Security News

Authorities Take Down Long-Running DDoS-for-Hire Service NightmareStresser

CyberScoop · 17 Sept 2026
Key Takeaway Small businesses should ensure they have DDoS mitigation measures (such as traffic filtering or a content delivery network) in place, since these attack services remain cheap and accessible despite law enforcement crackdowns.

The US Justice Department announced the seizure of the primary domain and associated websites for NightmareStresser, one of the most popular and long-running distributed denial-of-service (DDoS) operations used by cybercriminals worldwide. The service allowed customers to pay for attacks that flood websites, servers and networks with junk traffic, knocking legitimate sites offline.

The takedown is part of an ongoing international effort called Operation PowerOFF, which targets IP stressers and DDoS booter services. It was carried out by the FBI's Anchorage field office alongside the Royal Canadian Mounted Police. Authorities have now seized more than 100 domains linked to DDoS-for-hire services since 2018, though the operators of NightmareStresser have not been identified. A threat researcher noted the service claimed to operate under Russian law.

According to officials, NightmareStresser's customers targeted educational institutions, government agencies, gaming platforms and millions of individuals in the US and abroad. Experts say many users of such services are not sophisticated hackers but opportunistic individuals using them for pranks, disputes or political statements, often against gaming servers and streamers. Despite this and other takedowns, similar tools remain widely available online, often with easy-to-follow instructions for non-technical users.

DDoS law enforcement cybercrime Operation PowerOFF network security

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.