Back to blog

Blog Post

Dutch Police Dismantle “Bulletproof” Hosting Provider

Share on social

Feb 20, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Dutch Police Dismantle “Bulletproof” Hosting Provider

[Bulletproof Hosting Takedown]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Following an investigation that lasted over a year, Dutch police have dismantled a “bulletproof” hosting provider. During the raid, 127 servers from ZServers/XHost were seized by law enforcement.

According to the Dutch National Police, the ZServers/XHost stood out because they were advertising that cybercriminals were welcome to exploit illicit activities from its servers, and promised the servers would remain anonymous to law enforcement agencies.

Hosting companies of this kind are referred to as “bulletproof” hosters. They provide hosting services to cybercriminals promising to protect users from law enforcement agencies, helping them remain anonymous on the internet. This allows criminals to host and distribute ransomware and host illicit materials without fear of server shutdown.

Dutch police raided the company on February 12th with the investigation revealing that the servers contained ransomware, botnets, and other malicious software, including tools from Conti and LockBit.

Law enforcement emphasized the dangers of bulletproof hosters. "A bulletproof hoster is not just any shadowy company that ignores rules; it is the backbone of global cybercrime. Without these 'safe havens,' many criminals would have nowhere to host their hacking tools, stolen data, and fake websites. Cybercriminals from all over the world pay a lot of money to have their illegal operations run here undisturbed. Bulletproof hosters ensure that malicious individuals can continue to hack, scam, and blackmail with impunity, and others pay the price for that." the police said in a statement.

While no suspects have been arrested to date, websites hosted on the seized servers have been made inaccessible. In accordance with the Public Prosecution Service, the Cybercrime Team of the Amsterdam police will continue to investigate the data found on the seized servers.

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient