Police in 21 countries, supported by Europol, have taken 53 DDoS-for-hire domains offline and made 4 arrests in the latest phase of Operation PowerOFF. The bigger number is a different one: more than 75,000 people were warned by email and letter that investigators know they used these services.
What happened
Operation PowerOFF is a long-running international effort against “booter” or “stresser” services, websites that rent out attack power to anyone who pays. Europol describes them plainly: “Booter services allow users to launch DDoS attacks against targeted websites, servers, or networks.” A DDoS attack floods a target with so much traffic that it slows down or stops answering real visitors.
According to BleepingComputer’s 16 April report, this phase produced four headline results: “75,000+ individuals warned via email and letters”, “4 arrests made”, “53 domains taken offline” and “25 search warrants issued”. Europol and The Hacker News put the number of participating countries at 21.
In the United States, authorities seized eight DDoS-for-hire domains, including Vac Stresser and Mythical Stress, The Hacker News reported.
What caught my attention is the shift in focus. Taking down the websites that sell attacks is not new. Sending tens of thousands of warnings to the customers is a clear message that buying an attack is not anonymous, and that the people clicking “launch” are now part of the investigation, not just the people running the service.
One figure is easy to confuse. BleepingComputer notes that earlier PowerOFF phases “had seized databases containing over 3 million criminal accounts”. That was earlier work, not this week’s action, although it helps explain how investigators could reach so many users now.
Who is affected
The 75,000 people who received warnings were warned, not arrested. Only four arrests are reported in this phase. Still, a warning letter from the police is not something anyone wants, and it shows that user records from these services are in law enforcement hands.
The targets of booter services are often small: online shops and gaming servers. In my experience these are businesses without a security team, and their owners may not know whether their hosting plan includes any protection at all.
Europol’s prevention work also targets young people directly, with search ads and warnings aimed at those looking for stresser services. That is a reasonable focus. I suspect many buyers treat these services like a game tool, something to knock a rival off a gaming server, without understanding that it is a crime.
By the numbers
| Item | Figure |
|---|---|
| Individuals warned by email and letter | 75,000+ |
| Arrests | 4 |
| Domains taken offline | 53 |
| Search warrants | 25 |
| Participating countries | 21 |
| Domains seized by U.S. authorities | 8 |
| Criminal accounts in databases seized in earlier phases | Over 3 million |
What to do now
- Find out what DDoS protection your host or ISP already offers. Do not assume you have it, and do not assume you lack it. Ask your provider what is covered and, just as important, how you activate it during an attack.
- Keep an incident contact list. Write down support contacts for your hosting company, your DNS provider and your internet provider, and keep it somewhere you can reach when your own website or email is not working.
- Talk to teenagers about “stresser” sites. Parents and schools should explain that renting one of these services to attack a server, a game or a school website is a crime, not a prank. The 75,000 warnings are a useful, concrete example to point to.
- Report attacks. If your site or service is hit, report it to your national police or CERT. Reports are how operations like this one find the services behind the traffic.
Why it matters
DDoS-for-hire is cheap, and cheap attacks tend to land on the people least able to absorb them. A small online store that goes down for a day during a sale loses real money, and a community gaming server can lose its players for good.
In my view, the most useful part of this operation is the customer side. For years the story has been about arresting admins and seizing domains, and new services appear soon after. Telling buyers, at this scale, that they have been identified changes the calculation for the casual user who thought paying a small fee for an attack carried no risk.
For readers in the Arab world who run small online businesses, the practical point stays the same whatever happens in Europe: know what your provider can do for you before you need it, and keep the phone numbers ready.
Sources
- Europol, Europol-supported global operation targets over 75,000 users engaged in DDoS attacks, April 2026, https://www.europol.europa.eu/media-press/newsroom/news/europol-supported-global-operation-targets-over-75-000-users-engaged-in-ddos-attacks
- BleepingComputer, Operation PowerOFF identifies 75K DDoS users, takes down 53 domains, 16 April 2026, https://www.bleepingcomputer.com/news/security/operation-poweroff-identifies-75k-ddos-users-takes-down-53-domains/
- The Hacker News, Operation PowerOFF seizes 53 DDoS domains, April 2026, https://thehackernews.com/2026/04/operation-poweroff-seizes-53-ddos.html
- TechCrunch, European police email 75,000 people asking them to stop DDoS attacks, 16 April 2026, https://techcrunch.com/2026/04/16/european-police-email-75000-people-asking-them-to-stop-ddos-attacks/