| Source1 | PublisherEuropol | Published2026-06-24 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial multi-agency infrastructure totals. The action disrupted named malware networks but does not prove every operator, credential, or replacement path was eliminated. | SourceGlobal cyber strike disrupts SocGholish, Amadey and StealC malware networks https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks |
| Source2 | PublisherU.S. Department of Justice | Published2026-06 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial backend-seizure and financial-pressure reporting. It does not establish complete removal of Huione-linked fraud or laundering services. | SourceJustice Department Seizes Backend Infrastructure Used by Huione Group Money Laundering Services https://www.justice.gov/opa/pr/justice-department-seizes-backend-infrastructure-used-huione-group-money-laundering-services |
| Source3 | PublisherU.S. Department of Justice | Published2026-06 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial legal-pressure reporting about one defendant. It is not evidence of a new Conti infrastructure takedown or complete successor disruption. | SourceUkrainian National Pleads Guilty to Wire Fraud Conspiracy in Connection with Conti Ransomware https://www.justice.gov/opa/pr/ukrainian-national-pleads-guilty-wire-fraud-conspiracy-connection-conti-ransomware |
| Source4 | PublisherU.S. Department of Justice | Published2026-06 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial AudiA6/Dark2Web arrest, charge, and infrastructure-action reporting. It does not prove all customers or successor laundering services were identified. | SourceTwo Charged in Connection with Cryptocurrency Money Laundering Service https://www.justice.gov/usao-edpa/pr/two-charged-connection-cryptocurrency-money-laundering-service-allegedly-laundered |
| Source5 | PublisherEuropol | Published2026-06 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial enabling-service dismantlement reporting. It does not prove that all downstream users or replacement services were removed. | SourceCybercriminal VPN used by ransomware actors dismantled in global crackdown https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown |
| Source6 | PublisherEuropol | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentOnline ecosystem disruption and referral/removal row only; do not treat as a full cybercrime infrastructure takedown, ransomware action, actor eradication, platform-wide remediation, or proof that all The Com-linked subgroups, victims, accounts, or successor channels were identified or removed. | SourceEuropol The Com Referral Action Days Online Ecosystem Disruption https://www.europol.europa.eu/media-press/newsroom/news/europol-led-action-against-nihilistic-violent-extremist-network-com |
| Source7 | PublisherBKA / ZIT | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentPhaaS infrastructure dismantlement and administrator-arrest row; do not treat as proof that every Kratos customer, stolen credential, downstream account takeover, or successor phishing kit was identified, remediated, or permanently disrupted. | SourceBKA / ZIT Kratos Phishing-as-a-Service Infrastructure Dismantlement https://www.bka.de/SharedDocs/Kurzmeldungen/DE/Kurzmeldungen/260720_Schlag_gegen_Phishing_Gruppierung_Kratos.html |
| Source8 | PublisherNCA | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentSentencing and activity-degradation row only; do not treat as a full actor takedown, infrastructure seizure, decryptor release, or proof that all actors using the Scattered Spider brand or tradecraft stopped. | SourceScattered Spider TfL Sentencing and Activity-Degradation Assessment https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case |
| Source9 | PublisherNCA / Nigerian Police Force / Meta | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentScam-centre arrest and device-seizure row only; do not treat as full fraud-network dismantlement, victim remediation, platform-wide scam removal, or proof that related laundering routes were eliminated. | SourceNCA / Nigeria / Meta Scam Centre Arrests https://www.nationalcrimeagency.gov.uk/news/nca-intelligence-sharing-leads-to-arrest-of-suspected-fraudsters |
| Source10 | PublisherNCA | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentCharges and fraud-platform legal-pressure row only; do not treat as a full takedown, infrastructure seizure, victim-risk elimination, or proof that all users or replacement spoofing services were disrupted. | SourceRussian Coms Fraud Platform Charges https://www.nationalcrimeagency.gov.uk/news/five-charged-in-nca-investigation-into-fraud-platform-responsible-for-millions-of-scam-calls |
| Source11 | PublisherDOJ | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentCharges and legal-pressure row only; do not treat as a full scam-center takedown, bank-account seizure, victim remediation, laundering-network dismantlement, or proof that successor laundering routes were eliminated. | SourceChinese Money Laundering Network Investment-Fraud Charges https://www.justice.gov/opa/pr/two-key-members-chinese-money-laundering-network-charged-laundering-43-million-investment |
| Source12 | PublisherDOJ | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentIndictment and legal-pressure row only; do not treat as a fresh server seizure, hosting-service takedown, ransomware-group takedown, or proof that all customers lost replacement infrastructure. | SourceMedia Land / ML.Cloud Bulletproof Hosting Indictment https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more |
| Source13 | PublisherSpanish National Police | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentFraud and laundering-network disruption; do not treat as complete victim remediation, full fraud-ecosystem dismantlement, or proof that all mule accounts, shell companies, or successor laundering routes were eliminated. | SourceSpanish Police Cyber Fraud and Laundering Network Dismantlement https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16947 |
| Source14 | PublisherINTERPOL | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentBroad fraud and laundering disruption; do not treat as full dismantlement of all participating scam centers, social-engineering operations, laundering routes, or criminal syndicates. | SourceOperation First Light 2026 Global Fraud Disruption https://www.interpol.int/en/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust |
| Source15 | PublisherTreasury / FBI | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentSanctions and takedown follow-on row; do not treat as a new July infrastructure seizure, ransomware-group takedown, cryptor-market removal, decryptor release, or proof that all customers or affiliates lost replacement services. | Source1VPNS / Ransomware Cryptor Enabler Sanctions and Takedown Follow-On https://home.treasury.gov/news/press-releases/sb0559 |
| Source16 | PublisherUK FCDO / Council of the EU | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentSanctions, attribution, and reconstitution-watch row; do not treat as a law-enforcement takedown, Lumma infrastructure seizure, malware eradication, arrest action, or proof that credential-theft activity stopped. | SourceUK/EU Russian Cyber Networks and Lumma Stealer Sanctions https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions |
| Source17 | PublisherGoogle / FBI | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentPublic-private disruption and reported FBI-coordinated action; do not treat as proof every infected device, reseller, customer, or successor proxy network was remediated or permanently removed. | SourceNetNut / Popa Residential Proxy Network Disruption https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks |
| Source18 | PublisherDOJ | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentArrest and indictment update only; do not treat as Scattered Spider takedown, infrastructure removal, or activity halt. | SourceScattered Spider Member Arrest and Extradition https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and |
| Source19 | PublisherDOJ | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentOperator/legal and financial-seizure row only; do not treat as a new BlackCat infrastructure takedown, ransomware-group disruption, decryptor release, or proof that all insider-enabled ransomware risk was eliminated. | SourceBlackCat/ALPHV Insider Sentencing and Asset Seizure https://www.justice.gov/usao-sdfl/pr/land-olakes-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims |
| Source20 | PublisherDOJ | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentGuilty-plea and extradition row only; do not treat as a Ryuk infrastructure takedown, decryptor release, active-ecosystem disruption, or proof that all Ryuk-linked tooling or successors were neutralized. | SourceRyuk Ransomware Guilty Plea and Extradition Legal Pressure https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy |
| Source21 | PublisherDOJ | PublishedMay 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentArrest follow-up to an existing botnet disruption; not a separate proof of full botnet eradication or device remediation. | SourceKimWolf DDoS Botnet Administrator Arrest https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos |
| Source22 | PublisherDutch Police / NCSC | PublishedMay 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentBotnet infrastructure disruption and server action; do not infer all infected devices were cleaned, all operators were arrested, or any associated residential-proxy service was permanently eliminated. | SourceDutch Police / NCSC Large Botnet Disruption https://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html |
| Source23 | PublisherDOJ | PublishedMay 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentTreat as infrastructure disruption, not full actor capability removal. | SourceGRU DNS Hijacking Network Disruption https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled |
| Source24 | PublisherDOJ | PublishedAug 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentGuilty-plea and legal/operator-pressure row; do not treat as a full takedown, infrastructure seizure, victim remediation, SaaS-provider compromise finding, sentencing outcome, eradication of data-sale channels, or proof that all co-conspirators, stolen records, credentials, or successor extortion workflows were neutralized. | SourceCloud Storage / SaaS Customer Extortion Guilty Plea https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers |
| Source25 | PublisherDOJ | PublishedAug 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentSentencing, legal/operator-pressure, and prior arrest-disruption row; do not treat as a fresh 2026 infrastructure seizure, full ransomware-operation takedown, decryptor release, victim remediation, recovery distribution, conviction of all co-conspirators, or proof that all Ransom Cartel tooling, stolen data, credentials, affiliates, or successor workflows were neutralized. | SourceRansom Cartel Creator Sentencing and Prior Arrest Disruption https://www.justice.gov/usao-edva/pr/belarusian-leader-international-ransomware-scheme-known-ransom-cartel-sentenced-16 |
| Source26 | PublisherGoogle / FBI reporting | PublishedJun 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentPhaaS/smishing infrastructure disruption and civil/legal pressure row; do not treat as proof that every phishing customer, stolen credential, payment-card exposure, SMS route, AI-enabled scam workflow, or successor kit was identified, remediated, or permanently disrupted. | SourceOutsider Enterprise PhaaS / Smishing Infrastructure Disruption https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/ |
| Source27 | PublisherU.S. Secret Service | PublishedJul 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentFinancial seizure/freezing and civil-forfeiture row; do not treat as a full scam-network takedown, arrest, conviction, victim reimbursement guarantee, complete laundering-route dismantlement, or proof that all fake investment platforms, recovery scams, or successor wallet clusters were remediated. | SourceSecret Service WFO Cryptocurrency Scam Seizures and Civil Forfeiture https://www.secretservice.gov/newsroom/releases/2026/07/us-secret-service-washington-field-office-investigations-result-seizure |
| Source28 | PublisherINTERPOL | PublishedMay 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentRegional cybercrime disruption and arrest row; do not treat as full eradication of MENA phishing, malware, scam, trafficking-linked fraud, or compromised-device ecosystems, and keep victim notification/device securing separate from guaranteed remediation. | SourceOperation Ramz MENA Cybercrime Disruption https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region |
| Source29 | PublisherU.S. Secret Service | PublishedAug 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentLocal fraud-infrastructure disruption and prevention row; do not treat as a cybercrime ecosystem takedown, arrest, indictment, sanctions action, full skimming-network dismantlement, victim remediation, credential/payment-card containment guarantee, or proof that all successor skimming activity stopped. | SourceSecret Service Operation Heat Check Skimming-Device Disruption https://www.secretservice.gov/newsroom/releases/2026/08/us-secret-service-miami-field-office-operation-heat-check-nets-13-illegal |
| Source30 | PublisherDOJ | PublishedAug 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentSuperseding-indictment and legal/operator-pressure row only; do not treat as a takedown, infrastructure seizure, sanctions designation, arrest, victim remediation, credential containment, disruption of Megapaper or Gigapaper availability, or proof that all Mabna Institute-linked hacking-for-hire activity stopped. | SourceMabna Institute Cyber-Theft Superseding Indictment https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary |
| Source31 | PublisherDOJ | PublishedJun 2026 | Publication / evidenceSource indexofficial | Why used / claim treatmentPublic-private account and financial disruption; do not treat as full dismantlement of Southeast Asia scam compounds, all fraud accounts, all laundering routes, or all organized-crime operators. | SourceScam Center Strike Force Disruption Week https://www.justice.gov/opa/pr/scam-center-strike-force-announces-results-us-private-industry-disruption-week |