Summary
Dutch financial crime investigators (FIOD) have arrested two men and seized over 800 servers linked to hosting infrastructure used by Russia to conduct cyberattacks, influence operations, and disinformation campaigns against EU targets. The arrests on May 18 targeted Andrey Nesterenko (39, Russian-born, based in The Hague) and Youssef Zinad (57, Amsterdam), co-operators of hosting companies that provided connectivity to Stark Industries Solutions — an ISP sanctioned by the EU as a staging ground for Russian intelligence cyber operations.
Stark Industries materialized just two weeks before Russia’s invasion of Ukraine and quickly became a source of massive DDoS attacks against European targets. After the EU sanctioned Stark’s Moldovan partners (PQHosting and the Neculiti brothers) in May 2025, the network’s assets were transferred to a new Dutch entity called WorkTitans BV, controlled by Nesterenko and Zinad, maintaining connectivity through Nesterenko’s MIRhosting.
Data reviewed by de Volkskrant showed that WorkTitans and MIRhosting were the most-used networks in pro-Russian attacks on Danish government bodies during Denmark’s November 2025 municipal elections. Customers of “the.hosting” received messages stating that data stored on seized servers “has been lost and cannot be recovered.”
Source
📰 Krebs on Security — Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
📰 Help Net Security — Dutch Seize 800 Servers
Commentary
This is a significant law enforcement win, but the backstory reveals how frustratingly slow the response has been. Krebs on Security first reported on Stark Industries’ role in Russian cyber operations back in May 2024 — a full two years ago. When EU sanctions finally came in 2025, the operators simply shuffled assets to a new Dutch entity and kept going. It took another year and direct evidence of election interference before authorities acted.
The seizure of 800 servers is substantial, but bulletproof hosting is a hydra problem. The real question is whether the intelligence gathered from these servers — laptops, phones, and server data — will lead to meaningful disruption of the Russian cyber operations that relied on this infrastructure. The timing, just days after the Megalodon supply chain attack, underscores that the internet’s infrastructure layer remains dangerously underregulated.
