Site navigation

DDoS Platforms Seized in Worldwide Crackdown

Staff Writer

,

DDoS-for-hire
The National Crime Agency has taken part in a global crackdown on platforms offering illegal DDoS-for-hire services, arresting administrators and targeting users in efforts to curb cyber-attacks.

The National Crime Agency (NCA) has announced its involvement in a global operation targeting popular services used by cybercriminals to disrupt public infrastructure and cripple UK businesses.

As part of a Europol-coordinated, international crackdown known as Operation PowerOFF, authorities have seized twenty-seven of the most popular platforms used to carry out Distributed Denial-of-Service (DDoS) attacks, designed to take websites offline.

DDoS attacks, which are illegal in the UK under the Computer Misuse Act 1990, enable cybercriminals to flood targets with illegal traffic, rendering websites inaccessible and causing significant harm to businesses and critical national infrastructure – often preventing people from accessing essential public services.

DDoS-for-hire, also known as ‘booter’ and ‘stresser’ site services, allow offenders to easily order DDoS attacks within a matter of minutes, significantly lowering the barrier for entry.

The motivations for launching such attacks vary, from economic sabotage and financial gain to ideological reasons, as demonstrated by hacktivist collectives such as Killnet or Anonymous Sudan.

The multifaceted operation, involving fifteen countries, targeted all levels of those engaged in this crime, resulting in three administrators behind the platforms being arrested, and several actions taken against users of these services.

Europol said it had provided analytical support, crypto-tracing expertise, and forensic assistance to the investigation, while also facilitating the exchange of information through the Joint Cybercrime Action Taskforce (J-CAT), which operates from its headquarters.

Following the operation, the NCA will use the large amounts of evidence the operation compiled to target those using such services in the UK. 

Depending on the level of offending, users will either be arrested or warned about engaging in cybercrime, with information relating to those based overseas passed to international law enforcement.

“DDoS-for-hire services are a key component of cybercrime, and enable individuals with limited technical capability to offend with ease due to their ease of access and perceived anonymity,” said Frank Tutty, from the NCA’s National Cyber Crime Unit.

“Operation Power OFF helps to undermine trust in this criminal marketplace and make cybercriminals think twice before unleashing DDoS attacks, which can have serious consequences.”

In addition to dismantling the infrastructure supporting these attacks, Operation PowerOFF is taking  proactive steps to prevent further incidents.

Building on past efforts, international law enforcement agencies are launching an online ad campaign aimed at deterring individuals from engaging in DDoS activities, hoping to find potential offenders before they act.

The campaign will use Google search ads to give deterrence messages to young people searching for DDoS-for-hire tools, alongside preventative messages through YouTube adverts aimed at those watching tutorials on DDoS-for-hire tools.


Recommended reading


In addition to these digital interventions, other methods such as ‘knock-and-talks’, involving face to face intervention, will be used, as well as more than 250 warning letters, and over 2,000 emails to reach users of illegal services.

“We know that booter services are an attractive entry-level cybercrime, and users can go on to even more serious offending,” said Tutty.

“This is why our Google ad campaign is such a crucial part of this overarching operation, preventing would-be offenders from engaging with them in the first place, in tandem with enforcement action undertaken by law enforcement partners around the world.”

Earlier this year, a report from Imperva showed the growing scale of the DDoS problem, with a 111% rise in DDoS attacks over the first half of 2024 compared to the same period in 2023, while a report from Microsoft in October highlighted that DDoS attacks are growing more sophisticated as they transform to target the application layer, with the tech company mitigating 1.25 million attacks in just the second half of the year, a 4x increase compared with last year.

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences