Dutch Authorities Arrest Two Bulletproof Hosting Administrators Linked to Russia-Aligned Threat Actors
The two suspects owned Dutch-registered companies that allegedly supplied infrastructure used to support Russia-aligned cybercriminal operations.

Dutch law enforcement has arrested two individuals in the Netherlands on suspicion of administering a bulletproof hosting service that provided operational infrastructure to Russia-aligned threat actors. The suspects are the registered owners of Dutch companies that allegedly offered these services, shielding clients from takedown requests and law enforcement inquiries.
Bulletproof hosting operators occupy a specific and legally significant position in the cybercriminal supply chain. Unlike conventional web hosts, they are typically structured to ignore, delay, or route around abuse complaints, making them attractive to groups that require persistent, difficult-to-disrupt infrastructure. Dutch prosecutors have not, at the time of writing, publicly named the two individuals or specified which threat actor groups are alleged to have been among their clients.
The arrests follow a pattern of coordinated European action against infrastructure providers rather than the end-users of illicit services. The Netherlands — where the Politie's Team High Tech Crime (THTC) has developed considerable expertise in tracing hosting chains — has become a notable venue for such proceedings. THTC has previously participated in operations targeting infrastructure linked to groups including Conti-affiliated actors and Cl0p.
The legal theory in cases such as this tends to center on whether the hosting administrator knew, or should have known, that the services were being used for criminal purposes. Dutch criminal statutes on computer infrastructure offenses, combined with European Union frameworks on aiding and abetting cybercrime, give prosecutors several avenues (the precise charges had not been confirmed publicly as of this writing). The breadth of potential liability for hosting providers under EU Directive 2013/40/EU on attacks against information systems is relevant here, particularly Articles 7 and 8, which address the liability of legal persons.
And this is not the first time corporate structure has been used as partial insulation: the suspects' use of legitimately registered Dutch companies raises questions about whether existing company registration and anti-money-laundering checks are sufficient to identify such arrangements earlier.
But the core enforcement question — how to establish the requisite knowledge for criminal liability without access to private communications — remains unresolved across European jurisdictions. Prosecutors generally seek logs, payment records, and internal correspondence to show that administrators actively curated their client base.
So the outcome of this case may carry weight beyond the Netherlands, particularly for other EU member states assessing whether to pursue similar infrastructure administrators under the same directive.
The case is currently at an early pre-trial stage. Dutch prosecutors are expected to present formal charges at a preliminary hearing, after which the court will determine whether to extend pre-trial detention. No trial date has been set.



