Sunday , September 13 2026

Law Enforcement Lures Cybercriminals With Fake DDoS Services

That booter website you just paid $100 to launch a distributed denial-of-service attack – are you sure it’s not a front for the cops?

No, of course it’s not. Wait, is it? The National Crime Agency in Britain says it is running multiple, real-looking cybercrime service sites designed to identify suspects at home and abroad. But you’re not falling for it. Are you?

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

That’s the mind game the U.K. counterpart to the FBI is after among the clientele of DDoS-for-hire, aka stresser/booter, services. These offer a simple, easy-to-use interface via which users can sign up, pay for credit and then order disruptions of specific websites, all in just a few minutes.

How many sites the NCA is running and what it offers aren’t exactly clear – a ploy at the heart of this newly disclosed effort, part of Operation PowerOff. Authorities say it’s designed to sow confusion and doubt and undermine trust in the criminal market. Paranoia, they hope, runs deep.

Call it an escalation in the never-ending fight against booter sites, which allow individuals with little technical ability to easily commit cybercrimes.

“Booter/stresser services are like grass: You can mow the lawn, but the grass will grow back,” Daniel Smith, head of research for cybersecurity firm Radware’s threat intelligence division, told me. “The problem with enforcement is the reaction. As law enforcement worldwide steps up their efforts to reduce crime, the criminals will escalate in lockstep, as there is too much profit involved in cybercrime for everyone to be scared away.”

Fostering uncertainty among customers is another way to attempt to reduce the proliferation of booter sites. Here’s what the NCA has confirmed: It’s running multiple fake booter websites “which have so far been accessed by around several thousand people.”

“Users based in the U.K. will be contacted by the National Crime Agency or police and warned about engaging in cybercrime. Information relating to those based overseas is being passed to international law enforcement,” the agency says.

Last December, the FBI, together with the NCA, Dutch police and Europol, collectively shuttered 48 big booter sites. One site alone is tied to more than 30 million attacks.

These services can pose a risk to public safety. “Such attacks have the potential to cause significant harm to businesses and critical national infrastructure and often prevent people from accessing essential public services,” the NCA said (see: Hacktivist Pleads ‘Not Guilty’ in Children’s Hospital DDoS Attack).

Individuals can always, of course, build their own botnet to launch DDoS attacks. Booter websites are a shortcut past that time-consuming and technically intensive task, often taken by low-level would-be hackers who might actually pause over disclosing payment card details if they thought police could be on the other side.

DDoS-for-hire services typically offer attractive price points, oftentimes “for as little as $30 per month,” DDoS mitigation firm Cloudflare reports. “The more you pay, the larger and longer of an attack you’re going to get.”

Behind the scenes, real stresser services can rely on several different strategies to fuel their disruptions. “Most booter/stresser services are powered by a combination of botnets comprised of IoT devices and cloud services as well as servers that allow spoofing, enabling operators to offer a wide variety of attack vectors to their clients,” Smith said.

Check Also

picture

Navigating the Cyber Threat Landscape – Digital bank, Bangladesh perspective

Digital banking has played a pivotal role in expanding financial access for millions in Bangladesh, …