The FBI seized NetNut, and the internet has not caught up
Proxy Compare fetched netnut.io on 8 Aug 2026 and recorded the seizure banner on every path, then checked what Google's AI Overview was still saying about the platform the same day. Re-run 27 Aug 2026: five paths including a nonexistent one all returned the banner.
8 Aug 2026 · updated 27 Aug 2026 · 4 min read
Point in time. The figures below were read on 8 Aug 2026 and are not updated after publication. For current numbers see the comparison table.

On 2 July 2026 the FBI seized NetNut. We fetched netnut.io on 8 August and the
seizure notice was still there, byte-identical on every path we tried, the
pricing page, the terms, the product pages. Seals from the FBI, the Department of
Justice and IRS Criminal Investigation.
Re-run on 27 August, and it still is. Every path returns the same page, including one that never existed:
$ for p in "" pricing/ terms-of-use/ residential-proxy/ nonexistent-page-xyz/; do
curl -s "https://netnut.io/$p" | shasum -a 256 | cut -c1-16
done
c91d29b826aabd52
c91d29b826aabd52
c91d29b826aabd52
c91d29b826aabd52
c91d29b826aabd52
All five answer HTTP 200. A seized domain does not 404 the pages it used to serve, it replaces the whole site with one document, which is why a link to a NetNut product page still looks alive to anything that only checks status codes.
The notice is worth reading closely, because of who it names:
This domain has been seized by the Federal Bureau of Investigation in accordance with federal law as part of a law enforcement action, taken in coordination with the Department of Justice and the Internal Revenue Service Criminal Investigation, against the NetNut residential proxy platform, its administrators, and its subscribers.
Not just the operators. The customers.
What the network actually was
NetNut was operated by Alarum Technologies, a publicly traded company. Reporting by Krebs on Security ties the platform to a botnet of at least two million consumer devices, the kind found in ordinary homes, smart TVs and streaming boxes, compromised by malicious software with little or no consent from their owners. Google's Threat Intelligence Group counted 316 distinct clusters of threat actors using suspected NetNut exit nodes in a single week during June 2026, cybercriminal and espionage groups among them.
That is the uncomfortable centre of this market. When a provider sells "residential" addresses, those addresses belong to somebody's home connection, and the question of how they agreed to that ranges from "an app that pays them" to "a checkbox in the terms of a free game" to, here, an answer a federal investigation found worth acting on.
The part that should change how you buy
NetNut's network was widely resold and white-labelled. A storefront with its own brand, its own pricing page and its own support desk may have been selling you the same exit nodes.
Establishing whether that touched you is a smaller job than it sounds, and it gets harder the longer you leave it. Three facts are worth writing down now: which supplier you actually paid, which hostname your code resolved when it connected, and the dates your traffic was moving through it. A reseller can put its own brand on a dashboard, but it is far less able to hide an upstream in the endpoint it hands you. If you resold that traffic on to anyone else, your own customers need those same three facts from you, and they need them from you rather than from a notice on a seized domain.
This is why we do not treat sourcing as a property of the vendor you are looking at. Every provider we track carries a "where the addresses come from" line, and where a provider does not publish it, the page says exactly that. They do not say is a finding, and it is the answer for most of the roster, not a fringe of it. The sourcing hub carries the current count, because that number moves as providers are added and a figure typed into a paragraph does not.
What the internet still says
On 8 August, five weeks after the seizure, we asked Google two queries:
bright data alternatives and oxylabs alternatives. Its AI Overview
recommended NetNut in its own generated prose on both.
On bright data alternatives:
NetNut: Great for high-volume operations requiring fast single-hop connectivity and sticky sessions via direct ISP connections.
On oxylabs alternatives:
NetNut: Uses a unique peer-to-peer and B2B hybrid network that provides fast connection speeds and high reliability for enterprise-level web scraping.
Both were verified as generated body text rather than copy lifted from a source card, using a two-stage capture that reads the overview before and after expanding its sources. On the same day, on two different queries, the same AI Overview correctly cited the FBI's own advisory about residential proxy networks.
It holds both facts. It connects neither.
We are not pointing at that to score a point about AI. It is the clearest illustration we have of why a price or a recommendation without a date attached is worth very little in this market. A summary restates what it learned. It cannot tell you what changed five weeks ago, and this market changes constantly providers reprice, restrict targets, get acquired, and occasionally get seized.
Every number on the table renders with the date we read it, and how we check explains where each one came from. That is not a flourish. It is the whole difference between our answer and the one that was at the top of the page when we looked.
Sources
- Seized by the Federal Bureau of Investigation netnut.io (seizure notice), read 8 Aug 2026
This domain has been seized by the Federal Bureau of Investigation in accordance with federal law as part of a law enforcement action, taken in coordination with the Department of Justice and the Internal Revenue Service Criminal Investigation, against the NetNut residential proxy platform, its administrators, and its subscribers.
- FBI Seizes NetNut Proxy Platform, Popa Botnet Krebs on Security, read 8 Aug 2026
the FBI seized hundreds of domains tied to NetNut, a residential proxy service run by publicly traded Israeli company Alarum Technologies
- FBI Seizes NetNut Proxy Platform, Popa Botnet (botnet size and consent) Krebs on Security, read 25 Aug 2026
a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims
- FBI Seizes NetNut Proxy Platform, Popa Botnet (threat-actor clusters) Krebs on Security, citing Google Threat Intelligence Group, read 25 Aug 2026
in a single week during June 2026, they observed 316 distinct clusters of threat actors using suspected NetNut exit nodes, including cybercriminal and espionage groups
Questions
Is NetNut shut down?
Yes. netnut.io has served an FBI seizure notice on every path since 2 July 2026, and we confirmed it again on 8 August. The notice names the platform, its administrators and its subscribers.
I bought proxies from NetNut. What should I do?
We are not lawyers and this is not legal advice. What we can tell you factually: the seizure notice explicitly names subscribers, and partner organisations separately disrupted infrastructure used by the platform and its subscribers. If you resold or built on that network, the first practical step is establishing which of your upstream suppliers were routing through it.
Which other providers were affected?
NetNut's network was widely resold and white-labelled, so a provider with its own branding may have been reselling it. We record an upstream supplier where we can establish one, and mark it unknown where we cannot, unknown is not the same as none.
