News

Operation PowerOFF 2026 - 53 Booter Domains Seized in Largest Wave Yet

Police from 21 countries seized 53 booter and stresser domains in April 2026, arrested four operators, and warned over 75,000 users. The full Operation PowerOFF report.

8 min readVerified security research
Threat intelligence map showing the 21 countries involved in the April 2026 Operation PowerOFF booter seizures

The largest coordinated strike against the DDoS-for-hire market to date landed in April 2026. In a single week of action, police from 21 countries seized 53 booter and stresser domains, arrested four suspected operators, and walked away with something more valuable than infrastructure: databases describing more than three million criminal user accounts.

The operation is the latest and largest wave of Operation PowerOFF, the Europol-led campaign that has been dismantling booter services since 2018. Europol described DDoS-for-hire as “one of the most prolific and easily accessible trends in cybercrime,” noting that the panels let someone with no technical knowledge launch attacks by following step-by-step tutorials.


The April 2026 Wave by the Numbers

The coordinated action around April 13, 2026 combined classic domain seizures with a prevention campaign aimed directly at the people who buy attacks.

  • 53 domains seizedBooter and stresser storefronts now display law enforcement splash pages instead of attack panels. The seizures also hit the servers and databases behind the panels.
  • 4 operators arrestedSuspected administrators were detained in connection with running the seized services, adding to the long list of booter operators prosecuted since 2018.
  • 3 million+ user accounts exposedThe seized databases contained registration details, payment trails, and attack logs for more than three million criminal user accounts, now in police hands.
  • 75,000+ warnings deliveredInstead of arresting every identified user, police sent more than 75,000 warning letters and emails, making clear that buying attacks is a known, traceable crime.
  • 100+ URLs delistedAdvertising pages promoting DDoS-for-hire services were removed from search engine results, cutting the customer acquisition funnel the panels depend on.

The participating countries were Australia, Austria, Belgium, Brazil, Bulgaria, Denmark, Estonia, Finland, Germany, Japan, Latvia, Lithuania, Luxembourg, the Netherlands, Norway, Poland, Portugal, Sweden, Thailand, the United Kingdom, and the United States.

Why the warnings matter: previous PowerOFF waves turned seized customer databases into prosecutions. The 75,000 users who received a letter or email in 2026 now know their names, payments, and attack logs are in an evidence file. For many, the warning is the last chance before a knock on the door.


The KimWolf Connection

The April wave did not happen in isolation. It capped a months-long run of actions against the botnets that supply booter panels with firepower.

On April 10, 2026, US prosecutors in the District of Alaska unsealed a criminal complaint charging Jacob Butler, a 23-year-old from Ottawa known online as “Dort,” with developing and operating the KimWolf botnet. According to the complaint, KimWolf infected more than one million devices worldwide and sold DDoS capacity as a service. Butler was arrested in Ottawa under an extradition warrant, in an investigation run by the Defense Criminal Investigative Service with FBI support.

A month earlier, in March 2026, US authorities and international partners seized command-and-control infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad IoT botnets. The Central District of California also unsealed seizure warrants targeting online services supporting 45 DDoS-for-hire platforms, redirecting their domains to splash pages warning visitors that DDoS services are illegal.

The pattern is deliberate: seize the botnets that generate the traffic, seize the panels that sell it, and identify the customers who bought it, all in the same season.


Did It Actually Reduce Attacks?

Early network telemetry says the disruption registered. Cloudflare’s DDoS Threat Report for the first half of 2026 shows April 2026 as the peak month of the period, with 6.46 trillion HTTP DDoS requests and 165 petabytes of network-layer attack traffic. Both measures declined in the following weeks, a drop Cloudflare’s analysts link in part to the PowerOFF seizures.

The effect is real but temporary. Every previous wave, from the 48 domains seized in December 2022 to the 27 services taken down in December 2024, was followed by a rebuild cycle as operators relaunched under new brands. Our running takedown timeline tracks the full history.


What This Means for You

For network owners, the lesson of April 2026 is that booter traffic remains cheap and constant, so layered DDoS defense and authorized stress testing are investments, not luxuries. For anyone tempted to rent an attack, three million seized user accounts and 75,000 warning letters describe the risk better than any disclaimer: the panel you pay today is the evidence locker of tomorrow.

If you need to validate your own infrastructure, do it legally. Our IP stresser guide and free tools guide cover options that keep you on the right side of every law involved, and our legality analysis explains the statutes country by country.


Sources and Further Reading

This article draws on primary sources from law enforcement agencies, government cybersecurity bodies, and independent security researchers. We link them so you can verify every claim.


Frequently Asked Questions

What happened in Operation PowerOFF in April 2026?

During a coordinated week of action around April 13, 2026, law enforcement from 21 countries seized 53 booter and stresser domains, arrested four suspected operators, and removed more than 100 URLs advertising DDoS-for-hire services from search results. Seized databases contained details on over three million criminal user accounts.

Which countries took part in the April 2026 wave?

Australia, Austria, Belgium, Brazil, Bulgaria, Denmark, Estonia, Finland, Germany, Japan, Latvia, Lithuania, Luxembourg, the Netherlands, Norway, Poland, Portugal, Sweden, Thailand, the United Kingdom, and the United States all participated in the coordinated action.

What is the KimWolf botnet case?

In April 2026, US prosecutors charged Jacob Butler, a 23-year-old from Ottawa, Canada, with developing and operating the KimWolf botnet, a DDoS-for-hire service that infected more than one million devices worldwide. He was arrested in Ottawa under an extradition warrant following a US investigation supported by the Department of Defense.

Did the seizures reduce DDoS attacks?

Early telemetry suggests yes. Cloudflare recorded April 2026 as the peak month for DDoS volume in the first half of the year, with a measurable decline afterward that its analysts link in part to the PowerOFF disruption of booter infrastructure.