Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
2026-05-31T13:23:27Z•e7738a92c84fe034a56f6eab881b0a35578548a3beac8911b08818c21dbde9d3
AWSCISACanvasDDoSGitHubGovCloudIoT-botnetKimwolfRussiaanti-ddos-abusearrestsbotnetcongressional-inquirycredential-exposurecybercrimedata-extortiondata-leakeducation-sectorhosting-abuseincident-responseinfluence-operationslaw-enforcementserver-seizurestate-sponsoredsupply-chain-security','vulnerabilities','zero-day','SharePoint-
What happened
A cluster of high-impact cyber incidents reported by KrebsOnSecurity in spring 2026: Dutch authorities seized ~800 servers and arrested two co-owners of hosting firms accused of providing infrastructure for Russian cyberattacks, influence and disinformation operations (including takeover of a sanctioned ISP). A CISA contractor publicly exposed AWS GovCloud credentials and internal build/deploy materials on GitHub, prompting congressional inquiries and active credential containment. Canadian and U.S. authorities arrested and charged an alleged Kimwolf IoT botnet operator after massive DDoS, dox
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- e7738a92c84fe034a56f6eab881b0a35578548a3beac8911b08818c21dbde9d3
- Enrichment time
- 2026-05-31T13:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.