Key takeaways
- On 2 July 2026 the FBI and IRS Criminal Investigation seized domains belonging to NetNut, a residential proxy service operated by Nasdaq-listed Alarum Technologies (ALAR).
- Investigators link the network to a botnet tracked as Popa, comprising at least two million devices that were compromised, often without their owners consent.
- We independently confirmed on 26 July 2026 that netnut.io serves a Federal Bureau of Investigation seizure notice.
- The buyer-side risk is indirect exposure: Google reported the network was widely resold and white-labeled, so some customers were routing traffic through it without knowing the brand.
- Seizure is not conviction. No charges or named defendants had been reported at the time of writing, and Alarum says it will cooperate with law enforcement.
A residential proxy is only as legitimate as the way its IP addresses were obtained. That sentence has been the argument of ethical proxy sourcing for years, usually as an abstraction. In July 2026 it stopped being abstract.
What happened, and when
On 2 July 2026, the FBI and IRS Criminal Investigation seized domains associated with NetNut, a residential proxy provider operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). The action was disclosed on 3 July alongside a coordinated technical disruption by Google's Threat Intelligence Group, Lumen and the Shadowserver Foundation.
Investigators tie the service to a botnet tracked as Popa, described as comprising "at least two million devices" that had been compromised by malicious software, in many cases without the device owner's knowledge or consent. Reporting describes the infection routes as pre-installed malware on cheap consumer hardware and trojanized applications, including proxy plugins distributed through the Badbox 2.0 ecosystem.
Google reported observing 316 distinct threat clusters using suspected NetNut exit nodes in a single week, spanning both criminal and espionage activity.
Alarum's legal counsel, Omer Weiss, said the company "takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated." By 8 July, Alarum stock had fallen roughly 67% to $2.62.
An important distinction: a domain seizure is an investigative action, not a finding of guilt. At the time of writing no charges had been filed publicly and no defendants had been named. The botnet linkage is what investigators and Google state; it has not been tested in court.
What we verified ourselves
Because seizure notices are sometimes lifted, and because the two NetNut domains were taken at different times, we checked directly rather than relying on reporting alone.
On 26 July 2026 we requested https://netnut.io/pricing/ and received HTTP 200 with the page title "Seized by the Federal Bureau of Investigation". The commercial site is gone; the seizure banner is what remains. This matches reporting that netnut.com was seized first, on 2 July, with netnut.io following by 8 July after a separate process.
We publish this as a dated first-party observation, in the same way we date every price in our pricing comparison. If you are reading this much later, re-check the domain yourself before acting.
Why a proxy network turns into a botnet
Every residential proxy provider faces the same supply problem: it needs IP addresses that belong to real homes, and it does not own any of them. There are only two ways to get them.
The legitimate route is to pay for consent. A provider partners with app developers who ask the user, in plain language, to share a slice of idle bandwidth in exchange for something — cash, an ad-free tier, in-game currency — and lets them withdraw at any time. This is slow, expensive, and permanently capped by how many people say yes.
The illegitimate route is to skip the asking. Bundle a silent proxy SDK into a free app, or ship it pre-installed on a cheap smart TV, and the pool grows without consent, without compensation, and without a cost ceiling.
From the buyer's side, traffic from both routes looks identical. Same latency, same success rate, same invoice. The difference is invisible in a dashboard and decisive in a courtroom — which is precisely why sourcing documentation, not benchmark numbers, is the thing worth reading before you sign.
The buyer's real exposure: white-label resale
The most consequential detail for anyone buying proxies is easy to miss. Google's Threat Intelligence Group stated that NetNut's infrastructure was "widely resold and white-labeled" by third-party proxy providers, and was "heavily sought out by cybercriminals seeking to obfuscate the source of their malicious traffic."
That means the set of affected buyers is larger than the set of NetNut customers. If you bought residential bandwidth from a small vendor that does not disclose its upstream, your invoice will not tell you whose exit nodes you used.
There is one question that resolves it, and it is worth sending today:
"Do you operate your own residential pool, or resell another network's? If you resell, name the upstream provider."
A vendor that answers plainly is a vendor you can audit. A vendor that treats the question as commercially sensitive has told you something too.
If you were routing traffic through NetNut
- Stop and re-route. The domains are under government control, so the service should be treated as unavailable regardless of what your remaining credits say.
- Preserve your records. Keep contracts, invoices and usage logs. They are what demonstrate what you bought, when, and for what purpose.
- Check your resellers, not just your direct vendors. Ask the upstream question above of every provider in your stack.
- Write down your use case. Price monitoring, ad verification and SEO measurement are ordinary commercial activities. Being able to show a documented, lawful purpose is materially different from reconstructing one later.
- Get advice if you have real exposure. If your organisation moved significant volume through the network, this is a question for your own counsel, not for a comparison site.
How to vet a provider's sourcing before you sign
The four networks we track publish materially different amounts of detail about where their IP addresses come from. The gap between them is the actual product difference — and after July 2026, the one that carries the most risk.
| Oxylabs | Bright Data | Decodo | IPRoyal | |
|---|---|---|---|---|
| How peers are recruited | Partner apps and SDK integrations, plus ISP-sourced IPs | Bright SDK embedded by app developers, enabled only after an explicit opt-in screen | Peer-to-peer network with informed opt-in; no partner apps named on the page | Direct partner Pawns.app plus IP service provider partnerships |
| What peers receive | Financial compensation or other rewards | In-kind only: rewards, fewer ads, virtual goods, upgraded app tier | Cash, calculated per GB contributed | $0.20/GB via Pawns.app, $5 minimum cashout, $3 welcome bonus |
| Self-graded sourcing | Tiers acquisition A+ (explicit consent) to C (malware); claims a majority Tier A+ | Developers must disclose participation and offer a 2-click opt-out | Peers keep full control over participation | Cites manual and automated vetting; ethics URL moved and the old one 404s |
| Buyer-side KYC | KYC form for every customer, risk-based escalation, EWDCI member | Strictest: verified companies only, human-reviewed, possible video call and ID | Automated fraud checks and screening for all; ID verification when flagged; EWDCI co-founder | Third-party KYC (iDenfy), mandatory only for ISP proxies |
| Restricted targets published | Compliance monitoring post-onboarding | Not stated on the pages retrieved | Blocks banking, government, streaming, app stores, ticketing | Not stated on the pages retrieved |
Read that table as a map of what each vendor is willing to put in writing, not as a ranking of virtue. Every row is a vendor claim; none of it has been independently audited by us. But a claim in writing is falsifiable and a silence is not, and the providers that name their acquisition channel are the ones you can actually hold to account.
Two rows deserve particular weight after this case. Named acquisition channels matter because "peer-to-peer network" describes both a consent-based pool and a botnet equally well. Buyer-side KYC matters because a network that will sell to anyone has little incentive to be careful about where its supply comes from — the same indifference tends to run in both directions.
Where to go instead
There is no version of this article that ends with a single correct answer, because the right provider depends on volume, geography and how much compliance paperwork your organisation needs. Our guide to choosing a proxy provider walks the full decision, and best residential proxies covers the shortlist in depth.
If what you need is the most documentation about sourcing and the strictest customer vetting, Bright Data and Oxylabs publish the most detail of the four. If you are replacing a mid-size workload and want to test before committing, start with the free trial terms rather than a headline rate.
Oxylabs
Publishes a tiered sourcing model (A+ to C) and requires a KYC form from every customer.
This article contains affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Our tests and rankings are independent and never influenced by partners.
Bright Data
Strictest buyer vetting of the four: verified companies only, human-reviewed.
This article contains affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Our tests and rankings are independent and never influenced by partners.
Whichever you pick, send the upstream question first. The cheapest per-GB rate on the market is worth nothing if the network behind it is seized in a year.
Not legal advice
This article summarises public reporting and our own dated observation of the seized domain. It is general information, not legal advice, and it does not assert that any person or company has committed a crime — no charges had been reported at the time of writing. If your organisation has material exposure, consult qualified counsel. For the wider legal picture around data collection, see is web scraping legal.
Sources: Krebs on Security — FBI Seizes NetNut Proxy Platform, Popa Botnet, BleepingComputer — NetNut proxy network disrupted, 2 million infected devices cut off, and our own retrieval of https://netnut.io/pricing/ on 26 July 2026. Provider sourcing and KYC statements are from data/provider-facts.json, retrieved 17 July 2026.