting per IP, per session, per endpoint protects the application. nginx's limit_req_zone, framework-level rate limiting, or a WAF in front of your origin all reduce your exposure to Slowloris-style and HTTP flood attacks.
Anycast and geographic distribution. Distributing your infrastructure across multiple locations with anycast routing means an attack targeting one location doesn't take down everything. Traffic gets absorbed across multiple points rather than concentrating at one.
Your infrastructure as an amplification target. Misconfigured DNS resolvers, NTP servers, and memcached instances don't just expose you to attack — they become weapons used against other people. Open DNS resolvers respond to spoofed queries and amplify traffic toward victims who may have no relationship to you. Lock down your DNS resolvers. Configure NTP with noquery. This isn't just self-protection — it's not becoming part of the weapon that attacks someone else.
The specific domains seized in this phase are gone, but the infrastructure model persists. New operators will appear. The supply of compromised IoT devices is not shrinking. Defending against DDoS requires ongoing architecture decisions, not a one-time response.
The Numbers That Actually Matter Going Forward
75,000 warning letters. 3 million user accounts. 53 domains down. The numbers from Europol's announcement are attention-grabbing, but the enforcement number that will determine whether this phase actually changes behavior is the prosecution rate against those 3 million accounts.
The whack-a-mole problem with operator takedowns is real and documented. New operators appear because the margins are good and the downside risk has historically been manageable. The customer-targeting strategy bets that the math changes if being a buyer carries prosecution risk.
What's also new is the blockchain warning layer. If law enforcement can tag criminal payment wallets on-chain — permanently, publicly, in a way that cryptocurrency exchanges and wallet software can surface to users — it introduces friction into the payment layer that the operators can't fully route around. Cryptocurrency was supposed to be anonymous. The public blockchain is not, and Europol's on-chain warning capability demonstrates that law enforcement is developing the forensic tooling to work effectively within it.
The seizure banner on every domain now says: "DDoS attacks are illegal. For years law enforcement agencies around the world have seized booter databases, arrested administrators, and collected information relating to the operation of these services, including information on the customers of these services. Anyone operating or utilizing DDoS services is subject to investigation, prosecution, and other law enforcement action."
Customers. Utilizing. Not just operators. The 3 million accounts on Europol's servers make that threat credible in a way it wasn't before this phase.
The supply chain security article covers how DDoS is used as a distraction layer in compound attacks — flood the network ops team while something quieter happens on the application side. The SSRF breakdown explains how server-side request forgery operates, the class of vulnerability that DDoS is increasingly used to distract defenders from during active exploitation. The web server explainer covers the infrastructure these attacks target at the server level.