Between March 9 and March 19, 2026, law enforcement agencies from 23 countries quietly dismantled one of the largest networks of dark web platforms ever documented.
373,000 sites. Run by a single operator. Investigated for five years. And almost none of it worked the way customers expected.
That last detail is the part most coverage of Operation Alice glosses over. Because the story isn’t just about a record-breaking dark web takedown. It’s about a criminal who spent years scamming other criminals, built an automated empire of fraudulent marketplaces at a scale that’s genuinely difficult to comprehend, and in doing so handed investigators a ready-made list of 440 people who tried to buy something so serious that paying for it made them suspects, even though nothing was ever delivered.
Quick answer: Operation Alice, a 10-day global operation led by German authorities and supported by Europol, shut down more than 373,000 fraudulent dark web sites between March 9 and 19, 2026. All of the sites were operated by a single individual who took Bitcoin payments for illegal content and cybercrime services, but never delivered anything. The operator is believed to be a 35-year-old man based in China, with an international arrest warrant issued. 440 customers who attempted to purchase illegal content have been identified, and investigations against more than 100 of them are ongoing.
What Operation Alice Was Actually Targeting
The investigation didn’t start with 373,000 sites. It started with one platform called “Alice with Violence CP,” flagged by German investigators in mid-2021.
Β What began as a routine inquiry into a single dark web address grew into a five-year case that kept expanding the longer investigators looked. By the time the operation launched on March 9, 2026, the same single operator was confirmed to be running all 373,000 of those platforms simultaneously,all through the Tor network, all using .onion domains, and all serving essentially the same fraudulent purpose.
Understanding why one person could realistically maintain that volume requires understanding how these sites actually work. An onion domain is a special type of web address that routes traffic through the Tor network, hiding both the server’s location and the identity of anyone visiting it. Unlike a regular website, spinning up an onion domain requires no registration, no verified hosting account, and no real infrastructure cost. With the right automated tooling, generating and hosting thousands of onion domains becomes a technical problem, not a human bandwidth problem.
The operator didn’t manage 373,000 sites the way a business manages 373,000 employees. He ran scripts. The sites maintained themselves. As we’ve covered in our guide on the deep web and dark web, the Tor network makes this kind of infrastructure trivially easy to scale in ways the surface web doesn’t.
The Criminal-Scamming-Criminals Layer
Here’s the detail that makes Operation Alice genuinely different from most dark web takedowns.
None of it worked. The entire network was a fraud from the inside out.
Of the 373,000 sites, more than 90,000 advertised packages of child sexual abuse material, purchasable by providing an email address and paying in Bitcoin. Packages were priced between β¬17 and β¬215, with promises of data volumes ranging from a few gigabytes to several terabytes. Between February 2020 and July 2025, the operator was running this operation continuously. The total amount collected from customers is estimated at around β¬345,000.
Nothing was ever delivered. Every package was empty. Every transaction was a scam.
The same model applied to the cybercrime-as-a-service offerings on the remaining sites, stolen credit card data, access to compromised systems, hacking tools, fraud services. Customers paid in Bitcoin for services that were never fulfilled. The operator collected the cryptocurrency and disappeared from those transactions.
This is criminal-on-criminal fraud at industrial scale. The operator was exploiting the fact that his “customers” couldn’t complain to anyone, file a chargeback, or report the non-delivery to authorities without exposing their own intent to purchase illegal material. It’s a business model with no realistic avenue for victims to seek recoursewhich is exactly why it sustained itself for over five years before law enforcement caught up.
The broader fraudulent infrastructure angle also connects to what we’ve seen in other underground markets, as we covered in our piece on how threat actors vet stolen credit card shops, the dark web economy has its own internal fraud problem, with fake services regularly scamming the people trying to buy illegal goods.
The Customers Became Suspects
This is the legal point that deserves more attention than it’s received.
When Operation Alice identified 440 people who had used the operator’s services, investigators immediately launched additional criminal investigations against every one of them, despite the fact that none of them received any content or service in return for their payments.
In most criminal jurisdictions, attempting to purchase child sexual abuse material is a criminal offence regardless of whether the transaction is completed or whether any material is ultimately received. The act of intentionally paying for it constitutes the offence. The customer’s intent, evidenced by the Bitcoin payment and the email registration, is the element prosecutors need.
Europol made this explicit in its official statement: “By paying for CSAM, the customers themselves became suspects, even though they never received the material. Investigators assessed that individuals seeking access to exclusive β and therefore severe β child sexual abuse material could represent high-value targets and provide important intelligence for law enforcement worldwide.”
In other words, the 440 customers didn’t just expose themselves to a fraud. They handed investigators a list. Ongoing investigations continue against more than 100 of those individuals across multiple jurisdictions as of the operation’s close date. One conviction from a related case, a 31-year-old father prosecuted in 2023 for attempting to purchase 70GB of material, shows how early action on similar intelligence has already resulted in convictions.
How Investigators Traced the Bitcoin Payments
The operator’s choice of Bitcoin over more privacy-preserving cryptocurrencies like Monero turned out to be a significant operational security mistake, and it’s worth understanding why.
Bitcoin transactions are permanently recorded on a public blockchain. Every payment made by every customer is visible, not to the naked eye, but to blockchain analysis tools capable of tracing the flow of funds from wallet to wallet. Unlike Monero, which was designed specifically to obscure transaction parties and amounts, Bitcoin maintains a transparent ledger that law enforcement agencies and blockchain intelligence firms can read and trace.
Over a five-year investigation, German authorities and their international partners were able to work backward through those transactions, Β The Bitcoin payments customers made to access the platform created a traceable thread from the purchase to the customer’s wallet, and from those wallets to real-world identities in many cases. This is the same type of tracing that helped prosecutors build the AudiA6 laundering case, as we covered in the AudiA6 crypto laundering takedown piece where blockchain forensics proved essential to connecting criminal proceeds to real individuals.
The lesson the carding and dark web fraud community has been absorbing for years is relevant here: Bitcoin provides pseudonymity, not anonymity. In a long-running investigation with the resources of 23 national law enforcement agencies, that distinction matters enormously.
The 23-Country Operation: Who Was Involved
Operation Alice ran from March 9 to March 19, 2026, ten days of coordinated action across 23 countries. Europol provided analytical and coordination support, while national agencies carried out searches, seizures, and arrests within their own jurisdictions.
Ukraine was specifically highlighted as a participant, represented by the National Police of Ukraine, a notable inclusion given the country’s ongoing circumstances, and a reflection of how international cybercrime cooperation has expanded to include nations facing other significant pressures.
Physical results from the operation included the seizure of 105 servers spread across multiple countries, along with computers, mobile phones, and electronic data storage devices from associated suspects and customers. These devices feed the ongoing investigations against the 100+ remaining individuals under active scrutiny.
The main suspect, believed to be a 35-year-old man currently located in China, has not been arrested. An international arrest warrant has been issued, but extradition from China to European or Western jurisdictions is a process with a complex and often lengthy track record. The infrastructure has been seized and dismantled. The operator remains at large.
This outcome β seized servers, ongoing warrant, suspect in a jurisdiction with limited extradition cooperation, is a common pattern in major dark web cases. We’ve seen it in the Ransom Cartel case, where Maksim Silnikau’s co-conspirators remain at large after the lead defendant’s conviction. Taking down the infrastructure is faster than securing the operator, and the investigation continues whether or not the arrest is imminent.
Why 373,000 Sites Sounds Impossible, and Isn’t
The number is so large it invites skepticism. How does a single person operate more than 373,000 websites?
The answer comes down to automation and the specific characteristics of the Tor network. On the surface web, scaling to hundreds of thousands of domains requires significant financial investment, verified hosting accounts, and domain registration β all of which create paper trails. On the Tor network, generating onion domains is computationally simple and costs almost nothing. The address is derived from a cryptographic key pair. With the right software and a server capable of handling the traffic, one person with basic technical knowledge can generate and register thousands of .onion addresses in a short period.
The sites themselves were templated. The same fraudulent marketplace design, the same payment flow, and the same empty promise of content delivery replicated across every domain. It’s the dark web equivalent of a phishing campaign that sends the same email to millions of addresses, the volume comes from automation, not from individual effort. As Hackread noted in their coverage, the operation shows “how easily such networks can scale using automation, cryptocurrency, and anonymized hosting.”
This automation is also what makes the dark web’s fraudulent infrastructure so difficult to contain. Shutting down 373,000 sites is a significant achievement.
Rebuilding 373,000 sites from a new server, with new cryptographic keys and new onion addresses, is something a determined operator could theoretically do in days. The real disruption comes from seizing the physical infrastructure, identifying the operator, and pursuing the customers, all of which Operation Alice accomplished, even if the arrest is still pending.
What Reporting Mechanisms Exist
If you encounter material of this nature online or believe you have come across evidence of child exploitation, there are legitimate reporting channels designed specifically for this purpose.
The Internet Watch Foundation (IWF) operates a reporting hotline for child sexual abuse material found online, including on the dark web. In the United States, the National Center for Missing & Exploited Children (NCMEC) operates the CyberTipline, which accepts reports from members of the public and routes them to law enforcement. The FBI’s Internet Crime Complaint Center (IC3) handles reporting of internet-facilitated crime including dark web activity.
These channels exist because successful operations like Operation Alice depend on intelligence from multiple sources, not just law enforcement monitoring, but reports from researchers, journalists, and the public. The five-year investigation that led to this takedown started somewhere specific. Most do.
The Bigger Picture: What One Takedown Actually Achieves
Operation Alice is one of the largest dark web takedowns by site count in documented law enforcement history. That matters. But it’s worth being honest about what a single operation does and doesn’t accomplish.
The 373,000 sites are gone. The 105 seized servers can’t be used to replace them without the operator rebuilding from scratch. The 440 identified customers face ongoing criminal scrutiny. The operator faces an international arrest warrant.
At the same time, the dark web as an infrastructure remains unchanged. Tor still functions. Onion domains are still free to generate. New fraudulent platforms have appeared since March 2026, because the tools and the market incentives that created this one remain in place. Europol’s Catherine De Bolle acknowledged in previous briefings that the agency views these operations as ongoing campaigns rather than permanent resolutions.
The most durable outcomes from operations like this tend to be two things: the prosecution of identified individuals, customers and operators alike, and the intelligence gathered from seized infrastructure that feeds subsequent investigations. The 105 seized servers likely contain logs, cryptocurrency wallet records, and communication histories that will generate new cases long after the March operation formally concluded.
For law enforcement’s sustained approach to the dark web, and the monitoring techniques that make takedowns like Operation Alice possible, our piece on how dark web warning signs reach investigators before attacks become public covers the intelligence pipeline that underpins this kind of long-running work.
Frequently Asked Questions
What was Operation Alice?
A 10-day international law enforcement operation, March 9-19, 2026, led by German authorities and supported by Europol, that shut down more than 373,000 fraudulent dark web sites operated by a single individual.
Were all 373,000 sites illegal?
Yes. They were fraudulent dark web platforms advertising child sexual abuse material packages and cybercrime-as-a-service offerings, neither of which was ever actually delivered. The entire network was designed to take cryptocurrency payments and provide nothing in return.
Did the operator make money from this?
Yes. Investigators estimate the operator collected around β¬345,000 in Bitcoin from customers purchasing packages priced between β¬17 and β¬215. None of the content or services promised were delivered.
What happened to the customers?
440 customers were identified through their Bitcoin transactions and email registrations. Additional criminal investigations were launched against all of them. Investigations against more than 100 remain active as of March 2026.
Has the operator been arrested?
No. The main suspect is believed to be a 35-year-old man based in China. An international arrest warrant has been issued. The investigation is ongoing.
How did one person run 373,000 websites?
Through automation. Onion domains on the Tor network are computationally cheap to generate and require no registration or hosting fees. Templated sites can be replicated across thousands of addresses quickly. The volume reflects scripted automation, not individual management of each site.