Cyber Security

Dutch Police seize 250 servers used for Bulletproof Hosting

0

Dutch authorities have seized around 250 physical servers running a bulletproof hosting service used exclusively by cybercriminals to maintain anonymity and evade law enforcement.

The Dutch police (Politie) did not disclose the name of the service but said it had supported illegal activity since 2022 and had appeared in over 80 cybercrime investigations worldwide.

Bulletproof hosting providers offer infrastructure that ignores abuse reports, resists takedown requests, and avoids Know Your Customer (KYC) checks. These services are typically used by ransomware gangs, malware operators, phishing groups, spammers, and even money-laundering operations. Clients often pay in cryptocurrency to stay anonymous.

Thousands of virtual servers taken offline

The targeted provider advertised full anonymity with zero cooperation with law enforcement. Investigators say the platform supported ransomware attacks, botnets, phishing campaigns, and even child abuse content distribution.

During the November 12 operation, police seized the servers located in data centers in The Hague and Zoetermeer. Taking down the physical servers also disabled thousands of virtual servers running on the same infrastructure.

A forensic investigation is now underway to identify operators and customers. No arrests have been announced.

The seizure came shortly after the Netherlands played a major role in the latest phase of Operation Endgame, which disrupted the Rhadamanthys, VenomRAT, and Elysium malware networks. That action included nine data center raids and the seizure of 83 servers and 20 domains.
However, Dutch police confirmed that the server takedown is not related to the Operation Endgame actions.

Although police declined to name the provider, sources indicated that servers belonging to CrazyRDP—a hosting service known for no-logs and no-KYC policies—were seized on November 12 in The Hague. The service has since gone offline.

CrazyRDP offered anonymous VPS and RDP access and was commonly recommended among cybercriminals. Several security reports have also highlighted its involvement in malicious activities.

The official CrazyRDP Telegram channel wiped its posts last week and redirected users to a new channel, where customers reported losing access to dozens of servers. Many suspected an exit scam after support staff cited “technical issues” and then went silent.

Although it remains unconfirmed whether CrazyRDP was the bulletproof host taken down, the service has been offline since the police operation.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

LG Source Code and Credentials allegedly leaked by hacker

Previous article

Oracle Identity Manager Zero-Day exploited

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *