Bulletproof Hosting Is Changing What’s Expected of Hosting Providers

Writer: Jordan Sprogis

Jordan Sprogis, Contributing Expert

Jordan Sprogis is a creative writer and tech researcher who has been working on online content for the better part of a decade. She holds a bachelor's degree in professional writing from Western Connecticut State University and has devoted much of her career to crafting content for various web verticals, including CyberSpyder and The Echo. Since joining HostingAdvice, Jordan has combined her storytelling ability with her fascination for advancements in technology to pen over 500 articles geared toward industry pros and newcomers alike.

Editor: Lillian Castro

Lillian Castro, Senior Editor

Lillian Castro brings more than 30 years of editing and journalism experience to our team. She has written and edited for major news organizations, including The Atlanta Journal-Constitution and the New York Times, and she previously served as an adjunct instructor at the University of Florida. Today, she edits HostingAdvice content for clarity, accuracy, and reader engagement.

Reviewer: Cristian Lopez

Cristian Lopez, News Manager

Cristian Lopez uses his Business Marketing background from the University of Illinois at Chicago to create comfortable environments for customers, clients, and colleagues to share their thoughts and ideas openly. From interviewing tech leaders to conducting UX market research projects, Cristian knows the importance of storytelling — a key variable for innovation and inspiration. His goal at HostingAdvice is to wow readers on the ever-evolving nature of the tech industry and bring his audience the most reliable and exciting content on all things hosting.

Follow the HostingAdvice team for a daily dose of tech news, trending IT discussions, and interviews with the web's most innovative technologists.
Follow Us:
2.7k
1k

When Dutch authorities recently seized more than 800 servers connected to the network behind the EU-sanctioned Stark Industries (no, not that one — but a UK-registered hosting provider), it became one of the biggest crackdowns on bulletproof hosting (BPH).

The operation, which has been accused of helping cyberattackers across Europe, resulted in the arrest of two operators and the seizure of hundreds of servers, laptops, mobile phones, and records at data centers in Dronten and Schiphol-Rijk.

Screenshot of the.hosting's homepage, which says it is closed
RIP to this rebrand.

If you visit the website now, you’ll be met with a teary-eyed announcement: “The project has shut down. The site is no longer maintained. All services have been stopped.”

The EU had already penalized Stark Industries on May 20, 2025 for supplying infrastructure to Russian bad actors. But its owners, the Neculiti brothers, got wind of the sanctions about two weeks before. Four days later, PQ Hosting Plus took over Stark’s main network number, and then nine days later, THE.Hosting was announced under Dutch company, WorkTitans B.V.

But if the Stark Industries operators saw the sanctions coming ahead of time and used that window to move everything to a new site, then what’s the point of sanctioning?

Taking Down Servers Doesn’t Always Take Down the Threat

Sanctions clearly weren’t enough. It turns out, neither was the raid: Infrastructure continued scanning at about its normal daily rate in the days following the seizure. Researchers at ELLIO, a threat-intel research firm, have been watching the Stark Industries/THE.hosting network closely since last year.

One would think everything would have shut down immediately. But more than a week after the FIOD pulled hundreds of servers, ELLIO said “the scanning did not stop,” with traffic continuing at similar levels as before the takedown. Which may be exactly why these kinds of hosts are being seen as part of the infrastructure problem. The fact is sanctioning and seizing won’t stop people who can make an entire shell company.

So could better KYC measures help?

In November, CISA, the NSA, the FBI, and cyber agencies from five other countries released a joint guide for ISPs and network defenders. In essence, it encourages anyone selling infrastructure to build “know your customer” (KYC) checks before leasing infrastructure.

“Bulletproof hosting is one of the core enablers of modern cybercrime,” said Acting CISA Director Madhu Gottumukkala. “By shining a light on these illicit infrastructures and giving defenders concrete actions, we are making it harder for criminals to hide and easier for our partners to protect the systems Americans rely on every day.”

“Bulletproof hosting is one of the core enablers of modern cybercrime.” — Acting CISA Director Madhu Gottumukkala

It’s kind of what became expected of banks when money laundering became commonplace. For most of its history, a bank’s job was to hold money, not also investigate where it came from. Now, banks are required to do the things we consider the basics today — verify ID, KYC, file suspicious activity, flag transactions over a certain dollar amount and frequency.

It worked, for the most part: Moving large amounts of dirty money did get harder. But it also created an entire underground market for getting around it.

It’s the entire background of “Breaking Bad,” right? Walter White had a deposit-the-drug-money problem because you can’t just drop $1 million into an account without the bank calling the authorities. But buying a car wash made it a million times easier to make the money appear legitimate.

Hosting may just have to figure out how to flow with the same kind of security change.

Hosting Is Entering Its ‘Know Your Customer’ Era

In general, infrastructure providers are responding. Cloudflare, for example, has expanded its abuse-reporting systems and is consistently investing in automated tools that help mitigate abusive activity. By some estimates, about 20% of the web uses Cloudflare, so hopefully, it’ll make a dent.

DMCA Reports Jumped More Than 1,000% in Six Months

Following an anti-piracy initiative, DMCA reports submitted to Cloudflare increased from roughly 11,000 in H2 2024 to 125,000 in H1 2025. The company also expanded enforcement, taking action on 54,000 reports compared to approximately 1,000 in the previous reporting period.

020K40K60K80K100K120K140KH2 2024H1 2025Reporting PeriodNumber of Reports
  • DMCA Reports Received
  • Reports Actioned

Cloudflare’s reporting shows that Digital Millennium Copyright Act (DMCA) takedown requests for hosting services have jumped from 11,000 to 125,000 over the course of six months.

It’s not the same thing as BPH, but it is another infrastructure provider asked to police their users. Think about that: Even Cloudflare, one of the largest abuse-mitigation operations in the industry, is still playing catch-up. Defenses built to respond after the fact can’t keep up with attacks that are faster and shorter than ever.

Hosting providers aren’t banks, and there’s no universal KYC mandate requiring them to act like one. But if the response to bulletproof hosting is any indication, providing the server and dealing with abuse later may not be worth it.

About the Author

Contributing Expert

Jordan Sprogis is a creative writer and tech researcher who has been working on online content for the better part of a decade. She holds a bachelor's degree in professional writing from Western Connecticut State University and has devoted much of her career to crafting content for various web verticals, including CyberSpyder and The Echo. Since joining HostingAdvice, Jordan has combined her storytelling ability with her fascination for advancements in technology to pen over 500 articles geared toward industry pros and newcomers alike.

« BACK TO: BLOG

Meet the Experts

Our team of experts with a combined 50+ years of experience in web hosting serve insight and advice to more than 20 million users!

We Know Hosting

$

4

8

,

2

8

3

spent annually on web hosting!