AlphaBay and Hansa Simultaneous Takedown Operation
Law enforcement secretly controlled AlphaBay's backup market to trap fleeing criminals.

AlphaBay was the biggest drug and fraud market the dark web had ever seen, and in July 2017, law enforcement didn't just shut it down. They took over its closest competitor first, ran it in secret for 27 days, and let thousands of fleeing criminals walk straight into a trap they built. The operation was called Bayonet, and it's still the clearest example on record of what intelligence-led policing actually looks like when it works.
Some context on scale, because the numbers here are not small. AlphaBay launched in 2014 as an eBay-style hidden marketplace on Tor. By the time it fell, Europol and the FBI put its inventory at over 200,000 users, 40,000 vendors, 250,000 drug listings, and 100,000 listings for stolen IDs, counterfeit goods, malware, firearms, and fraud services. At the joint press conference, agents called it ten times the size of Silk Road, which had roughly 14,000 listings when it got shut down back in 2013. Europol's conservative estimate put total transactions since 2014 at $1 billion, in bitcoin and other cryptocurrencies. And this wasn't abstract. The FBI traced specific drug sales on the platform back to real overdose deaths. A market that size, moving that much product, wasn't going to go away just because someone pulled a plug.
How law enforcement identified Alexandre Cazes through his operational errors
Alexandre Cazes ran AlphaBay under the handles Alpha02 and Admin. He was 25, Canadian, living in Thailand, and by most measures, running a very profitable business. He also made a string of mistakes that read less like a criminal mastermind and more like someone who never expected to get caught.
Start with the email. AlphaBay's official welcome messages went out from "[email protected]," That address had also been used by Cazes to set up a personal LinkedIn account, the Justice Department's complaint states. The same address connected his criminal operation directly back to his real identity. One password-reset field, and the whole identity unravels.
Then there's the handle itself. Alpha02 wasn't a name he invented for AlphaBay. He'd been using it since at least 2008 on carding and hacking forums, which meant investigators had nearly a decade of digital breadcrumbs to work backward through.
The arrest itself was almost comic in its bad timing. Cazes was logged into his personal laptop, actively running a reboot command, when Thai police showed up. The reboot was a response to a service outage law enforcement had engineered. The laptop wasn't encrypted. Sitting right there on it: an unencrypted personal net worth statement, mapping his assets across multiple countries, which made full seizure straightforward. His servers were hosted at a Canadian company traceable directly to him, and he'd left multiple cryptocurrency hot wallets open and unsecured.
The root problem wasn't cryptography, it was compartmentalization. Cazes never built a separate, disposable identity just for running the market. He mixed his real life and his criminal enterprise in the same digital footprint, over and over. The encryption tools held up fine. The human using them didn't.
Thai authorities arrested Cazes on July 5, 2017. He died by suicide in custody before he could be extradited. Investigators went on to seize his and his wife's luxury cars, homes, a hotel, and his cryptocurrency holdings.
Seizing AlphaBay alone would have displaced rather than disrupted the criminal ecosystem
Shutting a market down doesn't stop dark web users from continuing to buy and sell drugs; they simply relocate. That happened after Silk Road got seized in 2013. Replacement markets emerged quickly, and the drug trade barely paused for breath.
Law enforcement knew that pattern would repeat with AlphaBay, and at 200,000-plus users, a simple displacement would erase most of the investigative value of the takedown. So the strategy flipped. Rather than accept that users would scatter to the next available market, why not control that next market first?
Hansa was already the third-largest dark web marketplace, Europol says, which made it the obvious landing spot the moment AlphaBay went dark. That's what set up the entire second phase of the operation: Hansa had to be quietly captured and controlled before anyone announced AlphaBay was gone.
Dutch police's discovery, infiltration, and quiet takeover of Hansa
Dutch police got their opening lead on Hansa from Europol's European Cybercrime Centre in 2016, with technical help from the security firm Bitdefender, Europol's own press release states. The break came from something almost embarrassingly simple: Hansa's administrators had left old IRC chat logs sitting on a server, logs that included their full names and a home address, and investigators were able to trace the exposure back to them.
The administrators eventually moved the site to a new, unknown host. But Dutch police traced the operation to a hosting company in Lithuania, and from there the trail led straight back to two German nationals running the show.
German police arrested both administrators on June 20, 2017, acting under Dutch judicial authorization. Then came the actual takeover: Dutch police assumed full, covert control of Hansa and started impersonating its own administrators. Infrastructure got seized across the Netherlands, Germany, and Lithuania, all while the site kept running like nothing had changed.
Behind the scenes, Dutch investigators rewrote Hansa's code. Credentials were logged as users submitted them. Private communications were intercepted at the platform level before security protections could shield them. Uploaded content was intercepted and analyzed for identifying details. Escrow features were quietly manipulated so that funds could be monitored and seized. Users had no idea any of this was happening. To them, it was just another day on the market.
The deliberate sequencing of the AlphaBay announcement and the resulting intelligence flood
Timing was the whole trick. When AlphaBay actually went dark, the FBI didn't announce anything right away. Silence let rumor take over: users speculated about exit scams, technical failures, maybe a raid. That uncertainty pushed people toward the next safe-looking option, and Dutch police already controlled it.
The effect was immediate and enormous. Hansa's registrations jumped from around 600 new users a day to more than 5,000 a day, an eight-fold spike Europol recorded right after AlphaBay's shutdown. The surge was so heavy it actually overwhelmed Hansa's servers, forcing Dutch police to temporarily pause new signups just to keep the collection operation stable.
Over the following 27 days, Dutch police ran the platform and monitored roughly 27,000 transactions, Darknet Diaries reported. None of this happened by accident. Delaying the announcement was a calculated move designed to maximize how many users walked into the honeypot. Delaying the announcement meant Hansa caught far more of the traffic than it would have otherwise.
Anyone can seize a server and call a press conference; running an intelligence operation means watching the system for weeks first. Anyone can seize a server and call a press conference. The real value here came from those 27 days of watching.
What the 27-day covert operation harvested
The haul was substantial. Analysis from CybelAngel lists email addresses, passwords, PGP keys, transaction histories, and private messages, all collected while Hansa appeared to be operating normally. Dutch police also worked to capture identifying information on vendors and buyers through changes made to the platform's backend.
According to sourcing from tordark.com, the total came to data on roughly 420,000 users. Around 10,000 foreign buyer addresses got passed to Europol, and more than 500 Dutch delivery addresses were flagged for parcel interception. Europol's own statement confirms the 10,000 figure directly. Rob Wainwright, Europol's Executive Director at the time, said the intelligence gave investigators "a new insight into the criminal activity of the darknet, including many of its leading figures."
That data wasn't a snapshot filed away and forgotten. Europol noted the intelligence would lead to further investigations, and Operation Bayonet itself involved coordination across 37 countries. Compare that to a standard takedown, where agents seize servers and get whatever forensic data happens to be sitting on the disks at that moment, frozen in time. Running Hansa live for nearly a month produced something different: behavioral data on active criminals who had no idea they were being watched.
How Bitdefender's role as a private-sector intelligence contributor demonstrated vendor credibility
Europol's original 2016 lead on Hansa came with technical assistance from Bitdefender, a detail Europol confirmed in its own press release. Wainwright went further in a separate interview: "There was certainly help that we received from Bitdefender at a technical level." That's about as direct an on-record credit as a law enforcement official gives a private vendor.
Bitdefender documented the technical details of its involvement afterward, with its research unit providing the analytical groundwork that Europol credited. Bitdefender has since been credited in other law enforcement operations as well.
The sourcing here draws attention more than the technology does. Bitdefender didn't write a blog post claiming it helped take down a billion-dollar dark web market. Europol said that, publicly, on the record, and Bitdefender documented the technical details afterward. That order matters. Credibility built on someone else's attribution, backed up by a documented case study, carries more weight with practitioners than a glossy report full of generic "threat landscape" language ever will. Firms that show up in the actual casework, and then explain what they did in plain, specific terms, earn a different kind of trust than firms that just talk about being experts.
What Operation Bayonet established about intelligence-led law enforcement strategy
At the joint announcement, Europol called Bayonet "one of the most sophisticated takedown operations ever seen in the fight against criminal activities online." Then-Attorney General Jeff Sessions went further, calling it "the largest dark Web criminal market takedown in history."" Neither line was hyperbole once you look at the mechanics.
The operation's design rested on four things: sequenced timing, covert control of a live platform, code-level changes that captured data in real time, and deliberate manipulation of user behavior. None of that is brute force. All of it depends on sustained, patient collection.
Three lessons come out of this that apply well beyond one dark web bust. First, displacement isn't just a nuisance to route around, it's a lever you can pull deliberately if you control where the crowd lands. Second, the best investigative data comes from watching a system run. Third, and this one keeps proving true across cybercrime cases generally, the weak point is almost always the human layer. Reused usernames, personal emails in the wrong field, sloppy compartmentalization. The crypto usually holds. People don't.
Europol's release on the operation noted that the intelligence gathered "will lead to further investigations," which tells you the whole thing was built for downstream casework. And the 37-country coordination scope set a benchmark for how large a dark web enforcement operation could actually get.
For anyone working in security, Bayonet is worth studying not as history but as a working model. It shows what happens when intelligence gets used to shape events in progress, rather than just explain them after the fact. That's the bar technically sophisticated audiences now hold intelligence-driven security work to, and it's not a low one.
Sources
- AlphaBay and Hansa taken down in coordinated operations by FBI and Dutch National Police - DataBreaches.Net
- Operation Bayonet: How the FBI Took Down AlphaBay and Hansa
- Massive blow to criminal Dark Web activities after globally coordinated operation - Takedown of AlphaBay and Hansa will lead to hundreds of new investigations in Europe | Europol
- Cops harpoon two dark net whales in megabust: AlphaBay and Hansa
- justice.gov
- tordark.com
- bitdefender.com


