Back to Feed
Nation-stateMay 26, 2026

Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands

Netherlands arrests two bulletproof hosting admins who served Russian-aligned threat actors and evaded EU sanctions.

Summary

Dutch authorities arrested a 57-year-old from Amsterdam and a 39-year-old from The Hague on May 18 for operating companies that provided hosting infrastructure to Russian threat actors. The suspects allegedly ran front companies for the sanctioned Stark Industries hosting provider, enabling Russian state-sponsored actors like NoName057(16) to conduct DDoS attacks and disinformation campaigns against EU targets. Investigators seized over 800 servers and equipment from data centers in Dronten and Schiphol-Rijk.

Full text

Authorities in the Netherlands have arrested the owners of two Dutch companies that allegedly provided bulletproof hosting services to Russian threat actors and evaded sanctions imposed by the European Union. According to an announcement by the Dutch Fiscal Information and Investigation Service (FIOD), the suspects, a 57-year-old from Amsterdam and a 39-year-old from The Hague, were arrested on May 18. The investigators conducted searches at three locations in Enschede and Almere, and at two data centers in Dronten and Schiphol-Rijk, and seized laptops, phones, and over 800 servers. FIOD says the 57-year-old man is the owner and director of a Dutch company that acted as a front for a sanctioned web hosting provider. The sanctioned entity had been created two weeks before the Russian invasion of Ukraine and facilitated disinformation, interference, and disruptive cyberattacks against members of the EU. After the company was sanctioned in May 2025, most of its technical infrastructure was transferred to the arrested suspect’s Dutch company.Advertisement. Scroll to continue reading. The 39-year-old man, FIOD says, is the director and owner of a firm that ensured the servers of the front company would remain functional and online. FIOD’s scant announcement does not name the two or their companies, but an eight-month investigation by de Volkskrant revealed that two suspects, Youssef Z. and Andrey N., provided services to Stark Industries, a web hosting provider founded by Moldovan nationals Iurie and Ivan Neculiti. “They have been acting as enablers of various Russian state-sponsored and affiliated actors to conduct destabilizing activities including information manipulation, interference, and cyber-attacks against the Union and third countries,” the EU said last year, when Stark Industries was placed on the sanctioned entities list. Per de Volkskrant’s investigation, Andrey N. owns Mirhosting, which had physical servers deployed at various data centers. Those servers were rented to Stark Industries, which helped Russian hackers such as NoName057(16) launch distributed denial-of-service (DDoS) and other types of attacks against EU targets. The EU’s May 2025 sanctions prohibited European citizens and entities from aiding Stark, and the two Moldovan brothers restructured their company and moved part of the activities to Youssef Z.’s firm. Called WorkTitans and based in Enschede, the company rents server space and resells it, essentially obscuring the real customer and making abuse detection difficult. Related: Canadian Man Arrested for Operating Kimwolf Botnet Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested Related: 201 Arrested in Crackdown on Cybercrime in Middle East, North Africa Related: Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain AttackCisco Patches Critical Vulnerability in Secure WorkloadApple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud PreventionSocket Raises $60 Million at $1 Billion ValuationMicrosoft Patches Exploited UnDefend and RedSun Defender Zero-DaysMicrosoft Rolls Out Mitigations for ‘YellowKey’ BitLocker BypassOver 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain AttackGitHub Confirms Hack Impacting 3,800 Internal Repositories Latest News Ghost CMS Vulnerability Exploited to Hack Over 700 WebsitesOncology Institute Discloses Data Breach266,000 Affected by Data Breach at Radiology Associates of RichmondAnthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS ProjectsLaravel-Lang Packages Poisoned for Malware DeliveryDocketWise Data Breach Impacts 143,000Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit May 20, 2026 Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveJoe Chen has become Chief Technology Officer at Trellix.Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.SecureAuth has named Mark van Oppen as Chief Revenue Officer.More People On The MoveExpert Insights Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) The Mythos Moment: Enterprises Must Fight Agents with Agents Only with the right platform and an agentic, AI-driven defense, will enterprises be able to protect themselves in the agentic era. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — NoName057(16)

Entities

NoName057(16) (threat_actor)Stark Industries (threat_actor)Mirhosting (product)WorkTitans (product)Dutch Fiscal Information and Investigation Service (FIOD) (vendor)