Netherlands Seizes 800 Servers of Hosting Firm That Enabled Pro-Russian Cyberattacks and Disinformation
On May 18, FIOD arrested Youssef Z., 57, of Amsterdam, and Andrey N., 39, of Den Haag, on suspicion of violating EU sanctions by indirectly supplying economic resources to sanctioned Russian and Belarusian entities
The WorkTitans seizure documents a post-sanctioning infrastructure-laundering playbook: sanctioned entities transfer servers to shell companies before enforcement catches up, sustaining cyber capacity under legal cover. Stark Industries completed that transfer within weeks of its May 2025 EU listing, and WorkTitans infrastructure appeared atop Danish authorities' list of networks used in November 2025 election-day attacks; bureaucratic lag in tracing successor entities carries electoral-interference costs. Physical seizure of 800 servers forces reconstitution through new proxies. MIRhosting's claim as a neutral provider could complicate the connectivity count against Andrey N. Charging sanctions evasion rather than awaiting cybercrime attribution creates a lower evidentiary threshold other EU states could adopt. Sourcing rests on the FIOD press release; secondary outlets amplify but add no independent reporting.
4 sources
- FIOD houdt twee verdachten aan wegens overtreding sanctiewetgeving -
FIOD (Dutch Fiscal Information and Investigation Service) - Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions -
NL Times - Netherlands seizes 800 servers of hosting firm enabling cyberattacks -
BleepingComputer - Twee mannen opgepakt op verdenking van faciliteren Russische cyberaanvallen -
NOS