Operation Eastwood, coordinated by Europol and Eurojust in July 2025, disrupted major parts of the pro-Russian NoName057(16) DDoS infrastructure and led to arrests, warrants and formal warnings. Official accounts describe a significant disruption and continuing investigation—not proof that the network has been permanently eliminated.
What happened in Operation Eastwood?
Law-enforcement agencies coordinated activity from 14 to 17 July 2025, with the main action on 15 July. Authorities in Germany, Latvia, Spain, Italy, Czechia, Poland and France carried out searches and took parts of the network’s central server infrastructure offline.
Europol and Eurojust presented the operation as an international action against NoName057(16), a hacktivist network that uses distributed-denial-of-service (DDoS) attacks. Eurojust defines a DDoS attack as flooding a website or online service with traffic until its capacity is overloaded and the service becomes unavailable.
How large was the disruption?
| Measure | What authorities reported | Attribution and qualification |
|---|---|---|
| Attack infrastructure | More than 100 computer systems worldwide disrupted | Eurojust and Europol operational accounts, July 2025 |
| Botnet | Hundreds of computer systems shut down | Eurojust description of the network’s own botnet |
| Malware participants | About 4,000 users downloaded software that enabled participation in DDoS attacks | Eurojust estimate |
| Supporters notified | About 1,100 people warned about potential criminal liability | Eurojust account of the operation |
| Administrators notified | 17 administrators warned about criminal-liability consequences | Eurojust account of the operation |
The figures describe systems and people reached by the operation; they do not establish that every participant was identified, arrested or charged.
Recommended Free Tools
#1 Best Overall
Arrests, searches and warrant counts
Two suspects were arrested, one in France and one in Spain. The legal totals differ between official releases because they refer to different jurisdictions and stages of the proceedings.
| Authority and date | Figure reported | How to read it |
|---|---|---|
| Eurojust, 16 July 2025 | Seven international arrest warrants | Eurojust’s consolidated international figure, including warrants for suspected main instigators believed to be living in Russia |
| Dutch police, July 2025 | Eight warrants issued by Germany, Spain and France | A national account covering the warrants reported by those issuing countries |
| Dutch police, July 2025 | 24 searches | Search activity reported in the Dutch account; it should not be treated as a replacement for Eurojust’s international total |
These numbers should not be merged into one total. They reflect separate authorities, legal processes and reporting dates, and they are not convictions.
Who is NoName057(16)?
European authorities characterize NoName057(16) as an ideologically motivated hacktivist group that publicly supports the Russian Federation and attacks Ukraine and countries aligned with NATO.
The crowd-sourced DDoSia model
The group recruited supporters through messaging services and distributed malware that allowed participants to contribute their computers to attacks. It also maintained a botnet made up of hundreds of servers. This combination gave the network a large pool of volunteer-controlled devices alongside infrastructure managed by the group itself.
Rank #3
The model is often described as crowd-sourced DDoS activity: the operators coordinate targets and tooling, while many participants supply computing resources. Downloading the software or joining a campaign does not by itself establish that a person was prosecuted, which is why authorities’ warnings about possible liability matter.
Which countries and services were targeted?
| Location or period | Reported targets and incidents |
|---|---|
| Germany | Eurojust recorded 14 attacks affecting about 230 organisations, including arms factories, power suppliers and government organisations. |
| Sweden | Authorities and bank websites were targeted. |
| Switzerland | Attacks coincided with a Ukrainian president’s parliamentary video message and the 2024 Ukraine Peace Summit. |
| Netherlands | Targets were reported around the June 2025 NATO Summit. |
| Broader European pattern | ENISA identified public-administration sites, ministries, parliamentary websites, municipalities, banks, payment providers, air and rail services, telecoms and hosting as recurring target types. |
The targets were generally public-facing services whose disruption could attract attention or inconvenience users, rather than evidence of long-term control over industrial systems.
Rank #4
What ENISA says about the campaign’s scale and impact
ENISA’s Threat Landscape 2025, published in October 2025, found that NoName057(16) sustained the highest operational tempo among five leading hacktivist groups. ENISA linked that pace in part to the group’s crowd-sourced DDoSia model.
Share of EU hacktivist activity by sector
| Sector | Share reported by ENISA |
|---|---|
| Public administration | 63.1% |
| Transport | 12% |
| Finance | 11.7% |
| Digital infrastructure | 5.4% |
| Manufacturing | 4% |
| Media and entertainment | 4% |
Share of DDoS attacks against EU digital-infrastructure services
| Group or category | Share reported by ENISA |
|---|---|
| All hacktivist-led DDoS activity | 57.5% of attacks against EU digital-infrastructure services |
| NoName057(16) | 33.8% of those incidents |
| Keymous+ | 21.4% |
| Mr Hamza | 6.5% |
High activity volume did not translate into widespread confirmed downtime. ENISA wrote that NoName057(16)’s activity led to almost no confirmed outages and that “the overall impact of DDoS activities remained marginal.” That gap between the number of attacks and measurable disruption supports ENISA’s assessment that the campaigns also served an information-operation purpose: demonstrating activity, generating publicity and creating pressure even when services recovered quickly.
Best Value
Was the network taken down permanently?
No permanent end has been established. Operation Eastwood removed more than 100 systems and major central infrastructure from operation, but the official statements describe disruption, arrests, warrants and ongoing investigative work. They do not establish that every server, administrator or participant was identified, nor do they report final convictions.
DDoS networks can regenerate when operators replace servers, recruit new participants or redistribute tooling. A takedown can therefore reduce capacity and expose organizers without guaranteeing that attacks stop indefinitely.
What service operators should take from the operation
The incidents show why public-facing organisations need plans for short, politically motivated traffic floods as well as conventional criminal attacks.
- Mitigation capacity: confirm that upstream providers can absorb attack volumes beyond the organisation’s normal bandwidth.
- Filtering speed: define who can activate rate limits, traffic challenges, scrubbing or emergency routing and how quickly they can do so.
- Geographic coverage: check whether protection extends to every region where users and services are hosted.
- Public-facing infrastructure: map government portals, payment pages, transport systems, DNS, APIs and other internet-dependent services that may be targeted together.
- Logging and forensics: retain traffic, firewall, DNS and application logs so an incident can be distinguished from a brief service fault and evidence can be shared with investigators.
- Regulatory and public-sector coordination: establish contacts and notification procedures before an incident, particularly for essential or publicly funded services.
Those measures improve resilience regardless of whether an attack is linked to NoName057(16) or another group.
The bottom line
European authorities achieved a substantial, multinational disruption of NoName057(16)’s DDoS infrastructure in July 2025, including server seizures, arrests, warrants and warnings to thousands of alleged supporters and administrators. The operation reduced the network’s operating base, but ENISA’s later assessment shows why attack counts should not be confused with lasting outages—and why Eastwood should be treated as a major intervention, not a guaranteed final takedown.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




