Threats & Adversaries · IoT / OT Attack
Server Seizures Miss THE.Hosting's Core Network Taking down a bulletproof host's boxes is not the same as taking down the host. If the routed network block stays live, the operation can keep scanning, reselling capacity, and supporting abuse under the same Internet identity after the raid.
Dutch investigators arrested two operators and seized more than 800 servers tied to THE.Hosting on May 18. But researchers still saw scanning activity at nearly the same level a week later, and the host's core AS209847 remained intact. AS numbers are the routing layer that tells the Internet where to send traffic, so keeping that piece alive preserves reach even after hardware is gone.
That leaves a clear limitation in standard takedowns: server seizure alone does not break a bulletproof hosting service if the upstream connectivity and address space survive.
7 sources · May 29
Timeline Sources May 29 Risky Biz News
Risky Bulletin: Dutch police take down 17m device botnet
Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer i [Read More
original May 28 Dark Reading
Dutch Raid Fails to Dent Russian Bulletproof Host
Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider's core IP address space intact.
original May 26 SecurityWeek
Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands
The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.
original Part of the PlainSec briefing for 2026-05-25
Every edition of this story: Server Seizures Miss THE.Hosting's Core Network
More from today
Threats & Adversaries · IoT / OT Attack
Server Seizures Miss THE.Hosting's Core Network Taking down a bulletproof host's boxes is not the same as taking down the host. If the routed network block stays live, the operation can keep scanning, reselling capacity, and supporting abuse under the same Internet identity after the raid.
Dutch investigators arrested two operators and seized more than 800 servers tied to THE.Hosting on May 18. But researchers still saw scanning activity at nearly the same level a week later, and the host's core AS209847 remained intact. AS numbers are the routing layer that tells the Internet where to send traffic, so keeping that piece alive preserves reach even after hardware is gone.
That leaves a clear limitation in standard takedowns: server seizure alone does not break a bulletproof hosting service if the upstream connectivity and address space survive.
7 sources · May 29
Timeline Sources May 29 Risky Biz News
Risky Bulletin: Dutch police take down 17m device botnet
Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer i [Read More
original May 28 Dark Reading
Dutch Raid Fails to Dent Russian Bulletproof Host
Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider's core IP address space intact.
original May 26 SecurityWeek
Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands
The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.
original Part of the PlainSec briefing for 2026-05-25
Every edition of this story: Server Seizures Miss THE.Hosting's Core Network
More from today