NetNut Seized by the FBI
News

NetNut Seized by the FBI: What It Means for Anyone Buying Proxies

On July 2–3, 2026, the FBI and IRS Criminal Investigation, working with Google’s Threat Intelligence Group, Lumen’s Black Lotus Labs, and the Shadowserver Foundation, seized hundreds of domains tied to NetNut — one of the largest residential proxy networks on the open internet, operated by the Nasdaq-listed Israeli firm Alarum Technologies (ALAR). Visitors to NetNut’s homepage now see an FBI seizure notice instead of a proxy dashboard.

The reason is what makes this relevant to every proxy buyer. Investigators say NetNut’s exit-node pool overlapped with Popa, a botnet of at least two million hijacked consumer devices — mostly budget smart TVs, streaming boxes, and Android phones running proxy code they never knowingly installed. In a single week in June, Google counted 316 distinct threat clusters routing attacks through those exit nodes, including nation-state espionage groups.

NetNut Seized by the FBI

NetNut Seized by the FBI

Why it matters for media buyers and account operators. NetNut was, per Google, “widely resold and white-labeled” by other proxy providers — which means some budget or reseller proxies you might have used could have been drawing from this pool without you knowing. Running your accounts through a botnet is a legal and reputational risk, not a bargain. And this isn’t a one-off: it’s the second major residential proxy takedown of 2026, after Google and the FBI dismantled IPIDEA in January. Google framed NetNut as a continuation, not a conclusion — expect more.

How to protect yourself. The lesson the whole industry is repeating: buy proxies only from providers that can show where their IPs come from — a disclosed, opt-in SDK where users consent and are paid, plus GDPR alignment and a data processing agreement. Vague sourcing answers and prices far below market are red flags, not deals. Established providers with documented sourcing (see our best residential proxies guide) are the safer bet, and it’s worth learning how to check whether a proxy is genuinely residential before you commit.

Bottom line. The takedowns target botnets and fraud, not the concept of residential proxies — legitimate, consent-sourced proxies used for legitimate work remain legal. But in 2026, ethical sourcing moved from a nice-to-have to a structural requirement. If you can’t tell where a provider’s IPs come from, assume the risk is yours.

You may also like

Leave a reply

Your email address will not be published. Required fields are marked *