Cyber Security News

Authorities Seized Thousands of Servers from Rogue Hosting Company Used to Fuel Cyberattacks

In a major law enforcement operation conducted on November 12, 2025, the East Netherlands cybercrime team successfully dismantled a significant criminal infrastructure.

Authorities seized approximately 250 physical servers located in data centers across The Hague and Zoetermeer, which collectively powered thousands of virtual servers used for illegal activities.

This operation represents one of the largest infrastructure takedowns targeting bulletproof hosting services that have been instrumental in facilitating cybercrimes across multiple jurisdictions.

The seized hosting company operated under the guise of legitimacy while providing complete anonymity to its users.

Police analysts identified that the provider marketed itself as bulletproof hosting, explicitly claiming not to cooperate with law enforcement agencies and guaranteeing protection for its criminal clientele.

Despite these promises, the company’s infrastructure ultimately became the centerpiece of a comprehensive investigation that has exposed its true nature as a criminal enterprise serving exclusively illegal purposes.

Police.nl security analysts noted that the hosting company had appeared in more than 80 criminal investigations both domestically and internationally since 2022.

The company continued facilitating illegal operations until the moment of seizure, demonstrating its persistent role in supporting various cybercriminal activities across different threat landscapes and attack vectors.

The Criminal Infrastructure’s Role in Cyberattacks

The rogue hosting provider functioned as a critical enabler for multiple types of cybercriminal activities.

Criminals rented digital space from this company to launch ransomware attacks, deploy botnets designed to compromise thousands of systems, execute sophisticated phishing campaigns targeting organizations and individuals, and distribute child exploitation material.

This hosting service essentially provided the digital foundation that allowed threat actors to conduct their operations with perceived impunity.

The operational scope of this infrastructure was substantial, with the platform housing criminal websites, malware command-and-control servers, phishing infrastructure, and various other illegal services.

The seizure of both physical and virtual servers immediately disrupted these criminal operations and prevented new attacks from being launched through this particular infrastructure.

Following the seizure, authorities prioritized analyzing the vast amount of data recovered from the servers to identify additional criminal networks, individual threat actors, and victims requiring notification.

The investigation continues with law enforcement agencies focusing on identifying all users of the hosting service and tracing the full extent of criminal activities conducted through this infrastructure.

This operation demonstrates the critical importance of targeting the underlying infrastructure that enables cybercriminal operations at scale.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

1 hour ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

2 hours ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

2 hours ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

3 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

4 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago