-
Dutch police, prosecutors and the Shadowserver Foundation shut down servers behind a criminal proxy service. It used nearly 178,000 infected devices, including hundreds in the Netherlands.
-
Owners did not know strangers were going online through their connections. Crimes done through those devices could point back to the wrong people.
-
Police say more takedowns may follow. They have not announced arrests or said how the devices were infected.

Dutch police revealed in a Thursday announcement that they have shut down a criminal proxy service that ran on nearly 178,000 hacked devices. Hundreds of them were in the Netherlands. Their owners had no idea that strangers were going online through their internet connections.
A cybercrime team from the North Holland police unit led the case. The team worked with the Dutch Public Prosecution Service and the Shadowserver Foundation, a security group that tracks online threats.
This week, police took servers offline at several hosting companies. Those servers kept the criminal proxy network running. Police said they busted the network by pooling and studying data and by working with partners in other countries. However, the announcement did not name the service. It also did not say how the devices were infected.
How a Proxy Service Works
Every device online has an IP address. It’s kinda like a return address on a letter, except this one is online. A proxy lets users route their traffic through another person’s device. As a result, websites see that address instead of the user’s actual address. A lot of people use proxies to keep their online activity private. Not every proxy service is illegal.
However, the criminal version works differently. Hackers break into devices that are old or poorly protected. Then they rent access to those devices to paying customers. A customer can hide behind the borrowed address while committing fraud or other crimes. The trail leads to the hacked device, not to the customer. Police say this makes it harder to find and charge the people behind the crime.
This Operation Puts Innocent Users at Risk
That is the main worry for police. If a criminal uses your hacked router or computer to commit a crime, your address ends up in the records. Police warned that the addresses of innocent people and businesses could be wrongly marked as suspect in criminal cases.
In plain terms, investigators could end up looking at the wrong person. That person might face hard questions about something they never did. Businesses face the same risk, since a hacked office device carries the same danger.
Police did not say whether they have wrongly suspected any owner so far. They also did not say where the other devices in the network were. The announcement only mentioned the Dutch ones. The owners themselves may never have noticed a thing. Police said the devices were used without their knowledge.
One of Several Recent Takedowns
This is not the first proxy network to fall this year. In March, the U.S. Justice Department, the FBI and European police, including Dutch officers, took down a service called SocksEscort.
The Dutch police have carried out other operations against criminal online services, including the takedown detailed in Dutch police shut down criminal host used for dark web activities. Court papers say it infected home and small-business routers with malware and sold access to them.
According to the Justice Department, SocksEscort offered access to about 369,000 IP addresses since mid-2020. Plans started at $15 a month for 30 connections. Investigators estimate the service earned more than 5 million euros.
In May, Dutch police and the country’s National Cyber Security Center took down servers behind a far bigger network. It had at least 17 million infected devices. Dutch media linked it to a proxy seller called Asocks. Officials did not confirm the name.
Analysts warn that takedowns do not always clean the infected devices. If weak spots stay open, new services can take the old ones’ place.
What Device Owners Can Do
The police announcement did not include advice for the public. But security agencies have given the same basic tips after earlier cases.
- Never skip phone, computer, or router updates. Install the update once they roll out.
- If your device is no longer getting updates, replace it with a newer one that receives regular updates.
- Insecure passwords are easily cracked; use strong passwords and don’t keep the default passwords provided.
- Enable 2FA everywhere possible.
- Do not use any app unless it comes from an approved app store.
- And, importantly, use a strong password to secure your Wi-Fi.
Old routers and cheap smart gadgets are common targets. Police said hackers often pick outdated devices with weak protection. If you still use one, it is time to swap it out.
What’s Next
Police say more servers could go offline in the coming weeks. Officials call this part of a wider effort to disrupt how cybercriminals work, rather than only chasing single suspects.
That approach makes sense for networks like this one. A proxy service has many parts, including servers, payment systems, and thousands of hacked devices. Taking away the servers cuts off the customers.
Still, the root problem remains. Millions of home devices run old software or weak passwords. Until that changes, criminals will keep finding ways to borrow other people’s internet connections.
For now, the Dutch owners caught up in this network have one thing in their favor. The service that was using their addresses is offline, and police are watching for what follows.