Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 7/10

Operation "Power Off": BKA Shuts Down DDoS Platforms

In a coordinated operation, international law enforcement agencies have taken down dozens of servers and arrested several cybercriminals. A German suspect is in custody in Thailand.

Operation "Power Off": Major strike against DDoS stresser services

The Frankfurt am Main General Public Prosecutor's Office and the German Federal Criminal Police Office (BKA), together with law enforcement agencies from a total of 21 countries, have carried out a massive strike against illegal DDoS platforms. Operation "Power Off", supported by Europol, specifically targeted so-called stresser services – web-based platforms that allow users to launch overload attacks against third-party systems in return for payment.

Key measures and results of the operation

The operation centred on dismantling criminal IT infrastructures. The participating authorities carried out more than 150 measures against incriminated infrastructure worldwide. In the process, more than 40 servers linked to a German defendant were seized. This man is alleged to have operated two of the world's most significant stresser services, named "Fluxstress" and "Netdowner".

Internationally, 16 searches took place, including in Poland and Brazil. In the course of their investigations, the Polish authorities arrested two suspected administrators and another person involved. The German suspect, a German national, is currently in the custody of the Thai authorities. An arrest warrant has been issued against him in Germany for the commercial and organised operation of a criminal trading platform on the internet.

Preventive measures against cybercrime

Alongside the repressive measures, the German authorities are also taking extensive preventive steps. They will contact more than 50,000 users of the services taken offline and point out that their actions are criminal offences. In addition, more than 50 communication platforms closely linked to the criminal services are being shut down.

The authorities are accompanying these measures with a target-group-oriented animated film that makes the criminal consequences of such activities clear. This is particularly relevant because stresser services often appear to many young people to be a supposedly harmless game – especially in the gaming scene.

What are stresser services and why are they dangerous?

How they work and how accessible they are

Stresser services are web-based platforms that enable their customers, for a fee, to carry out targeted overload attacks (distributed denial-of-service attacks, DDoS) against websites and other web-based services. What sets these services apart is that they require no in-depth technical skills. As a result, DDoS attacks are made accessible to a wide circle of users – a considerable security threat.

In a DDoS attack, victim systems are deliberately overloaded so that their content is temporarily unreachable. The consequence: websites or services go down. This can cause considerable economic damage to the affected companies and potentially also lead to outages of critical infrastructure such as energy, water or communication systems.

The varied motives of attackers

The motives behind DDoS attacks are diverse. The authorities distinguish several categories: economic sabotage and financial gain come first. Cybercriminals also use DDoS attacks to disguise other cyberattacks or to gain competitive advantages for themselves in online gaming.

In addition, there are political and ideological motives. So-called hacktivist groups use DDoS attacks to build up social pressure. These groups direct their attacks against both national German and Europe-wide internet presences, particularly in the areas of security, infrastructure and finance.

Data gathering and intelligence

In the course of the operation, the participating law enforcement agencies obtained leads on more than three million user records with criminal connections. This data is of great value for further investigations against criminal users of the platforms. It enables the authorities to solve a large number of individual cases and identify further suspects.

This extensive collection of data illustrates the scale of the problem: millions of people use or have used stresser services. Many of these users may not be aware of the criminal consequences.

Assessment: Why is this operation significant?

Stresser services as a gateway into cybercrime

According to the German Central Office for Combating Internet Crime (ZIT), stresser services are one of the most common "entry-level offences" – particularly for young people. The services act as a gateway into the so-called underground economy for inexperienced cybercriminals. Many users start out carrying out DDoS attacks for supposedly harmless reasons (such as gaming advantages) and can then drift into more criminal activities.

A long-term strategy since 2018

Operation "Power Off" is not an isolated measure, but has been running since 2018 as a long-term strategy. It is supported by Europol and the European Cybercrime Centre (EC3). Over the years, a large number of service platforms for DDoS attacks have already been identified and taken offline. The current operation represents a new "sprint" in this ongoing fight.

International cooperation is essential

The involvement of authorities from 21 countries shows that cybercrime knows no national borders and can only be fought effectively through cross-border cooperation. One perpetrator is in Thailand, the servers are distributed globally, the users are worldwide – without international coordination, a successful intervention would be impossible.

Criminal consequences and deterrent effect

Carsten Meywirth, Director at the Federal Criminal Police Office and Head of the Cybercrime Division, emphasises: "Operating and using stresser services is a criminal offence and has tangible consequences." This is a clear message to potential users – especially to young people who may underestimate the legal implications of their actions.

The combination of repressive measures (shutting down services, arrests, seizing servers) and preventive measures (contacting 50,000 users, shutting down communication platforms, awareness films) is intended to achieve a multi-layered deterrent effect.

Relevance for companies and critical infrastructure

For operators of websites, online services and critical infrastructure, this operation is highly significant. It underlines the ongoing threat posed by DDoS attacks and at the same time shows that law enforcement agencies are actively tackling the infrastructure behind such attacks.

The fact that potentially millions of people had access to stresser services also means that every company must reckon with DDoS attacks. An adequate security infrastructure and DDoS protection measures are therefore not optional, but necessary. This applies in particular to companies with an internet presence and to operators of critical infrastructure.

Outlook: The future of fighting cybercrime

The BKA signals that it will continue to rely on close cooperation with international partners in future. Operation "Power Off" is an example of a systematic, long-term approach – not a one-off action, but a continuous process.

The data obtained on three million users suggests that further investigations will follow. The authorities now have the means to identify individual users and take action against them. This will presumably lead to a wave of criminal proceedings against users of stresser services – particularly in Germany and the 21 participating countries.

The clear message to potential offenders is: "The long arm of the law reaches into the virtual world too and is pulling more and more of those responsible out from behind the shelter of supposed anonymity." Cybercrime is no longer an anonymous activity – and it does not pay.