FBI Seizes NetNut & Popa Botnet: What SMBs Must Know

The FBI's seizure of the NetNut proxy platform and the Popa botnet in July 2026 is the kind of enforcement action that makes headlines for a day, then gets forgotten. That would be a mistake. For small and medium-sized businesses, this proxy network seizure is a signal worth paying attention to — because the infrastructure that was just dismantled existed specifically to hide the people stealing from businesses like yours.

What NetNut and the Popa Botnet Actually Were

To understand why this matters, it helps to know what these operations did. The Popa botnet was a network of compromised devices — think routers, home computers, and business endpoints — infected with malware and quietly recruited into a vast relay system. NetNut was a proxy platform that allowed paying customers to route their internet traffic through these infected devices, masking their real location and identity.

In plain terms: criminals paid to borrow the internet connection of someone's hacked home router or office computer. This let them log into stolen accounts, scrape credential databases, and conduct fraud without their real IP address ever appearing in the logs. The infected devices were often those of ordinary people and small business employees who had no idea their connection was being rented out to bad actors.

Why Proxy Networks Are a Threat to Business Credentials

Here is where this becomes directly relevant to your business. Proxy networks like NetNut are a favourite tool for credential stuffing — an attack where criminals take username and password combinations leaked in past data breaches and try them across hundreds of websites and business tools. Because the login attempts come from thousands of different IP addresses, automated security systems often miss them.

If any of your employees reuse passwords across personal and work accounts — and statistically, many do — their credentials may already be circulating in infostealer dumps and dark web markets. A proxy network is what makes exploiting those credentials at scale not just possible, but easy and cheap. The Popa botnet lowered the barrier for anyone willing to pay for access.

The seizure removes one major piece of that infrastructure, but it does not remove the stolen data. Credential dumps sold or shared before the takedown still exist. The buyers and users of NetNut's services still exist. Enforcement actions are meaningful, but they are not a reset button on exposure that has already happened.

What the Timing Tells Us About Your Risk Window

Law enforcement operations like this take months or years to build. The FBI was watching, gathering evidence, and working with international partners long before the domains were seized. During that entire window, the infrastructure was operational and actively being used. Businesses that suffered credential exposure during that period may not know it yet.

This is the uncomfortable reality of the modern threat landscape: the damage is often done quietly, long before anyone hears about a takedown. Infostealer malware logs your employees' credentials in the background. Those logs get packaged and sold. Buyers use proxy services to stay invisible while they test and exploit the access. By the time a news story appears, the exposure may be months old.

That is why reactive security — waiting for an incident before investigating — leaves SMBs consistently behind the curve. Monitoring your business's presence in breach databases, infostealer dumps, and dark web markets needs to happen continuously, not just after a headline.

What Your Business Should Do Right Now

The proxy network seizure is a useful reminder to take stock of your current exposure. Start by identifying which employee or company email addresses appear in known breach datasets. Check whether any credentials tied to your domain are circulating in infostealer logs — these are detailed dumps that often include the exact website, username, and password captured from an infected device, and they are traded actively on dark web forums.

Enforce unique, strong passwords across all business tools and enable multi-factor authentication wherever possible. Audit which third-party services your team logs into with company credentials, since those are high-value targets for credential stuffing attacks that rely on proxy anonymity to avoid detection.

At Breachrr, we monitor breach databases, infostealer dumps, dark web markets, public code repositories, and domain infrastructure to surface exactly this kind of exposure before it becomes a breach. If the NetNut and Popa botnet story has you wondering whether your business credentials are already out there, the honest answer is: you should find out. Run a free audit at breachrr.com/audit and see what we find.

Want to see if your company is exposed?

Want to see if your company is exposed?

Run a free audit →
FBI Seizes NetNut & Popa Botnet: What SMBs Must Know · Breachrr · Breachrr