Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Sergiy P. Usatyuk, an Orland Park, Illinois resident, pleaded guilty in federal court on February 27, 2019, to conspiracy to cause damage to internet-connected computers. The Justice Department said he owned, administered and supported illegal “booter” services used to launch distributed denial-of-service (DDoS) attacks. In November 2019, he was sentenced to 13 months in prison, three years of supervised release and forfeiture of $542,925 plus servers and other equipment.

What Usatyuk pleaded guilty to

Usatyuk pleaded guilty to one count of conspiracy to cause damage to internet-connected computers in the U.S. District Court for the Eastern District of North Carolina. The plea announcement described conduct carried out with a co-conspirator from about August 2015 through November 2017.

Although this article uses the phrase “booter owner” from the case topic, “owner” was not a formal legal title. The Justice Department described Usatyuk in its headline as a former operator and said he and his co-conspirator developed, controlled and operated the services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The services named by prosecutors

  • ExoStress.in, also marketed as “ExoStresser”
  • QuezStresser.com
  • Betabooter.com, or “Betabooter”
  • Databooter.com
  • Instabooter.com
  • Polystress.com
  • Zstress.net

What a booter service is

A booter, sometimes called a stresser, is a web-based service that lets a customer pay to direct a distributed denial-of-service attack at a chosen target. The attack sends large volumes of unrequested traffic toward an internet-connected system, potentially overwhelming it, interrupting access or impairing normal operations.

The plea announcement said a customer could use a browser and an online payment method to subscribe, identify a target and start an attack. That description explains the conduct in this case; it is not a recommendation or instruction for using such a service.

What the government said the operation did

Advertised attack and downtime figures

According to the Justice Department’s February 2019 plea announcement, the ExoStresser website stated that, as of September 12, 2017, it had launched 1,367,610 DDoS attacks and caused 109,186.4 hours of network downtime. Those numbers were claims displayed by the service and reported by the government; they were not presented as an independent audit.

Money from subscriptions and advertising

The same announcement said the operators received more than $550,000 from subscriber fees and advertising during the conspiracy. That is a case-specific figure for the period described, not an estimate of booter-service revenue generally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Effects on a Pittsburgh-area school district

The government cited a November 2016 Betabooter attack against a school district in the Pittsburgh area. It said the attack disrupted the district’s systems and affected 17 other organizations that shared infrastructure, including additional school districts, county government, career and technology centers and a Catholic diocese.

Assistant Attorney General Brian A. Benczkowski said with the plea announcement: “For over two years, Sergiy Usatyuk conspired to launch millions of DDoS attacks that paralyzed the computer systems of U.S. organizations for more than 100,000 hours.” U.S. Attorney Robert J. Higdon Jr. said DDoS-for-hire services threaten people by impeding critical internet access and jeopardizing safety and security. These were official statements issued when the plea was announced.

Plea and sentence are separate milestones

Date Milestone What it established
February 27, 2019 Guilty plea Usatyuk admitted one conspiracy count involving damage to internet-connected computers.
November 14, 2019 Sentencing Chief U.S. District Judge Terrence W. Boyle imposed 13 months in prison and three years of supervised release.
November 14, 2019 Forfeiture The court ordered forfeiture of $542,925, along with dozens of servers and other computer equipment tied to the scheme or its proceeds.

The February announcement described the offense and the defendant’s admissions at the plea stage. The November announcement supplied the final punishment and forfeiture terms; those later figures should not be substituted for the earlier allegations or revenue description.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this case fits the broader crackdown

The Usatyuk case was one part of wider action against DDoS-for-hire infrastructure. In 2023, the Justice Department said four defendants in separate Los Angeles prosecutions had pleaded guilty and that 13 domains had been seized as part of Operation PowerOFF and related international efforts. The department also described previously seized booter-site data showing hundreds of thousands of registered users had launched millions of attacks against millions of victims. Those are historical descriptions of seized data, not a current universal count of all attacks or users.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a separate 2022 action, the department announced charges against six defendants and seizure of 48 domains. Criminal informations in that matter contained allegations, and the department expressly noted that defendants are presumed innocent unless proven guilty beyond a reasonable doubt. Those defendants, domains and allegations were not part of Usatyuk’s conviction.

Why the case matters

The case demonstrates how a service marketed through a website can become evidence in a federal computer-crime prosecution when its operators knowingly facilitate attacks. It also shows why the financial and technical consequences extend beyond the person who orders an attack: shared hosting or network infrastructure can carry disruptions to schools, government bodies, religious organizations and other unrelated users.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.