ClosedLow impactAI Refreshed

US and Canada Arrest Suspected KimWolf DDoS Botnet Administrator

Occurred 1 Mar 2026Β·Detected 22 May 2026Β·
πŸ‡ΊπŸ‡Έ Canada / United States (joint law enforcement operation)2 reportsEnded 19 Jun 2026
CyberPropertyCyberCasualty & Liability

US and Canadian authorities arrested 23-year-old Jacob Butler in Ottawa on a US extradition warrant for allegedly operating the KimWolf DDoS botnet. Reporting indicates the botnet infected between one and two million devices globally, was tied to DDoS attacks measured at nearly 30 Tbps, and targeted US Department of Defense IP addresses. The botnet was reportedly dismantled in March 2026 as part of a joint US-Canada-Germany law enforcement operation. Full victim inventory, critical-infrastructure targeting, and confirmation of complete infrastructure neutralization remain incompletely documented.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. The reported arrest and March 2026 takedown of KimWolf reduce the probability of near-term continued large-scale DDoS events originating from this specific infrastructure, limiting forward-looking insured loss potential. Reported scale (one to two million infected devices, peak attack volume near 30 Tbps, attacks against US Department of Defense IP addresses, and per-victim losses exceeding USD 1m in some cases) indicates a material cyber threat-actor disruption event with insured-relevant attack volumes. Specific insured loss events, total victim counts, full target inventory, and confirmation of complete botnet neutralization remain incompletely documented. Continued monitoring is warranted for aftershocks, copycat or successor DDoS-for-hire activity, and any residual infrastructure.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

1 active match

  • TRIA Certified Areas
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

πŸ‡¨πŸ‡¦ CanadaπŸ‡©πŸ‡ͺ GermanyπŸ‡ΊπŸ‡Έ United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts