discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Dutch cops liberate 17M devices from botnet’s clutches

Dutch police say they dismantled a botnet of at least 17 million infected devices after tracing 200 servers in the Netherlands.

By Connor Jones·May 29·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Police and the NCSC-NL say a researcher tip led them to infrastructure behind a huge botnet, and a hosting provider shut it down after finding criminal use. The same week, NCSC-NL warned that residential proxy networks are rising and can hide cybercrime.

Why it matters

The takedown shows how much disruption a botnet can create when it spans millions of devices and crosses infrastructure providers. It also highlights the growing overlap between botnets, residential proxies, and the consumer devices that quietly end up enrolled in both.

Police in the Netherlands found a giant secret network of hacked gadgets. It had millions of devices in it, and many were ordinary things like routers and phones.

Think of it like one bad boss controlling a huge pile of toys from hidden rooms. Police traced the rooms, took some servers away, and the hosting company shut the whole thing down.

The story also warns that weak passwords and old software make gadgets easy to grab. Keeping devices updated is like locking the front door before trouble gets in.

Analysis

What happened

Dutch police said they dismantled a botnet that involved at least 17 million infected devices. The investigation started after a researcher at the Netherlands' National Cyber Security Centre tipped them off, which led police to uncover 200 servers supporting the botnet inside the country.

Cybercrime specialists from The Hague Police Unit seized several servers from a hosting provider for analysis. After that, the provider shut the infrastructure down once it realized the services were being used for “criminal purposes.” Police did not say how the botnet was being used in this case, but they noted the common uses of botnets include phishing, DDoS attacks, and online fraud.

What is known about the network

The police and NCSC-NL did not name the botnet, which is unusual for a takedown of this kind. They also did not spell out every device type involved, but their statements pointed to poorly secured consumer gear such as routers, mobile devices, and IoT hardware.

Both organizations urged basic defensive hygiene: stop relying on default passwords, avoid apps from unofficial sources, and keep software updated.

Wider context

The takedown landed alongside a separate NCSC-NL warning about the rise of residential proxy networks, which it called a worrying trend. Those services are legal, but they are often abused to hide malicious traffic and make attacks harder to trace. NCSC-NL said the misuse of residential proxies makes it harder to map digital threats and can pull unsuspecting consumers into cybercrime without their knowledge.

On the same day, NCSC-NL also published its annual Cybercrime Monitor. Using 2024 data, it said external cyberattacks on Dutch companies were at a nine-year low: 4 percent of organizations reported an external attack, down from 11 percent in 2016. It linked much of the improvement to broader use of multi-factor authentication, which it said is now effectively universal in larger organizations and has also risen sharply among smaller ones.

Key points

  • Dutch police said they dismantled a botnet spanning at least 17 million infected devices.
  • Investigators traced 200 servers in the Netherlands and seized several from a hosting provider.
  • The botnet was not named, and officials did not say exactly how it was used.
  • NCSC-NL separately warned about rising abuse of residential proxy networks.
  • The agency said wider use of multi-factor authentication is linked to fewer reported attacks on Dutch companies.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityglobal-newstechiotpolicy

Author

Connor Jones

Intelligence analysis by

GPT-5.4 Mini

Published

May 29, 2026

Source

theregister.com

Share

Topics

securityglobal-newstechiotpolicy

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…