Dutch police have seized approximately 250 physical servers and thousands of virtual servers belonging to an unnamed bulletproof hosting provider operating out of The Hague and Zoetermeer. This hosting service, active since 2022, was used exclusively by cybercriminals and has been linked to over 80 cybercrime investigations both in the Netherlands and internationally. The provider advertised complete anonymity, did not enforce Know Your Customer (KYC) policies, and refused to cooperate with law enforcement, making it a popular choice for threat actors.
The infrastructure supported a range of illicit activities, including ransomware operations, malware distribution, phishing campaigns, botnet control, and the hosting of child abuse content. The takedown blocks further criminal use of the service and enables forensic analysis of the seized servers to identify operators and clients. No arrests have been announced yet, but the operation is expected to provide valuable intelligence for ongoing and future investigations into cybercrime facilitated by bulletproof hosting services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After the seizure, Dutch police said they would conduct forensic analysis of the confiscated infrastructure to identify the hosting service's operators and customers. Authorities did not confirm the provider's identity at the time of the announcement.
Dutch police seized infrastructure supporting an unnamed bulletproof hosting provider, taking about 250 physical servers and thousands of virtual servers offline. Authorities said the service had appeared in more than 80 cybercrime investigations in the Netherlands and abroad, and no arrests were announced.
Reporting cited by BleepingComputer indicated the impacted infrastructure may be connected to CrazyRDP, a no-KYC, no-logs VPS/RDP provider that reportedly went offline around November 12. Dutch authorities did not confirm that attribution.
Dutch authorities said the unnamed bulletproof hosting provider had been active since 2022, offering anonymity and refusing cooperation with law enforcement. Investigators later linked the service to ransomware, botnets, phishing, and child abuse content distribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.