The Netherlands has launched one of its largest cybercrime operations, seizing 800 servers and arresting two people accused of operating IT infrastructure used by Russia for cyberattacks, influence operations and disinformation campaigns within the European Union. The operation is the culmination of a year-long investigation focused on the infrastructure of Stark Industries Solutions and its successors. The Netherlands is sending a strong message against hosting providers that facilitate state-sponsored cyberattacks.
See also: FlowerStorm phishing gang adopts virtual machine obfuscation

The Dutch financial crime agency FIOD arrested a 57-year-old man from Amsterdam and a 39-year-old man from The Hague, charging them with violating the Sanctions Act by directly or indirectly making financial resources available to entities subject to EU. The searches were carried out at three businesses in Enschede and Almere and at two data centres in Dronten and Schiphol-Rijk. The coordinated operation revealed the scope of the infrastructure used for hostile activities, with the seizure also including laptops, phones and a significant amount of digital evidence.
The Dutch investigation focuses on Stark Industries , a large hosting provider that emerged just two weeks before the Russian invasion of Ukraine . Stark quickly became the source of massive DDoS attacks against European targets and emerged as a leading provider of proxy and anonymity services that repeatedly appeared in cyberattacks linked to Russian hacking groups. The timing of the company’s emergence was not coincidental – cybersecurity experts believe it was part of a premeditated strategy to create infrastructure that would support Russian hybrid warfare operations.
Infrastructure transfer after EU sanctions in the Netherlands
In May 2025 , the EU imposed sanctions on PQHosting and the Neculiti brothers for their assistance in Russia ’s hybrid warfare efforts . However, these sanctions failed to target Stark ’s remaining connection to the internet – a Netherlands- based internet service provider called MIRhosting . This omission proved critical, as it allowed the Russian infrastructure to continue operating through alternative channels. The case highlights the complexity of sanctioning interconnected hosting networks and the need for more comprehensive approaches.
See also: Russian GRU cyber campaign targets Ukrainian support companies

MIRhosting is operated by Andrey Nesterenko , a 39-year-old Russian who runs the business from the Netherlands . When information leaked to the media that PQHosting and the Neculiti brothers were to be subject to EU sanctions, the Stark network assets were transferred to a new entity called the-hosting , under the control of the Dutch entity WorkTitans BV . This rapid transfer of assets demonstrates the planned nature of the business and the operators’ ability to anticipate and react to regulatory threats.
WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad . WorkTitans received connectivity to the wider internet exclusively through MIRhosting , where Zinad had previously worked. This close connection between companies and individuals reveals a complex network of partnerships designed to circumvent sanctions and keep hostile infrastructure operational.
Technical protection advice for organizations
The case highlights how hosting infrastructure can be used as a weapon on a large scale to support both cyberattacks and information operations. Cybersecurity experts recommend that organizations monitor for targeted DDoS and maintain rate limits, scrubbing capabilities, and backup capacity. In addition, it is critical to use threat intelligence to identify infrastructure connected to providers that are subject to sanctions or are prone to abuse, including successor brands and resellers. Organizations should also strengthen their defenses against influence operations by monitoring for fake domains, cloned websites, and bot-powered narratives.
See also: Russia: Apple stops all payments – No more subscription renewals

MIRhosting an internal investigation into the allegations regarding the Danish and has temporarily suspended services. The case is expected to have broader implications for the hosting industry, as providers will need to step up their due diligence and monitoring processes to avoid similar legal consequences, according to a report by Krebs on Security.
