This DDoS Shop Sold Disruption for Years Before the FBI Seized Its Domains
An organisation does not have to be an attractive espionage target to become the victim of a cyberattack. Sometimes someone only has to want its website unavailable and be willing to pay a service to make that happen. A US takedown this week targets one of the long-running shops selling that disruption.
The US Department of Justice announced court-authorised domain seizures associated with NightmareStresser on 15 September, updating the announcement on 16 September. According to the seizure-warrant affidavit cited by the department, the service was used for hundreds of thousands of actual or attempted distributed denial-of-service attacks worldwide since 2022. That wording does not establish the same number of successful attacks or unique victims.
The target is the market for interruption
The action involved FBI Anchorage and the Royal Canadian Mounted Police and formed part of Operation PowerOFF. The department describes services marketed as booters or stressers as a low-barrier route to criminal attacks against schools, government services, businesses and other online platforms. The announcement reports domain seizures, not a declaration that all infrastructure, users or other DDoS services have disappeared.
For a business, the practical significance is the gap between the attacker’s effort and the defender’s cost. Buying an interruption can be straightforward. Absorbing it may mean lost transactions, diverted staff and a hurried public response. That asymmetry is BlackTree’s assessment of the risk, not a financial estimate for the victims in this case.
A takedown is a useful moment to rehearse your own response
Organisations should welcome disruption of criminal services without treating it as a reason to downgrade resilience. The useful next step is a bounded operational check: if the site stops responding, can the team distinguish overload from an application failure, and can it reach the people able to help?
- Identify the services whose interruption matters. Include customer-facing applications, DNS dependencies and access routes the response team itself needs. Set priorities around business impact rather than treating every endpoint as equally important.
- Confirm the mitigation contact and process. Know which hosting, network or protection provider handles each layer, how to reach it during an incident and what information it needs. Do not discover account ownership while traffic is already failing.
- Exercise a realistic outage decision. Test the escalation and communications process without generating harmful traffic. Who can authorise emergency assistance, and who decides what customers should be told?
- Preserve useful evidence. Agree how relevant traffic and service records will be retained and shared with responders. Collect only what the investigation needs and handle customer information appropriately.
- Check that recovery includes validation. Once service returns, confirm the application and its dependencies are functioning normally. Record what failed, which controls helped and which operational gaps remain.
These are preparedness recommendations, not an allegation that an organisation has been attacked by NightmareStresser. A service outage alone cannot establish an actor or even prove malicious traffic is the cause.
The authorities have removed a route through which people could purchase disruption. The question for defenders is whether their response still depends on a scramble through old emails and expired contact lists. Criminal convenience should not be matched by organisational uncertainty.
Sources
- US Department of Justice, FBI seizure of DDoS-for-hire domains associated with NightmareStresser, published 15 September and updated 16 September 2026.


