Dutch cops liberate 17M devices from botnet’s clutches
Dutch police say they dismantled a botnet of at least 17 million infected devices after tracing 200 servers in the Netherlands.
Intelligence analysis by GPT-5.4 Mini
Police and the NCSC-NL say a researcher tip led them to infrastructure behind a huge botnet, and a hosting provider shut it down after finding criminal use. The same week, NCSC-NL warned that residential proxy networks are rising and can hide cybercrime.
Police in the Netherlands found a giant secret network of hacked gadgets. It had millions of devices in it, and many were ordinary things like routers and phones.
Think of it like one bad boss controlling a huge pile of toys from hidden rooms. Police traced the rooms, took some servers away, and the hosting company shut the whole thing down.
The story also warns that weak passwords and old software make gadgets easy to grab. Keeping devices updated is like locking the front door before trouble gets in.
Analysis
What happened
Dutch police said they dismantled a botnet that involved at least 17 million infected devices. The investigation started after a researcher at the Netherlands' National Cyber Security Centre tipped them off, which led police to uncover 200 servers supporting the botnet inside the country.
Cybercrime specialists from The Hague Police Unit seized several servers from a hosting provider for analysis. After that, the provider shut the infrastructure down once it realized the services were being used for “criminal purposes.” Police did not say how the botnet was being used in this case, but they noted the common uses of botnets include phishing, DDoS attacks, and online fraud.
What is known about the network
The police and NCSC-NL did not name the botnet, which is unusual for a takedown of this kind. They also did not spell out every device type involved, but their statements pointed to poorly secured consumer gear such as routers, mobile devices, and IoT hardware.
Both organizations urged basic defensive hygiene: stop relying on default passwords, avoid apps from unofficial sources, and keep software updated.
Wider context
The takedown landed alongside a separate NCSC-NL warning about the rise of residential proxy networks, which it called a worrying trend. Those services are legal, but they are often abused to hide malicious traffic and make attacks harder to trace. NCSC-NL said the misuse of residential proxies makes it harder to map digital threats and can pull unsuspecting consumers into cybercrime without their knowledge.
On the same day, NCSC-NL also published its annual Cybercrime Monitor. Using 2024 data, it said external cyberattacks on Dutch companies were at a nine-year low: 4 percent of organizations reported an external attack, down from 11 percent in 2016. It linked much of the improvement to broader use of multi-factor authentication, which it said is now effectively universal in larger organizations and has also risen sharply among smaller ones.
Key points
- Dutch police said they dismantled a botnet spanning at least 17 million infected devices.
- Investigators traced 200 servers in the Netherlands and seized several from a hosting provider.
- The botnet was not named, and officials did not say exactly how it was used.
- NCSC-NL separately warned about rising abuse of residential proxy networks.
- The agency said wider use of multi-factor authentication is linked to fewer reported attacks on Dutch companies.



