Poland arrests five people as Europol and the DOJ take down the Lolek “bulletproof” host for allegedly facilitating Netwalker ransomware and other attacks
Europol The Hacker News : Lolek Bulletproof Hosting Servers Seized, 5 Key Operators Arrested Habiba Rashid / HackRead : Feds Seize Bulletproof Hosting Service “Lolek Hosted” Jurgita Lapienytė / Cybernews.com : Hosting service used by criminals taken down in Poland Rohan Goswami / CNBC : ‘Bulletproof’ hosting site that allegedly enabled 400 ransomware attacks seized, founder indicted Akshaya Asokan / DeviceSecurity.io : ‘Bulletproof’ LolekHosted Down Following Police Operation Joe Warminsky / The Record : Takedown of Lolek bulletproof hosting service includes arrests, NetWalker indictment Claudia Glover / Tech Monitor : Illegal web hosting service Lolek Hosted taken down by Europol, the FBI and the IRS X: @dojcrimdiv : Administrator of ‘Bulletproof’ Webhosting Domain Charged in Connection with Facilitation of NetWalker Ransomware U.S. Authorities Announce Court-Authorized Seizure of LolekHosted https://www.justice.gov/... [image] @uuallan : Interesting, Netwalker used Lolek for hosting. I am pretty sure other ransomware groups use them as well. Nice reporting from @LawrenceAbrams https://www.bleepingcomputer.com/ ... [image] @europol : 🌐 5 arrested in Poland by @CyberPolicjafor running bulletproof hosting service used by criminals to launch cyberattacks across the world. This latest success in the fight against cybercrime was supported by Europol and the @FBI. Press release ⤵️ https://www.europol.europa.eu/ ... Forums: Slashdot : ‘Bulletproof’ Web Site Hosting Ransomware Finally Seized, Founder Indicted
Context & Ripple Effects
The case targets an enabling layer of ransomware operations rather than only a single attack group: Polish authorities, Europol, and U.S. agencies acted against the hosting service alleged to have supported NetWalker and other ransomware activity.
It fits a later pattern of multinational disruption aimed at cybercrime infrastructure, including the LabHost phishing-service operation and arrests tied to LockBit operators in Poland and Ukraine.
First-order effects
- Lolek Hosted’s seizure and the arrests immediately remove the alleged operators and hosting capacity from the customers that depended on the service.
- The U.S. case against Lolek’s administrator extends the operation from infrastructure disruption to individual legal exposure.
Second-order effects
- Ransomware and other criminal users of the service must replace disrupted hosting and operational support, adding friction to active campaigns.
- The joint action gives investigators a route to connect an alleged infrastructure provider with downstream ransomware activity, increasing pressure on comparable hosting intermediaries.
Third-order effects
- If repeated, cross-border actions against hosting, botnet, and phishing providers could make the shared service layer a more consequential enforcement target than any one malware brand.
- The pattern points toward cybercrime enforcement focused on chokepoints—servers, domains, and service operators—although durable disruption depends on whether replacements can be established quickly.
The trend: Law enforcement is increasingly pursuing the infrastructure and service providers that make cybercrime campaigns scalable, alongside the operators of individual ransomware groups.