A major DDoS-for-hire operation has been disrupted after U.S. authorities seized internet domains linked to NightmareStresser, a long-running service allegedly used to launch hundreds of thousands of distributed denial-of-service attacks against targets worldwide.
The court-authorized seizures, carried out by the FBI Anchorage Field Office with the Royal Canadian Mounted Police (RCMP), form part of Operation PowerOFF, an international effort to dismantle the infrastructure behind criminal DDoS-for-hire services. The case highlights how easily disruptive cyberattacks can now be purchased and launched and why organizations need to treat internet availability and resilience as core cybersecurity priorities.
The U.S. Department of Justice announced the court-authorized seizures on September 15, saying the operation was part of a continuing crackdown on so-called “booter” and “stresser” services, platforms that allow customers to pay for DDoS attacks without having to operate the underlying infrastructure themselves. The action was led by the FBI Anchorage Field Office, in coordination with the Royal Canadian Mounted Police (RCMP), and conducted as part of the broader international Operation PowerOFF.
The case is another reminder that DDoS attacks are no longer limited to technically sophisticated threat actors. Commercialized attack services have lowered the barrier to entry, allowing individuals with relatively little technical knowledge to purchase the ability to disrupt websites, networks and online services.
NightmareStresser allegedly powered hundreds of thousands of attacks
According to an affidavit supporting the seizure warrant, the NightmareStresser service was used for hundreds of thousands of actual or attempted DDoS attacks against victims worldwide since 2022.
The victims of booter services can range from schools and government agencies to gaming platforms, businesses and individual users. A sufficiently large attack can overwhelm network bandwidth or consume server resources, making an online service slow or completely inaccessible.
The DOJ said the infrastructure targeted in the latest operation was being used to facilitate attacks against victims in Alaska and elsewhere in the United States, while the broader activity associated with the service extended internationally.
For organizations operating public-facing digital services, the disruption can go beyond a temporary website outage. An attack can interfere with customer access, online transactions, remote services, communications and other business-critical functions.
And unlike some highly specialized cyberattacks, launching a DDoS attack through a booter service does not necessarily require the attacker to build a botnet or develop sophisticated malware.
That accessibility is precisely what makes the ecosystem attractive to less-skilled cybercriminals.
What are “booter” and “stresser” services?
The terms “booter” and “stresser” are commonly used for DDoS-for-hire services.
The basic model is straightforward: a customer pays an operator, provides a target and requests an attack. The service operator supplies the infrastructure needed to generate large volumes of traffic against the target.
The FBI describes these platforms as services advertised through online forums, websites and, in some cases, dark-web marketplaces. Some operators also sell access to botnets made up of compromised devices.
The word “booter” comes from the intended result — effectively “booting” a target off the internet.
While legitimate organizations can conduct controlled stress testing of their own infrastructure, law-enforcement agencies distinguish such authorized testing from criminal DDoS-for-hire activity. The FBI says participating in DDoS attacks or using booter and stresser services to conduct attacks is illegal and can result in criminal prosecution under U.S. federal law.
Operation PowerOFF targets the business behind DDoS attacks
The NightmareStresser seizure is not an isolated takedown.
It forms part of Operation PowerOFF, an international law-enforcement effort focused on disrupting the infrastructure and operators behind DDoS-for-hire services.
The latest operation also builds on years of investigations by prosecutors and investigators in Alaska and Los Angeles. According to the DOJ, those cases have resulted in charges against 12 defendants who allegedly facilitated DDoS-for-hire services and the seizure of more than 100 internet domains associated with such operations.
The strategy is significant because authorities are targeting the commercial infrastructure that makes DDoS attacks accessible in the first place.
Rather than responding to individual attacks one at a time, law enforcement is attempting to disrupt the services, domains and operators that enable large numbers of attacks.
The FBI has previously described partnerships with domestic and international agencies as critical to addressing the DDoS threat, reflecting the fact that attack infrastructure, service operators and victims can all sit in different jurisdictions.
Why businesses should pay attention
A domain seizure does not eliminate the DDoS threat.
Attack-for-hire services can disappear and reappear under different names, infrastructure or domains. Compromised IoT devices, routers, servers and other internet-connected systems can also continue to provide attackers with the capacity to generate malicious traffic.
For businesses, the lesson is therefore less about NightmareStresser itself and more about resilience.
Organizations should assume that internet-facing services may eventually be tested by malicious traffic and prepare accordingly.
This is particularly important for organizations whose operations depend heavily on digital availability: banks and financial institutions, telecommunications companies, cloud services, online retailers, government portals, universities, healthcare organizations, gaming platforms and critical infrastructure providers.
A DDoS attack may not compromise confidential information. It can still create a serious business incident if customers, employees or citizens cannot reach an essential service.
The MEA perspective: availability is becoming a cybersecurity issue
For organizations across the Middle East and Africa, the issue is equally relevant.
Governments and businesses across the region are rapidly expanding digital services, cloud adoption, e-commerce, online banking and digitally enabled public infrastructure. As more services become internet-dependent, availability becomes an increasingly important part of cybersecurity and operational resilience.
For organizations with limited cybersecurity resources, DDoS protection is sometimes treated as a secondary requirement behind endpoint security, identity management or data protection.
That approach can leave a gap.
A service does not need to be breached for an organization to suffer a cybersecurity incident. If customers cannot access the service, transactions cannot be completed or a public-facing government platform becomes unavailable, the operational consequences can still be significant.
This is why cybersecurity planning should address the full availability lifecycle prevention, detection, response, communications and recovery.
Organizations can also use professional cybersecurity training and awareness programs to ensure that technical teams, executives and operational staff understand their respective roles during a DDoS incident.
Ten actions security teams should take now
1. Identify your internet-facing assets
Maintain an up-to-date inventory of public IP addresses, domains, APIs, applications, VPN gateways, DNS infrastructure and cloud services. You cannot adequately protect infrastructure that your security team does not know exists.
2. Establish DDoS protection before an attack
Work with your ISP, cloud provider or specialized DDoS mitigation provider to determine what protections are available. Depending on the environment, this may include traffic scrubbing, rate limiting, CDN-based protection, upstream filtering or anycast distribution.
3. Define acceptable traffic thresholds
Know what normal traffic looks like for critical services. Establish baselines for bandwidth, requests per second, geographic distribution and application behavior so abnormal traffic can be detected more quickly.
4. Protect critical applications separately
Not every service has the same business importance. Identify which systems are essential to revenue, public services, customer operations or safety and ensure they receive appropriate availability protections.
5. Build an incident response playbook for DDoS
Do not wait for the first attack to decide who should call the ISP, who communicates with customers and who makes technical changes. Establish roles, escalation paths and decision points in advance.
6. Maintain strong relationships with service providers
Make sure your network, hosting, cloud and DDoS mitigation providers know who to contact during an emergency. Confirm that escalation procedures work outside normal business hours.
7. Monitor DNS and domain infrastructure
Attackers may target more than the application itself. Monitor DNS availability, domain configuration and certificate infrastructure, and ensure that critical domains have appropriate redundancy.
8. Test your resilience
Conduct controlled, authorized resilience exercises. Organizations should understand how applications, firewalls, load balancers, DNS services and upstream providers behave when traffic increases sharply.
9. Train technical and non-technical teams
A DDoS incident quickly becomes a business problem. Security, IT, communications, customer service and executive teams should understand what happens during an attack and what information they can safely communicate.
For organizations looking to strengthen this capability, cybersecurity training, professional certification and awareness programs can help teams build the skills required to prepare for and respond to incidents.
10. Report serious attacks and preserve evidence
Keep logs, traffic records, timestamps, indicators and communications with service providers. Organizations affected by criminal DDoS activity should consider reporting the incident to relevant law-enforcement or national cyber authorities. In the United States, the FBI encourages victims to contact a local field office or report incidents through the Internet Crime Complaint Center (IC3).
DDoS-for-hire is becoming an ecosystem problem
The NightmareStresser case highlights a broader change in the cybercrime economy.
Attackers do not necessarily need to possess advanced technical skills when criminal infrastructure can be purchased as a service. DDoS-for-hire platforms effectively turn attack capability into a commodity.
That model creates problems for defenders because disruption can be initiated quickly, cheaply and remotely.
It also explains why international cooperation matters. A service may have customers in one country, infrastructure in another, compromised devices distributed across dozens of countries and victims somewhere else entirely.
No single organization can address that entire chain alone.
The FBI and DOJ’s continuing actions against DDoS-for-hire infrastructure demonstrate that law enforcement is increasingly targeting the services that enable attacks, not only the individuals who ultimately launch them. The latest operation with the RCMP is another example of that cross-border approach.
What organizations should take from the NightmareStresser seizure
The seizure of NightmareStresser domains removes part of an established DDoS-for-hire infrastructure, but it does not remove the underlying threat.
For security leaders, the more important question is whether their organization could continue operating if a large volume of malicious traffic arrived tomorrow.
That means treating availability as a core cybersecurity requirement rather than simply an IT performance issue.
The organizations that are best prepared will not necessarily be those that can prevent every DDoS attack. They will be the ones that understand their critical services, have appropriate upstream protections, know how to activate their response plans and can keep essential operations running while an attack is underway.
NightmareStresser may be disrupted. The business model behind DDoS-for-hire is unlikely to disappear overnight.
For defenders, resilience remains the longer-term answer.
Source: U.S. Department of Justice, U.S. Attorney’s Office for the District of Alaska, September 15–16, 2026; FBI.




