# Netherlands Dismantles Major Hosting Infrastructure Enabling Russian-Backed Cyberattacks


In a significant law enforcement action targeting state-sponsored cyber operations, Dutch financial crime investigators arrested two suspects and seized approximately 800 servers from a web hosting operation allegedly used to support Russian and Belarusian entities engaged in cyberattacks, disinformation campaigns, and interference operations across Europe.


## The Operation: A Major Coordinated Takedown


The Financial Crime Investigation Department (FIOD) of the Netherlands announced the action on May 22, 2026, following months of investigation into a hosting infrastructure network connecting multiple entities across Dutch territory. The operation resulted in the arrest of a 57-year-old company director and a 39-year-old internet connectivity provider, with raids conducted simultaneously at data centers in Dronten and Schiphol-Rijk, as well as residential locations in Enschede and Almere.


Authorities seized 800 servers, laptops, mobile phones, and administrative records from the facilities. According to FIOD's statement: "The Dutch web hosting company, according to the research team, provided support to actions by the Russian Federation that undermine democracy and security, including through information manipulation and disruption of public and economic systems."


## Background and Context: Sanctions Evasion


The investigation centered on Stark Industries, a web hosting firm founded on February 10, 2022—just weeks before Russia's full-scale invasion of Ukraine. The company became a known provider of infrastructure to sanctioned Russian and Belarusian entities, enabling their offensive cyber operations.


On May 20, 2025, the European Union formally designated Stark Industries as a sanctioned entity, subjecting it to asset freezes and restrictions on doing business within EU member states. Rather than ceasing operations, investigators discovered that the infrastructure was transferred to a newly established Dutch company designed to obscure the connection to sanctioned entities.


The Front Company Structure:


| Entity | Role | Location |

|--------|------|----------|

| Stark Industries | Original hosting provider (sanctioned) | Netherlands |

| WorkTitans B.V. | Successor entity (alleged front company) | Netherlands |

| THE.Hosting | Brand name used by WorkTitans | Netherlands |

| Mirhosting | Physical infrastructure & connectivity provider | Almere |


According to reporting by De Volkskrant, WorkTitans B.V. operated under the brand name THE.Hosting, while Mirhosting, based in Almere, provided the physical backbone—operating server colocation facilities, managing equipment, and supplying high-capacity connectivity to major internet exchange points in Amsterdam and Frankfurt. This infrastructure allowed traffic from Stark's sanctioned operations to enter European internet backbone networks and reach the WorkTitans infrastructure.


## Technical Details: How the Infrastructure Enabled Attacks


The seized hosting infrastructure supported multiple categories of malicious activity:


### Cyberattack Infrastructure

The servers hosted command-and-control (C2) systems and attack platforms used to conduct distributed denial-of-service (DDoS) attacks and other offensive cyber operations. Danish authorities and infrastructure providers linked the seized infrastructure to attacks conducted by NoName057(16), a pro-Russian hacktivist group known for targeting critical organizations with high-volume DDoS campaigns.


### Disinformation and Influence Operations

Beyond cyberattacks, the hosting provider maintained servers used to distribute disinformation and conduct influence operations designed to undermine democratic processes and social cohesion across Europe. These operations included:


  • Content distribution platforms for false narratives and propaganda
  • Botnet coordination for amplifying disinformation on social media
  • Phishing and credential theft infrastructure targeting political and governmental organizations

  • ### Operational Security Features

    The infrastructure employed several techniques to evade detection and sanctions enforcement:


  • Multi-jurisdiction distribution across Netherlands data centers to exploit regulatory gaps
  • High-capacity international connectivity via Amsterdam and Frankfurt exchanges to distribute attack traffic globally
  • Entity obfuscation through the creation of front companies with no apparent connection to sanctioned operators
  • Rapid infrastructure migration after sanctions designation to maintain operational continuity

  • ## Implications for Cybersecurity and International Enforcement


    This case demonstrates several critical trends in state-sponsored cyber operations:


    Sanctions Evasion as Standard Practice. Rather than halting operations following EU sanctions, the threat actors immediately migrated to successor entities. This illustrates that sanctions alone are insufficient without coordinated technical enforcement and infrastructure takedowns.


    Critical Infrastructure Concentration. A small number of hosting providers and internet exchange points control disproportionate access to European infrastructure. The concentration of attack capability in a single operation—now seized—suggests similar infrastructure may exist elsewhere, currently undetected.


    Complicity and Willful Blindness. Mirhosting initially claimed to have "quickly intervened upon receipt of abuse complaints." However, the scale of the operation (800 servers, multiple data center locations) suggests either systematic negligence or deliberate tolerance of abuse reports. Hosting providers enabling sanctioned entities face significant legal and reputational risk.


    Supply Chain Interdependency. The operation required coordination between multiple entities—the hosting company, connectivity provider, and data center operators. Disrupting any single link should theoretically have cascading effects; the fact that this chain remained operational until law enforcement intervention suggests weak enforcement mechanisms.


    ## Recommendations


    For Internet Service Providers and Hosting Companies:

  • Implement robust customer identity verification and beneficial ownership screening
  • Conduct quarterly audits of customer infrastructure and activity patterns
  • Maintain abuse complaint logs and escalation procedures with clear documentation
  • Establish rate-limit protections and behavioral anomaly detection
  • Coordinate with sector ISACs on threat intelligence regarding sanctioned entities

  • For Regulatory Authorities:

  • Expand cross-border information sharing between FIOD, Europol, and national law enforcement
  • Develop technical standards for hosting providers to demonstrate sanctions compliance
  • Increase inspection and audit frequency at critical internet exchange points
  • Establish penalties and liability for providers that knowingly or negligently support sanctioned operations

  • For Organizations:

  • Monitor for DDoS attacks originating from seized IP ranges; such attacks may continue from successor infrastructure
  • Review network logs for historical connections to THE.Hosting or Stark Industries infrastructure
  • Strengthen detection of credential theft and account compromise, as disinformation operations often precede targeted attacks

  • ---


    ## HackWire Analysis


    This operation represents a watershed moment in European law enforcement's capacity to disrupt state-sponsored cyber operations at infrastructure scale. What distinguishes this action from typical hosting takedowns is its targeting of the sanction-evasion mechanism itself—not just shutting down a malicious service, but dismantling the deliberate architectural choice to route sanctioned operations through Dutch law's blind spots.


    The timing is significant. One year elapsed between EU sanctions designation (May 2025) and the FIOD seizure (May 2026). That gap wasn't incompetence; it was evidence collection. The investigation likely required months of traffic analysis, financial record correlation, and cross-agency coordination. This suggests that European counterparts observed the Stark→WorkTitans migration in real time and used it as a Rosetta Stone to map the entire ecosystem—every data center, every ISP, every accomplice.


    The pattern recognition here is chilling: Stark Industries was founded days before Ukraine invasion. This wasn't a pivot by an existing provider; it was infrastructure built from inception to serve a purpose. Similar infrastructure likely exists now, purpose-built and waiting. The 800 seized servers represent capacity, not exclusivity.


    For defenders, the hidden risk is timing. Attackers using this infrastructure have months to find alternatives. The NoName057(16) group will migrate. The disinformation operations will continue elsewhere. Taking down infrastructure is tactically necessary but strategically temporary unless accompanied by international enforcement that makes successor infrastructure untenable faster than the last attempt.


    The most actionable detail: Mirhosting's claim of "quick intervention" deserves scrutiny. 800 servers generating abuse complaints should trigger immediate suspension, not slow investigation. If Mirhosting genuinely discovered only after law enforcement arrived that its data centers hosted attacks, the industry's detection and compliance mechanisms have failed catastrophically. If they knew, this is accomplice liability.


    Organizations should assume the infrastructure's customer database has been compromised. Customers of THE.Hosting—even those using it for ostensibly legitimate purposes—face exposure from law enforcement investigation and sanctions secondary liability. — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)