Dutch Police Pull the Plug on 17-Million-Device Botnet Run Through 200+ NL Servers
Politie and NCSC seized command infrastructure hosted on Dutch soil, dismantling a network that pulled in PCs, phones, tablets and IoT gear at scale.

Dutch law enforcement has dismantled a botnet that, by their own count, had roped in at least 17 million infected devices worldwide.
The operation was run jointly by the Politie and the National Cyber Security Center (NCSC). Investigators say more than 200 servers physically located in the Netherlands were doing the work — acting as command, control and relay infrastructure for the network. Those servers are now in police hands.
The infected fleet is broad. Windows machines, tablets, smartphones, and a long tail of internet-connected IoT devices were all conscripted, according to the agencies. That mix is consistent with mass-opportunistic malware families that scoop up anything reachable rather than targeting a specific platform.
Neither agency has publicly named the malware family behind the botnet, the threat actor, or the specific crimes the network was used to commit. Botnets of this shape are typically rented out for DDoS, credential stuffing, proxy services for fraud, ad fraud, and as a delivery layer for ransomware affiliates.
Jurisdiction here sits with the Dutch authorities, with cross-border coordination likely flowing through Europol's EC3 given the international victim spread. The NCSC operates under the Ministry of Justice and Security and routinely notifies Dutch ISPs and downstream CERTs when victim IPs are identified.
17 million is a big number. For context, that puts this takedown in the same weight class as the 911 S5 disruption announced by US authorities in 2024, which counted around 19 million compromised IPs.
No arrests have been announced at the time of writing. The Politie has historically used seized botnet infrastructure to push victim-notification data into the Dutch politie.nl/checkjehack style portals, where users can check whether their email or IP appeared in seized datasets. Expect a similar lookup tool to surface in the coming weeks.
What affected users should do
If you suspect a device on your network was part of this — sluggish IoT gear, unexplained outbound traffic, a router you haven't patched in years — treat it as compromised rather than merely suspicious.
- Factory-reset IoT devices and routers, then apply the latest firmware before putting them back online. Change default credentials.
- On Windows, Android and iOS endpoints, run a current AV/EDR scan, rotate passwords for any accounts used on the device, and enable MFA on email and financial accounts.
- Watch the Politie's official channels and your national CERT for a victim-lookup tool tied to this seizure. Have I Been Pwned-style notifications may also surface once the dataset is processed.
The takedown removes the current C2 layer. It does not clean the endpoints. Without remediation on the device side, the same boxes will be recruited into the next botnet within weeks.


