NetNut Domains Seized by the FBI - The Full Story, Timeline and Safe Alternatives (2026)

By Marcus Reiner · 2026-07-25 · 16 min read · News

#netnut down#netnut shut down#is netnut safe#netnut fbi#netnut alternative#netnut seized#netnut 2026#proxy botnet

The FBI seized NetNut's domains in July 2026 following a Google-led investigation into a botnet built from hijacked consumer devices. Here is exactly what happened, what Alarum Technologies has said publicly, and what to use instead.

EDITOR'S TOP PICK
Decodo
Smartproxy reborn — affordable premium proxies
From $2/GB · 4.7/5 stars · Trust Score 94/100
Visit Decodo → Read full review

What happened to NetNut

On July 2, 2026, Alarum Technologies Ltd (Nasdaq: ALAR, TASE: ALAR) and its subsidiary NetNut Ltd were informed that the FBI had seized certain domains associated with NetNut's residential proxy network. The seizure was carried out by the FBI in coordination with the Department of Justice and the Internal Revenue Service Criminal Investigation division, targeting the NetNut residential proxy platform, its administrators and its subscribers.

Visiting netnut.com now shows an official seizure notice bearing the seals of the IRS Criminal Investigation division, the Department of Justice, the FBI, and acknowledging assistance from Google, Lumen's Black Lotus Labs, and the Shadowserver Foundation. The notice states that Google, Lumen and Shadowserver, with assistance from their partners, disrupted other domains and infrastructure used by the NetNut platform and its subscribers in separate and independent civil and terms-of-service actions.

Google's Threat Intelligence Group led the investigation that triggered the action. Google's researchers tied NetNut's residential exit-node pool to a botnet the company internally refers to as 'Popa' - infrastructure built from more than two million hijacked consumer devices, including Android phones, tablets and streaming boxes, enrolled into the proxy network without their owners' knowledge or consent.

Timeline - what Alarum has said, and when

July 2, 2026: Alarum Technologies disclosed that it and NetNut had been made aware of the domain seizure. The company issued a public statement pledging to fully cooperate with law enforcement to investigate any misuse of its infrastructure and to hold those responsible to account.

July 3, 2026: Alarum issued a follow-up update disclosing that the disruption was affecting a portion of its network services and warning that a prolonged outage could have a material adverse effect on its operations, financial results and ability to serve customers. As of this update, the company stated that neither Alarum nor NetNut had been formally contacted by the FBI or any other governmental authority regarding the seizure. Alarum said it was devoting substantial technical and operational resources to investigating the incident and expected the traffic pause on affected services to last several days.

July 4, 2026: A further update confirmed additional NetNut-associated domains had been seized, expanding the scope of the disruption beyond the initial July 2 action. Alarum filed these updates with the SEC as Form 6-K current reports, standard disclosure for a foreign private issuer reporting material events to investors.

As of this writing, Alarum's public position remains that it is investigating whether its infrastructure was misused for malicious or unlawful purposes by third parties, and that it has not been formally contacted by law enforcement with specific charges or findings.

The botnet allegation, in plain terms

Google's Threat Intelligence Group publicly ties NetNut's residential IP pool to a botnet built from over two million compromised consumer devices. This is functionally similar to the BadBox 2.0 and Aisuru botnets that led to the shutdown of 922Proxy, LunaProxy and eleven other IPIDEA-linked brands earlier in 2026 - a pattern where a residential proxy network's IP pool is sourced, at least in part, from devices that were never knowingly opted in by their owners.

This is a serious allegation because it directly contradicts how NetNut has historically marketed itself. NetNut's own positioning emphasized that it sources residential IPs through direct ISP partnerships rather than a peer-to-peer SDK model - the opposite of the botnet-style sourcing that Google's investigation describes. If accurate, this would mean the core sourcing claim NetNut built its reputation on was not the whole picture.

It is worth being precise about what is confirmed versus alleged. Confirmed: the FBI seized NetNut-associated domains, with DOJ, IRS-CI, Google, Lumen and Shadowserver named on the seizure notice. Confirmed: Alarum has publicly acknowledged the seizure and is investigating internally. Not yet independently confirmed in a court filing or formal charge as of this writing: the specific mechanics or scale of the alleged misuse, since neither company has released a full technical accounting and Alarum states it has not yet been formally contacted by authorities with details.

What this means if you are a NetNut customer

If you have an active NetNut subscription, several of the domains you would normally use to manage your account or route proxy traffic through may currently be inaccessible or redirected to the seizure notice. Alarum's own guidance as of early July was that the disruption could last several days, though the company has not published a firm restoration timeline as of this writing.

Do not send any new payments to NetNut until the situation is publicly resolved. If you have an active subscription and are billed on a recurring basis, check your payment method for pending charges and consider pausing or cancelling auto-renewal until there is clarity on whether the service will resume normal operations.

If you need residential, ISP, datacenter or mobile proxies right now for active work, treat this as the moment to migrate rather than wait. The safest path is a provider with a transparent, auditable IP-sourcing process and an active KYC program - not simply a service that resumes access first.

How to evaluate whether any proxy provider is safe

Four checks worth running on any provider before trusting them with your traffic or payment details, whether you're evaluating a NetNut replacement or any other proxy purchase. First, KYC process: legitimate providers verify who their customers are. If you can buy bandwidth with no identity verification and a throwaway email, treat that as a red flag.

Second, IP sourcing transparency: ask directly how residential IPs are sourced and what device owners are told when they opt in. Providers like Bright Data, Decodo and IPRoyal publish this information; if a provider cannot answer clearly, that is itself an answer.

Third, corporate transparency: check who actually runs the company. A named leadership team, a real headquarters, and a public legal entity registered somewhere with actual regulatory oversight are basic signals. Alarum Technologies, despite the current situation, is a publicly traded company (Nasdaq: ALAR) with SEC disclosure obligations - which is precisely why this incident became public and documented in the way it did, rather than the company simply vanishing.

Fourth, check independent evaluation. Every provider on ToptierProxy.com carries a Trust Score built from 225+ criteria including sourcing ethics, compliance certifications and corporate transparency. We are actively re-evaluating NetNut's listing in light of these events.

Safe NetNut alternatives in 2026

1. Decodo - Best overall replacement for speed-sensitive work. 115M+ residential IPs at $2/GB with a Site Unblocker that automatically handles Cloudflare and DataDome. Decodo has won Proxyway's Best Value Provider award three years running and publishes clear sourcing documentation.

2. Bright Data - Best for enterprise and compliance-sensitive teams. 400M+ IPs across 195 countries, SOC 2 Type II and ISO 27001 certified, with a strict KYC compliance program and a decade-plus track record serving over 20,000 organizations.

3. Oxylabs - Best for large-scale scraper API needs. 175M+ IPs, ranked near the top for performance in the independent Proxyway 2025 Proxy Market Research report, with a published KYC policy and Trust Center.

4. IPRoyal - Best budget-friendly replacement. Pay-as-you-go from $1.75/GB with no expiry on bandwidth, ethically sourced through a consenting peer network.

5. Webshare - Best free-tier option to test before committing. A permanent free tier (10 datacenter IPs, 1GB residential bandwidth monthly) with no credit card required, useful for evaluating a new provider risk-free while you plan a full migration.

Quick Comparison Top Providers
1
Bright Data
From $8/GB · 4.9/5
2
Oxylabs
From $8/GB · 4.8/5
3
Decodo
From $2/GB · 4.7/5
Compare all providers side by side →
EDITOR'S TOP PICK
Decodo
Smartproxy reborn — affordable premium proxies
From $2/GB · 4.7/5 stars · Trust Score 94/100
Visit Decodo → Read full review

Frequently Asked Questions

Is NetNut shut down permanently?

As of this writing, NetNut's domains have been seized by the FBI and the service is disrupted, but Alarum Technologies has not stated the company is shutting down permanently. Alarum is publicly traded and has committed to cooperating with law enforcement while investigating internally. We will update this article as the situation develops.

Why did the FBI seize NetNut's domains?

The seizure notice, issued jointly by the FBI, DOJ and IRS Criminal Investigation, states the action targeted the NetNut residential proxy platform, its administrators and its subscribers. Google's Threat Intelligence Group ties NetNut's residential IP pool to a botnet built from over two million hijacked consumer devices enrolled without owner consent.

Is it safe to keep using NetNut right now?

We do not recommend sending new payments to NetNut or relying on it for active work until the situation is publicly resolved with clarity from Alarum or law enforcement. If you have an existing subscription, consider migrating to an alternative provider for time-sensitive work.

What is the best NetNut alternative?

Decodo is the closest match for speed-sensitive workloads at $2/GB with 115M+ IPs. Bright Data is the best choice for enterprise compliance needs. IPRoyal is the best budget option at $1.75/GB. Full comparison above.

Is Alarum Technologies (NetNut's parent company) shutting down?

No. Alarum Technologies is a Nasdaq and Tel Aviv Stock Exchange listed public company (ALAR) with ongoing SEC disclosure obligations. As of its most recent public statements, Alarum said it had not been formally contacted by the FBI with specific findings and is conducting its own internal investigation while cooperating with authorities.

Can I get a refund from NetNut?

NetNut has not published a public refund policy in response to this incident as of this writing. If you have an active subscription and are concerned about billing, contact your payment provider directly and consider a chargeback if you believe you are not receiving the service you paid for, documenting your account status and any communication with NetNut first.

Related Resources on ToptierProxy