Hundreds of thousands of DDoS attacks can be traced back to a service that just lost its front door to the FBI.
U.S. authorities have seized domains associated with NightmareStresser, which the Justice Department describes as “one of the world’s longest-running” DDoS-for-hire operations. Investigators say the platform facilitated hundreds of thousands of actual or attempted attacks worldwide since 2022.
Booter services lower the technical barrier to DDoS attacks by putting attack infrastructure behind a paid web interface. Taking NightmareStresser’s domains offline disrupts one major access point, but it does not mean the wider DDoS-for-hire ecosystem has disappeared.
How authorities took NightmareStresser offline
NightmareStresser was not simply a website selling DDoS software. It operated as a booter service, giving customers a web-based way to rent attack infrastructure and direct DDoS traffic at a target.
According to BleepingComputer, the platform called itself the “#1 online IP booter” while claiming to offer such services round the clock — a claim the FBI has now put to the test.
A 2023 investigation by Searchlight Cyber found that the platform had more than 566,000 registered users and operated 52 dedicated servers, with an advertised attack capacity of up to 200 Gbps.
Authorities say the service was subsequently used in hundreds of thousands of actual or attempted attacks against victims worldwide since 2022, including educational institutions, government agencies and other organizations.
The FBI's action targeted the service's domains, which covered nightmare-stresser.com and nightmarestresser.org. Control of the domains was transferred to the U.S. government, and visitors are now shown an FBI seizure notice.

The Department of Justice (DOJ) says the FBI's Anchorage Field Office and the Royal Canadian Mounted Police (RCMP) helped carry out the operation as part of Operation PowerOFF, a wider international effort targeting DDoS-for-hire platforms.
DDoS attacks are getting larger and easier to launch
NightmareStresser’s advertised attack capacity of up to 200 Gbps is modest compared with the largest DDoS attacks now being observed in the wild. Cloudflare says it mitigated 935 network-layer attacks exceeding 1 Tbps in the first half of 2026, including 805 in Q2 alone.
The problem is not only that attacks are getting bigger. DDoS has become increasingly industrialized, with booter services, botnets, and automated tools turning attack capabilities into something you can rent rather than build.
That mirrors a broader pattern across cybercrime: specialized capabilities are increasingly packaged into ready-made services and kits, lowering the technical barrier for would-be attackers. NightmareStresser fits directly into that model, giving customers access to attack infrastructure without requiring them to build or operate it themselves.
That makes its seizure a big win regardless: it disrupts not just the service, but potentially thousands of others that rely on it, even though they will probably look elsewhere until those, too, get booted out of service.
What this means for enterprises at risk
For organizations, the takeaway is not to assume that seizing a major DDoS service means the threat is gone.
DDoS-for-hire operations can move domains, rebuild infrastructure, or lose customers to competing services. Businesses with internet-facing services should therefore maintain upstream DDoS mitigation, monitor unusual traffic patterns, test failover procedures, and make sure incident-response teams know how to contact hosting, cloud, and network providers during an attack.
For users and smaller enterprises, the risk lies in an increase in attackers rather than highly skilled ones. That makes the resilience measures mentioned above more important as the cost of launching these attacks continues to fall while their capacity rises.
The FBI can remove one provider from the market, but it cannot remove the demand behind DDoS-for-hire services. For defenders, resilience still matters more than any single takedown.
Other news: Researchers uncovered six flaws in stolen-device reporting systems that could let attackers blacklist legitimate phones from cellular networks and even disrupt cellular backup connections used by home security systems.





