Skip to content
News

NetNut Shutdown Explained (2026)

NetNut's residential proxy network was disrupted by Google and the FBI over ties to the Popa botnet. Here's what happened and how to migrate safely.

David Razvan
September 4, 2026 3 min read
NetNut Shutdown Explained
Click Here to Add Proxyon as a Trusted Source Add as a preferred source

Don't want to read?

Time is a precious resource, get the insights you need using your favorite AI chat.

TL;DR

Google, the FBI, and the IRS Criminal Investigation division disrupted NetNut's residential proxy network on July 2, 2026, tying it to a two-million-device botnet. Here is what is confirmed and what to do if you were a customer.


NetNut

Reuters reported that Google's Threat Intelligence Group disabled accounts and services tied to NetNut-related malware operations and shared technical intelligence with law enforcement. The FBI seized hundreds of domains tied to the network and swapped in seizure banners.

The keyword here is disruption, not shutdown. Google's own language describes this as a significant degradation of NetNut's capacity, not a full takedown. NetNut's parent, Nasdaq-listed Alarum Technologies, confirmed the domain seizures and said it is cooperating with law enforcement while disputing the underlying allegations.

The action traces back to June 19, 2026, when researchers linked NetNut's infrastructure to a botnet tracked as Popa, built on roughly two million devices, mostly smart TVs, streaming boxes, and Android phones enrolled without clear consent.

If you're weighing a move, residential proxies sourced with clear consent are the baseline to check for, not an afterthought.


The Reseller Risk Most Buyers Miss

The Reseller Risk Most Buyers Miss

NetNut ran a reseller program, and Google said it holds high confidence that a number of residential proxy brands were whitelabeling NetNut's infrastructure under their own name. Checking your own contract isn't enough. If your provider blends in whitelabeled supply, you can inherit the same sourcing problem without ever signing up with NetNut directly. The Hacker News and KrebsOnSecurity both traced Popa's infrastructure across multiple commercial brands, not one storefront.

Also Read: How to Do Web Scraping Without Getting Blocked


What to Do?

What to Do If You Were a Customer

Don't pick a replacement on price or pool size alone. Ask exactly how a provider sources its IPs, whether device owners opted in, and whether the pool is resold from somewhere else.

Then migrate in stages: point one workflow at the new provider, compare success rate and retry rate against your old setup, and only scale over once the numbers hold. If you're comparing datacenter proxies as a stopgap while you vet a new residential source, keep in mind they solve availability, not sourcing risk.

Rotate old credentials and remove stale allowlist entries once you cut over. The metric that matters here isn't price per GB, it's cost per successful, compliant request.


FAQ Section

FAQ Section

Did NetNut shut down?

Not officially. Public reporting points to a major disruption, not a confirmed permanent closure. Alarum says it is cooperating with the investigation.

Why was NetNut targeted?

Google and the FBI linked its residential proxy network to the Popa botnet, alleging it was used for malware command-and-control, password-spraying attacks, and other abuse.

Are residential proxies illegal?

No. The problem isn't the proxy type, it's how the IPs are sourced. Consent-based, transparent networks are a different category from device pools enrolled without disclosure.

Should I stop using NetNut immediately?

Treat it as an active outage and compliance risk. Start migrating workflows now rather than waiting for a hard failure.


Final Thoughts

NetNut's disruption is a reminder that residential IP sourcing isn't a detail to skip past. Google and the FBI have degraded the network, not confirmed its shutdown, so treat any pipeline still pointed at NetNut as an active risk.

Get back to building.

We'll handle the proxies.