Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Netherlands seizes servers in massive crackdown on Russian‑linked cyberhost

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-06-07 T 08:55:57 Z | [ 2 MIN READ ]
Netherlands seizes servers in massive crackdown on Russian‑linked cyberhost
2 Min Read
Share

Netherlands seizes servers amid EU sanctions breach

In a coordinated raid on May 18, Dutch financial‑crime investigators confiscated ↓ 800 servers and detained two men accused of funneling resources to a sanctioned Russian hosting network. The operation, described by Reuters, targets the infrastructure that powered DDoS assaults and disinformation campaigns across the European Union.

Arrests of two operators

Andrey Nesterenko, a 39‑year‑old Russian national, and Youssef Zinad, 57, were taken into custody after raids on facilities in Enschede, Almere, Dronten and Schiphol‑Rijk. Authorities seized laptops, phones and ↓ 2 additional pieces of equipment linked to the illicit network.

“The seizure disrupts a key conduit for hostile cyber activity,” said a spokesperson for the Tax Intelligence and Investigation Service (FIOD).

The seized hardware belonged to MIRhosting, a Dutch‑registered ISP that supplied connectivity to WorkTitans BV, the entity that inherited assets from the previously sanctioned PQHosting. WorkTitans and MIRhosting were identified as primary channels for Russian‑aligned attacks on Danish government sites during the November 2025 municipal elections.

Both Nesterenko and Zinad deny wrongdoing. Nesterenko, a former piano prodigy from Nizhny Novgorod, argues the transfer to the.hosting pre‑dated the EU sanctions and that shutting down a legitimate Dutch firm will only hurt innocent clients. Bloomberg notes that the broader strategy of sanction evasion remains a persistent challenge for European regulators.

In a statement, MIRhosting claimed an internal review found no evidence of involvement in the Danish election interference, noting that network traffic showed no spikes indicative of large‑scale DDoS activity. The firm has temporarily paused services to WorkTitans while the investigation proceeds.

The case echoes earlier findings that cyber‑crime infrastructure can adapt quickly to regulatory pressure, a pattern also observed during the recent pandemic where threat actors leveraged disrupted supply chains for malicious gain.


Words by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026
Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.