Dutch financial crime investigators have arrested two men and seized more than 800 servers as part of a probe into hosting infrastructure allegedly used to support cyberattacks, interference operations, and disinformation campaigns.
The Dutch Fiscal Information and Investigation Service, known as FIOD, said the suspects are a 57-year-old company director and a 39-year-old man who led a separate business providing internet connectivity. Investigators allege the companies indirectly made economic resources available to Russian and Belarusian entities sanctioned by the European Union.
At the center of the case is Stark Industries, a web hosting firm founded on February 10, 2022, shortly before Russia’s full-scale invasion of Ukraine. Dutch authorities say the hosting operation supported activity by the Russian Federation that undermined democracy and security, including information manipulation and disruption of public and economic systems.
What Dutch authorities seized
FIOD carried out raids at data centers in Dronten and Schiphol-Rijk, along with searches in Enschede and Almere. Investigators seized servers, laptops, phones, and administrative records.
The operation was not only a cybercrime action. It also appears to be a sanctions case. Stark Industries was added to the EU sanctions list on May 20, 2025. After that designation, investigators believe the hosting infrastructure was moved to a newly created Dutch company that acted as a front for sanctioned entities.
Dutch reporting has identified that company as WorkTitans B.V., which offered hosting services under the brand THE.Hosting. That reporting also connects the case to Mirhosting, an Almere-based provider said to have operated physical servers, colocation services, and high-capacity connectivity into major internet exchanges in Amsterdam and Frankfurt.
For security teams and buyers of hosting, DDoS mitigation, and infrastructure monitoring services, the case is a reminder that provider risk is not limited to uptime or pricing. Abuse handling, sanctions exposure, network transparency, and upstream relationships can become operational risks for legitimate customers too.
Why the infrastructure mattered
The seized systems were allegedly part of a hosting chain that allowed traffic connected to Stark Industries to enter European networks and reach WorkTitans-controlled infrastructure. Authorities have not published a full technical map of the network, but the case highlights how physical hosting, connectivity providers, and front companies can be combined to keep controversial or abusive infrastructure online.
The same Dutch reporting alleged that Danish authorities and infrastructure providers linked WorkTitans to attacks by the pro-Russian hacktivist group NoName057(16), which has previously targeted organizations with distributed denial-of-service attacks. That specific link has not been independently verified, so it should be treated as an allegation rather than a confirmed finding.
WorkTitans did not respond to requests for comment cited in the reporting. Mirhosting denied knowingly supporting illegal activity and said it intervened quickly after receiving abuse complaints.
Key details for infrastructure buyers
The case gives security and procurement teams several practical questions to ask when assessing hosting or network providers:
- Does the provider publish a clear abuse handling process and response timeline?
- Can the provider explain its upstream carriers, data center locations, and jurisdictional exposure?
- Does the provider screen customers and counterparties for sanctions risk?
- Are customers given enough logging and routing visibility to investigate suspicious traffic?
- Can the provider demonstrate how it separates legitimate customers from high-risk infrastructure?
These questions matter because a seizure at the provider level can affect more than the suspect customers. When investigators take physical servers or administrative systems, unrelated tenants may face downtime, data access problems, or urgent migration work.
The Dutch investigation is still developing. For now, the confirmed action is substantial: two arrests, more than 800 servers seized, and a sanctions-linked probe into infrastructure that authorities say supported Russian-aligned cyber and information operations.
