# Netherlands Dismantles Major Hosting Infrastructure Enabling Russian-Backed Cyberattacks
In a significant law enforcement action targeting state-sponsored cyber operations, Dutch financial crime investigators arrested two suspects and seized approximately 800 servers from a web hosting operation allegedly used to support Russian and Belarusian entities engaged in cyberattacks, disinformation campaigns, and interference operations across Europe.
## The Operation: A Major Coordinated Takedown
The Financial Crime Investigation Department (FIOD) of the Netherlands announced the action on May 22, 2026, following months of investigation into a hosting infrastructure network connecting multiple entities across Dutch territory. The operation resulted in the arrest of a 57-year-old company director and a 39-year-old internet connectivity provider, with raids conducted simultaneously at data centers in Dronten and Schiphol-Rijk, as well as residential locations in Enschede and Almere.
Authorities seized 800 servers, laptops, mobile phones, and administrative records from the facilities. According to FIOD's statement: "The Dutch web hosting company, according to the research team, provided support to actions by the Russian Federation that undermine democracy and security, including through information manipulation and disruption of public and economic systems."
## Background and Context: Sanctions Evasion
The investigation centered on Stark Industries, a web hosting firm founded on February 10, 2022—just weeks before Russia's full-scale invasion of Ukraine. The company became a known provider of infrastructure to sanctioned Russian and Belarusian entities, enabling their offensive cyber operations.
On May 20, 2025, the European Union formally designated Stark Industries as a sanctioned entity, subjecting it to asset freezes and restrictions on doing business within EU member states. Rather than ceasing operations, investigators discovered that the infrastructure was transferred to a newly established Dutch company designed to obscure the connection to sanctioned entities.
The Front Company Structure:
| Entity | Role | Location |
|--------|------|----------|
| Stark Industries | Original hosting provider (sanctioned) | Netherlands |
| WorkTitans B.V. | Successor entity (alleged front company) | Netherlands |
| THE.Hosting | Brand name used by WorkTitans | Netherlands |
| Mirhosting | Physical infrastructure & connectivity provider | Almere |
According to reporting by De Volkskrant, WorkTitans B.V. operated under the brand name THE.Hosting, while Mirhosting, based in Almere, provided the physical backbone—operating server colocation facilities, managing equipment, and supplying high-capacity connectivity to major internet exchange points in Amsterdam and Frankfurt. This infrastructure allowed traffic from Stark's sanctioned operations to enter European internet backbone networks and reach the WorkTitans infrastructure.
## Technical Details: How the Infrastructure Enabled Attacks
The seized hosting infrastructure supported multiple categories of malicious activity:
### Cyberattack Infrastructure
The servers hosted command-and-control (C2) systems and attack platforms used to conduct distributed denial-of-service (DDoS) attacks and other offensive cyber operations. Danish authorities and infrastructure providers linked the seized infrastructure to attacks conducted by NoName057(16), a pro-Russian hacktivist group known for targeting critical organizations with high-volume DDoS campaigns.
### Disinformation and Influence Operations
Beyond cyberattacks, the hosting provider maintained servers used to distribute disinformation and conduct influence operations designed to undermine democratic processes and social cohesion across Europe. These operations included:
### Operational Security Features
The infrastructure employed several techniques to evade detection and sanctions enforcement:
## Implications for Cybersecurity and International Enforcement
This case demonstrates several critical trends in state-sponsored cyber operations:
Sanctions Evasion as Standard Practice. Rather than halting operations following EU sanctions, the threat actors immediately migrated to successor entities. This illustrates that sanctions alone are insufficient without coordinated technical enforcement and infrastructure takedowns.
Critical Infrastructure Concentration. A small number of hosting providers and internet exchange points control disproportionate access to European infrastructure. The concentration of attack capability in a single operation—now seized—suggests similar infrastructure may exist elsewhere, currently undetected.
Complicity and Willful Blindness. Mirhosting initially claimed to have "quickly intervened upon receipt of abuse complaints." However, the scale of the operation (800 servers, multiple data center locations) suggests either systematic negligence or deliberate tolerance of abuse reports. Hosting providers enabling sanctioned entities face significant legal and reputational risk.
Supply Chain Interdependency. The operation required coordination between multiple entities—the hosting company, connectivity provider, and data center operators. Disrupting any single link should theoretically have cascading effects; the fact that this chain remained operational until law enforcement intervention suggests weak enforcement mechanisms.
## Recommendations
For Internet Service Providers and Hosting Companies:
For Regulatory Authorities:
For Organizations:
---
## HackWire Analysis
This operation represents a watershed moment in European law enforcement's capacity to disrupt state-sponsored cyber operations at infrastructure scale. What distinguishes this action from typical hosting takedowns is its targeting of the sanction-evasion mechanism itself—not just shutting down a malicious service, but dismantling the deliberate architectural choice to route sanctioned operations through Dutch law's blind spots.
The timing is significant. One year elapsed between EU sanctions designation (May 2025) and the FIOD seizure (May 2026). That gap wasn't incompetence; it was evidence collection. The investigation likely required months of traffic analysis, financial record correlation, and cross-agency coordination. This suggests that European counterparts observed the Stark→WorkTitans migration in real time and used it as a Rosetta Stone to map the entire ecosystem—every data center, every ISP, every accomplice.
The pattern recognition here is chilling: Stark Industries was founded days before Ukraine invasion. This wasn't a pivot by an existing provider; it was infrastructure built from inception to serve a purpose. Similar infrastructure likely exists now, purpose-built and waiting. The 800 seized servers represent capacity, not exclusivity.
For defenders, the hidden risk is timing. Attackers using this infrastructure have months to find alternatives. The NoName057(16) group will migrate. The disinformation operations will continue elsewhere. Taking down infrastructure is tactically necessary but strategically temporary unless accompanied by international enforcement that makes successor infrastructure untenable faster than the last attempt.
The most actionable detail: Mirhosting's claim of "quick intervention" deserves scrutiny. 800 servers generating abuse complaints should trigger immediate suspension, not slow investigation. If Mirhosting genuinely discovered only after law enforcement arrived that its data centers hosted attacks, the industry's detection and compliance mechanisms have failed catastrophically. If they knew, this is accomplice liability.
Organizations should assume the infrastructure's customer database has been compromised. Customers of THE.Hosting—even those using it for ostensibly legitimate purposes—face exposure from law enforcement investigation and sanctions secondary liability. — HackWire Editorial
---
## Related Coverage