Key Takeaways
When Dutch authorities recently seized more than 800 servers connected to the network behind the EU-sanctioned Stark Industries (no, not that one — but a UK-registered hosting provider), it became one of the biggest crackdowns on bulletproof hosting (BPH).
The operation, which has been accused of helping cyberattackers across Europe, resulted in the arrest of two operators and the seizure of hundreds of servers, laptops, mobile phones, and records at data centers in Dronten and Schiphol-Rijk.

If you visit the website now, you’ll be met with a teary-eyed announcement: “The project has shut down. The site is no longer maintained. All services have been stopped.”
The EU had already penalized Stark Industries on May 20, 2025 for supplying infrastructure to Russian bad actors. But its owners, the Neculiti brothers, got wind of the sanctions about two weeks before. Four days later, PQ Hosting Plus took over Stark’s main network number, and then nine days later, THE.Hosting was announced under Dutch company, WorkTitans B.V.
But if the Stark Industries operators saw the sanctions coming ahead of time and used that window to move everything to a new site, then what’s the point of sanctioning?
Taking Down Servers Doesn’t Always Take Down the Threat
Sanctions clearly weren’t enough. It turns out, neither was the raid: Infrastructure continued scanning at about its normal daily rate in the days following the seizure. Researchers at ELLIO, a threat-intel research firm, have been watching the Stark Industries/THE.hosting network closely since last year.
One would think everything would have shut down immediately. But more than a week after the FIOD pulled hundreds of servers, ELLIO said “the scanning did not stop,” with traffic continuing at similar levels as before the takedown. Which may be exactly why these kinds of hosts are being seen as part of the infrastructure problem. The fact is sanctioning and seizing won’t stop people who can make an entire shell company.
So could better KYC measures help?
In November, CISA, the NSA, the FBI, and cyber agencies from five other countries released a joint guide for ISPs and network defenders. In essence, it encourages anyone selling infrastructure to build “know your customer” (KYC) checks before leasing infrastructure.
“Bulletproof hosting is one of the core enablers of modern cybercrime,” said Acting CISA Director Madhu Gottumukkala. “By shining a light on these illicit infrastructures and giving defenders concrete actions, we are making it harder for criminals to hide and easier for our partners to protect the systems Americans rely on every day.”
“Bulletproof hosting is one of the core enablers of modern cybercrime.” — Acting CISA Director Madhu Gottumukkala
It’s kind of what became expected of banks when money laundering became commonplace. For most of its history, a bank’s job was to hold money, not also investigate where it came from. Now, banks are required to do the things we consider the basics today — verify ID, KYC, file suspicious activity, flag transactions over a certain dollar amount and frequency.
It worked, for the most part: Moving large amounts of dirty money did get harder. But it also created an entire underground market for getting around it.
It’s the entire background of “Breaking Bad,” right? Walter White had a deposit-the-drug-money problem because you can’t just drop $1 million into an account without the bank calling the authorities. But buying a car wash made it a million times easier to make the money appear legitimate.
Hosting may just have to figure out how to flow with the same kind of security change.
Hosting Is Entering Its ‘Know Your Customer’ Era
In general, infrastructure providers are responding. Cloudflare, for example, has expanded its abuse-reporting systems and is consistently investing in automated tools that help mitigate abusive activity. By some estimates, about 20% of the web uses Cloudflare, so hopefully, it’ll make a dent.
DMCA Reports Jumped More Than 1,000% in Six Months
Following an anti-piracy initiative, DMCA reports submitted to Cloudflare increased from roughly 11,000 in H2 2024 to 125,000 in H1 2025. The company also expanded enforcement, taking action on 54,000 reports compared to approximately 1,000 in the previous reporting period.
- DMCA Reports Received
- Reports Actioned
Cloudflare’s reporting shows that Digital Millennium Copyright Act (DMCA) takedown requests for hosting services have jumped from 11,000 to 125,000 over the course of six months.
It’s not the same thing as BPH, but it is another infrastructure provider asked to police their users. Think about that: Even Cloudflare, one of the largest abuse-mitigation operations in the industry, is still playing catch-up. Defenses built to respond after the fact can’t keep up with attacks that are faster and shorter than ever.
Hosting providers aren’t banks, and there’s no universal KYC mandate requiring them to act like one. But if the response to bulletproof hosting is any indication, providing the server and dealing with abuse later may not be worth it.
