Netherlands Seizes 800 Servers, Arrests Two for Aiding Russia Cyberattacks

Two men arrested in Netherlands for running hosting companies that enabled Russian cyberattacks and disinformation, with over 800 servers seized.

By Central
Dutch authorities dismantle a hosting network used to evade EU sanctions and launch attacks, including against Danish elections.

Dutch authorities have arrested two men who co-owned internet hosting companies allegedly used to provide critical infrastructure for Russian cyberattacks, influence operations, and disinformation campaigns targeting European Union member states. The arrests, executed by the Dutch Fiscal Information and Investigation Service (FIOD) on May 18, resulted in the seizure of more than 800 servers across multiple data centers and company premises. The suspects, a 57-year-old from Amsterdam and a 39-year-old from The Hague, are charged with violating sanctions law by making economic resources available to EU-sanctioned entities. The operation dismantles a key technical backbone that had enabled pro-Russian hacking groups to launch devastating distributed denial-of-service (DDoS) attacks and other malicious activities with near-impunity.

The investigation centered on the activities of MIRhosting, a Netherlands-based internet service provider, and its associated entities. The 39-year-old suspect, Andrey Nesterenko, a Russian native and former piano prodigy who founded MIRhosting’s parent company in 2004, was identified as a central figure. The second suspect, Youssef Zinad, 57, was also arrested and is alleged to have been instrumental in the operational management of the hosting network. The FIOD’s action directly targeted the infrastructure that had been used to keep Stark Industries Solutions, a hosting provider sanctioned by the EU, connected to the wider internet after previous sanctions failed to fully sever its operations.

How Stark Industries Survived EU Sanctions

Stark Industries Solutions emerged as a significant threat actor infrastructure provider shortly before Russia’s full-scale invasion of Ukraine in 2022. The provider quickly became a primary source for massive DDoS attacks against European targets and a top supplier of proxy and anonymity services frequently linked to Russian state-sponsored hacking groups. In May 2025, the EU sanctioned PQHosting and its owners, the Neculiti brothers, for providing Stark with one of its main internet conduits. However, a subsequent investigation revealed that Stark’s remaining internet connection was provided by MIRhosting.

When news of the impending PQHosting sanctions leaked, critical Stark network assets were hastily transferred to a new entity called the[.]hosting, controlled by a Dutch company, WorkTitans BV. Further analysis showed that WorkTitans was run by Nesterenko and Zinad, and that it was solely dependent on MIRhosting for its internet connectivity. This transfer allowed Stark’s malicious activities to continue unabated for months despite the EU sanctions, directly leading to the current investigation and arrests.

The Danish Election Connection

The Dutch investigation was prompted, in part, by evidence that WorkTitans and MIRhosting networks were the most heavily used in pro-Russian cyberattacks against Danish government bodies during the week of Denmark’s municipal elections in November 2025. A report by the Dutch daily de Volkskrant detailed how the infrastructure was leveraged to launch disruptive attacks intended to interfere with the democratic process. Prior to his arrest, Nesterenko denied any knowledge of the misuse, stating he had severed ties with the Neculiti brothers when sanctions were enacted. MIRhosting released a statement asserting it had found no evidence of its services being used to influence the Danish elections, though it temporarily paused services to WorkTitans as a precautionary measure.

A Long History of Hosting Malicious Activity

Nesterenko’s involvement in providing a safe haven for malicious cyber activity is not new. In 2008, his company hosted stopgeorgia[.]ru, a hacktivist website that coordinated cyberattacks against Georgia concurrently with the Russian military invasion of that country. This event is widely considered the first instance of a major cyberattack occurring in parallel with conventional warfare. In a statement provided prior to his arrest, Nesterenko claimed that MIRhosting does not support cybercrime or sanctions evasion, and that the hardware transfer to WorkTitans was not intended to circumvent sanctions. He argued that the crackdown would harm innocent parties and would not stop cybercrime. Zinad, who previously worked at MIRhosting and was described by Nesterenko as a business consultant, has not responded to requests for comment.

What This Means for European Cybersecurity

This arrest represents a significant blow to the logistical framework that enables Russian hybrid warfare. The seizure of 800 servers and the disruption of a major hosting provider will create operational friction for threat actors who relied on this specific infrastructure. It also underscores the critical importance of investigating and prosecuting intermediaries who knowingly or negligently provide internet services to sanctioned entities. The case highlights the cat-and-mouse nature of sanctions enforcement, where assets are rapidly moved between shell companies and jurisdictions to evade legal consequences. The Dutch action demonstrates a clear commitment to closing these loopholes and holding enablers of cyberattacks accountable, even when they operate from within the EU.

How Organizations Can Protect Against Sanctions Evasion Risks

For companies and government bodies operating within the EU and the Five Eyes intelligence alliance, this case underscores the need to rigorously vet third-party vendors and hosting providers. It is critical to monitor for rapid changes in IP ownership, anonymous shell company registrations, and known associations with sanctioned entities. The use of a reputable threat intelligence platform that tracks “bulletproof” hosting providers and their network blocks can help security teams proactively block traffic from compromised or malicious infrastructure.

What Affected Users and Organizations Should Do Now

While this operation targets a specific criminal network, it serves as a broader reminder of the persistent threat landscape. Organizations should immediately review their network logs for any suspicious connections originating from IP ranges associated with MIRhosting, WorkTitans, or the[.]hosting. For individuals concerned about their digital privacy and security in the wake of such state-sponsored cyberattacks, the most effective action is to adopt a layered security approach. Using a reputable no-log VPN service with a verified privacy policy and a kill switch provides a critical layer of protection against traffic interception and targeted attacks. Additionally, enabling two-factor authentication on all critical accounts, using strong, unique passwords managed through a zero-knowledge password manager, and keeping all software and operating systems fully patched are essential basic steps. Vigilance and proactive defense remain the most reliable countermeasures against the evolving tactics of state-aligned threat actors.

Share This Article