Summary
- On July 2, 2026, the FBI and the IRS Criminal Investigation Division seized hundreds of NetNut domains, one of the world's largest residential proxy providers.
- NetNut relied on the Popa botnet: at least 2 million household devices — Smart TVs and streaming boxes — converted into exit nodes without the genuine consent of their owners.
- In a single week in June, Google identified 316 threat actor clusters using NetNut exit nodes.
- Google warns that many well-known residential proxy brands were reselling NetNut in whitelabel mode. In other words: you may have been using it without knowing it.
- Shares of its parent company, Alarum Technologies (NASDAQ: ALAR), fell approximately 67% in one week.
On July 2, 2026, the NetNut homepage was replaced by an FBI seizure notice. What followed was not just the shutdown of a platform: it was a warning signal for the entire data extraction industry.
This article examines what happened, what it means for engineering teams and companies that depend on proxy infrastructure, and why the criteria used to choose a data provider today is simultaneously a legal decision and an operational continuity decision.
1. The Operation: What Happened on July 2, 2026
The FBI, in coordination with the IRS Criminal Investigation Division, the Google Threat Intelligence Group (GTIG), Lumen Technologies (Black Lotus Labs), and the Shadowserver Foundation, seized hundreds of domains linked to NetNut.
The seizure was not simultaneous, and the detail matters. On July 2,
netnut.com went down, but the main service domain, netnut.io, remained operational and advertising residential proxies for hours. Registered with Namecheap, its transfer required an additional step: WHOIS records show it was transferred to FBI name servers (ns1.fbi.seized.gov) on July 3 at 05:04 UTC, and propagation took several more days to complete. By July 8, the corporate website of the parent company, alarum.io, was also displaying the seizure notice.
NetNut was commercially operated by Alarum Technologies Ltd., an Israeli company publicly traded on NASDAQ under the ticker ALAR and headquartered in Tel Aviv. Until the moment of seizure, it marketed itself as a premium rotating residential proxy service for web scraping, price monitoring, and market intelligence. In the week following the FBI action, its stock collapsed approximately 67%, to $2.62.
The action was not an isolated event: it was the conclusion of an investigation that took public shape on June 19, 2026, when three cybersecurity firms simultaneously published findings linking NetNut's infrastructure to the Popa botnet.
2. The Popa Botnet: How It Worked and Why It Matters
Popa is the technical name for the network of compromised devices that underpinned NetNut's residential IP infrastructure. Its operation relied on three primary mechanisms.
Propagation via hidden SDKs. The Popa SDK was embedded in low-cost Android-based devices — primarily Smart TVs and streaming boxes — and in unofficial apps such as SmartTube. Once installed, it converted the device into a proxy exit node without presenting the user with any clear notice or requesting explicit consent.
The scope of the problem extends well beyond NetNut. According to a report from proxy tracking firm Spur, 42% of the apps available for LG's webOS television platform includes SDKs that convert the TV into a permanent residential proxy node. On Samsung's Tizen apps, the proportion exceeds 25%.
Layering over Vo1d. Researchers documented that Popa operated as an additional layer on top of a pre-existing Android botnet called Vo1d. While Vo1d managed control of compromised devices, Popa channeled their traffic into NetNut's proxy infrastructure.
Scale and diversity of threat actors. The impact was not theoretical. In a single week of June 2026, the GTIG identified 316 distinct threat actor clusters — criminal and espionage groups — using NetNut exit nodes for password spraying, credential stuffing, advertising fraud, and unauthorized sensitive data scraping.
There is an additional risk that Google highlighted and that is often overlooked: when a household device becomes a proxy exit node, the unauthorized traffic passing through it can reach other private devices on the same local network. The compromised television not only lends its IP — it opens a door to the rest of the home.
Benjamin Brundage, founder of Synthient — one of the firms that published the evidence — confirmed that the domain seizures disrupted both the Popa botnet and the proxy network that operated on top of it.
Alarum Technologies' position was one of partial rejection. Through its legal counsel, Omer Weiss, the company stated it would cooperate with authorities, but in a statement issued prior to the seizure had denied the "botnet" characterization, describing the SDKs as "bandwidth-sharing functionality that does not transform users' devices into malware-controlled systems." The GTIG and independent research firms maintain the opposite interpretation.
3. The Operational Impact on Legitimate Customers
What makes this case relevant for the industry is not only the criminal dimension, but the collateral impact on thousands of teams that used NetNut for entirely legitimate operations: price monitoring, competitive intelligence, and public data extraction.
For those users, the consequences were immediate:
Complete pipeline disruption. Overnight, scrapers lost access to residential exit nodes. Integrations stopped working without prior notice.
Loss of committed capital. Prepaid balances and active contracts were frozen or lost as a direct result of the judicial actions.
Indirect reputational and legal exposure. The traffic of legitimate companies became involuntarily associated with an infrastructure under federal investigation. This generated audit risk and mass blocks on target platforms that detected IP patterns linked to the case.
The Whitelabel Problem: You May Have Been Using It Without Knowing
Here is the point that turns this case into an industry-wide problem and not just a NetNut customer problem. In its report, the GTIG was explicit:
"Google has high confidence that many popular residential proxy brands are in fact reselling the NetNut botnet under white label."
Translated: the name on your invoice does not tell you where your IPs come from. An intermediary provider can purchase capacity from NetNut, rebrand it, and sell you a service with a dashboard, support, and impeccable documentation — built on hacked televisions. And Google warns that the cycle repeats: when a network loses its botnet, its operators buy capacity from competitors and become resellers, so the contaminated infrastructure is redistributed rather than eliminated.
The risk of using proxy infrastructure without verifying its origin is not merely ethical. It is a concrete operational risk that can interrupt critical data services with no possibility of rapid recovery.
4. Industry Context: NetNut Is Not an Isolated Case
The dismantling follows a pattern that is repeating with increasing frequency. In early 2026, legal actions driven by Google led to the seizure of IPIDEA's infrastructure, NetNut's largest competitor. Before that, the BadBox 2.0 operation had already demonstrated that botnets built on mass-market consumer devices represent a systemic risk vector.
The communicating vessels effect is evident: according to Brundage, NetNut gained popularity precisely after the IPIDEA takedown. Each takedown redistributes demand toward the next provider on the list, without resolving the underlying problem.
What these operations have in common is their objective: not scraping itself, but the illicit infrastructure that some providers use to sustain their residential IP networks. The distinction matters.
The scraping of publicly available data has growing legal backing. The Ninth Circuit ruling in hiQ Labs vs. LinkedIn (2022) established that automated access to publicly accessible data does not violate the Computer Fraud and Abuse Act (CFAA). What authorities are pursuing is not the extraction of public data, but the illegal method of obtaining the residential IPs that make it possible at scale.
If you want to examine exactly where the legal line falls, we cover it in detail in what is legal and what can lead to a lawsuit in web scraping.
5. The Question Every Company Should Be Asking
The NetNut case forces a question that many data teams have so far avoided: where exactly do the IPs my provider offers me come from?
Legitimate residential proxy networks obtain their IPs through one of three methods: direct agreements with ISPs, bandwidth-sharing programs with explicit and revocable user consent, or data center infrastructure. The difference between these models and the Popa model — which recruited consumer devices without clear disclosure — is not a minor technical detail. It is the line between a sustainable operation and one that can disappear overnight by court order.
Checklist: 5 Questions to Audit Your Proxy Provider
Send these to your current provider in writing. The answers — and especially the evasions — will tell you almost everything.
1. IP origin and consent
Question: Where exactly do your residential IPs come from, and what consent mechanism did the device owner accept? Can they revoke it, and how?
Red flag: answers that talk about "bandwidth sharing" without explaining how that consent is obtained, documented, and revoked.
2. Supply chain and whitelabel
Question: Do you operate your own network, or do you resell third-party capacity? If you resell, from whom, and under what audit?
Red flag: the question causes discomfort or is answered with generalities. After the NetNut case, this is the most important question on the list.
3. Documented regulatory compliance
Question: What documentation do you have on GDPR, CCPA, and applicable privacy regulations? Are there independent audits or verifiable certifications?
Red flag: generic mentions of "compliance" without documents, certificates, or an identifiable auditor.
4. KYC policies
Question: What Know Your Customer controls do you apply to prevent your infrastructure from being used for malicious purposes?
Red flag: anonymous registration, cryptocurrency-only payment, absence of customer verification. If anyone can buy, anyone does.
5. Track record and traceability
Question: Have you appeared in cybersecurity firm reports or prior investigations? What rate limiting mechanisms do you apply to avoid overloading target sites?
Red flag: unexplained appearances in reports from Spur, Synthient, or Google's GTIG. Verify it yourself before asking.
6. What to Do if You Were Using NetNut (or Think You Might Have Been)
Three paths, ordered from least to most structural change.
Option A — Audit and Stay
If your provider passes the checklist with real documentation, don't touch anything. Migrating has its own cost and risk. Document the audit in writing and repeat it every six months: the ecosystem is fluid and a clean provider today may be reselling contaminated capacity within a quarter.
Option B — Migrate to a Provider with Verified Origin
If the answers don't hold up, migrate. When evaluating candidates, prioritize IP origin traceability over price per gigabyte: in this market, a price well below average usually indicates that someone is not paying for their IPs. We cover the evaluation criteria in how to choose the right web scraping provider.
Keep in mind the rebound effect Google warns about: after a takedown, operators buy capacity from competitors. Verifying at the moment of contracting is not enough.
Option C — Outsource the Entire Pipeline
If proxy infrastructure management is not your competitive advantage, the reasonable question is why you are assuming it. Outsourcing transfers the continuity and compliance risk to whoever holds it as a primary responsibility.
In Any of the Three Cases
Review your retry and failover architecture. The NetNut failure showed that many pipelines had no plan B: the provider went down and everything went down. A design with a secondary provider and controlled degradation turns a critical interruption into a minor inconvenience. We write about this in how to resolve blocks with IP rotation.
7. What This Means for Scraping as a Professional Practice
The shutdown of NetNut is not the end of data extraction. It is confirmation that the infrastructure on which it operates matters as much as the practice itself.
Companies that extract public data in a structured manner, respecting
robots.txt files, the terms of service of target sites, and applicable privacy regulations, operate within a legal framework that is increasingly well-defined and protected. What this case closes is the space for those who sought shortcuts at the infrastructure layer. If you want the full legal framework, we cover it in how to avoid legal and compliance issues in web scraping.
At AUTOScraping, we work exclusively with infrastructure of verified origin, including our status as a Bright Data Solution Partner — one of the few proxy networks to have won specific litigation over access to public data and that operates under documented compliance standards. Every pipeline we build is designed to be operationally stable and legally sustainable over the long term, not to maximize volume at any cost.
The NetNut case, in that sense, does not change what we do. It confirms why we do it this way.
Want a review of the data origin in your current pipeline? Let's talk — or learn how Data Factory works.
Frequently Asked Questions
Did NetNut shut down permanently?
Its infrastructure was seized by the FBI on July 2, 2026 and its main domains redirect to US government servers. Alarum Technologies stated it is cooperating with the investigation but has not announced any resumption of service. In practice, the service stopped operating.
What is the Popa botnet?
It is the network of at least two million compromised household devices — primarily Smart TVs and Android streaming boxes — that fed NetNut's residential IPs. Devices were infected via hidden SDKs in applications, without clear notice or genuine consent from the device owner.
Is using residential proxies illegal?
No. What is illegal is how some providers obtain the IPs. A network that acquires them through ISP agreements or explicit, revocable user consent operates within the law. The crime lies in recruiting third-party devices without disclosure, not in using a proxy.
How do I know if my Smart TV is part of a proxy botnet?
Synthient maintains a page that indicates whether your public IP appears in its proxy node records. The FBI also published a guide to prevent household devices from becoming tools for third parties. As a general rule: use recognized brands with certified Android TV and be very selective about the apps you install.
How do I know if my proxy provider was reselling NetNut?
Ask them in writing. Google indicated that many well-known brands were reselling NetNut under white label, so the brand on your invoice guarantees nothing. If your service experienced degradation or outages during the first week of July 2026, that is a strong indicator.
What happens to the prepaid balance I had with NetNut?
Funds and active contracts were frozen by the judicial actions. Recovery depends on the ongoing legal process and there is no foreseeable timeline. This is a practical argument for avoiding concentrating prepaid balances with a single provider.
Does this affect my web scraping projects?
Only if they depended on contaminated infrastructure. Extracting public data remains legal and is backed by case law such as hiQ vs. LinkedIn. What this case calls into question is the infrastructure layer, not the practice itself.
Sources
- KrebsOnSecurity. FBI Seizes NetNut Proxy Platform, Popa Botnet. July 2, 2026. https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/
- KrebsOnSecurity. Popa Botnet Linked to Publicly-Traded Israeli Firm. June 18, 2026. https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/
- Google Threat Intelligence Group. Google Continued Disruption of Residential Proxy Networks. July 2, 2026. https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks
- Synthient. Popa: From Sourcing to Distribution. June 2026. https://synthient.com/blog/popa-from-sourcing-to-distribution
- Spur. Smart TV Apps and Residential Proxy SDKs. June 2026. https://spur.us/blog/smart-tv-apps-residential-proxy-sdks
- Infosecurity Magazine. FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors. July 3, 2026. https://www.infosecurity-magazine.com/news/fbi-google-take-down-netnut-proxy/
- GovInfoSecurity. FBI Disrupts Widely Used NetNut Residential Proxy Service. July 3, 2026. https://www.govinfosecurity.com/fbi-disrupts-widely-used-netnut-residential-proxy-service-a-32154
- FBI. Evading Residential Proxy Networks: Protecting Your Devices. 2026. https://www.fbi.gov/investigate/cyber/alerts/2026/evading-residential-proxy-networks-protecting-your-devices-from-becoming-a-tool-for-criminals
- TechSpot. The FBI and Google just took down a botnet that hijacked 2 million smart TVs. July 2026. https://www.techspot.com/news/113021-fbi-google-took-down-botnet-hijacked-2-million.html




