How to Tell If a Proxy
Provider Is Ethical

Two of the residential proxy industry's largest networks, IPIDEA and NetNut, were both dismantled in 2026 after researchers tied their IP pools to non-consensual device enrollment. Here's the checklist that would have flagged both before you ever signed up, plus what actually happened in each case.

Rows of illuminated data center server cabling representing proxy and network infrastructure.
TL;DR
An ethically sourced proxy provider can show you, not just tell you, how its IP pool was acquired: documented consent from device owners or a direct ISP lease, a self-serve way to test before you buy, independent benchmark data instead of only self-reported numbers, and clear ownership of whatever brand you're actually signing up with. Two of the industry's largest networks failed that test in 2026. Google disrupted IPIDEA, which turned out to be 13 outwardly separate brands run from shared infrastructure, on January 29, 2026. The FBI and IRS Criminal Investigation seized NetNut's domains on July 2, 2026, after researchers tied its infrastructure to a botnet called "Popa," and NetNut had itself absorbed a wave of customers displaced by the IPIDEA takedown months earlier. Both failures trace back to the same root cause: IP pools built from devices enrolled without meaningful disclosure.
  • Check how the IP pool is sourced, not just whether the provider says "ethical." Ask for documentation of device-owner consent or a direct ISP lease agreement, not just marketing copy.
  • Check who actually owns the brand. Google identified IPIDEA as controlling 13 ostensibly independent proxy brands from shared Hong Kong-registered infrastructure (Google Cloud Blog, Jan 29, 2026).
  • Check for self-serve access and independent benchmarks. A provider that requires a sales call before you can test anything is harder to audit and harder to walk away from quickly.
  • Treat this as an ongoing check, not a one-time decision. NetNut passed enough of a basic trust bar to absorb IPIDEA's displaced customers, then failed the same underlying test five months later.

"Ethically sourced" appears on nearly every residential proxy provider's homepage. It's rarely backed by anything a buyer can actually verify. That gap matters more after 2026 than it used to: two networks that used the phrase, or something close to it, in their own marketing were dismantled within six months of each other, both for the same underlying reason.

This is a working checklist for telling the difference between a provider that can substantiate its sourcing claims and one that can't, built directly from what investigators and independent researchers found wrong with IPIDEA and NetNut. The checklist comes first. The two case studies that produced it follow, along with what to do if you had an active subscription with either network.

The Checklist: Six Signals of an Ethically Sourced Proxy Provider

A provider is worth trusting with your traffic if it can show verifiable consent for how it acquired its IPs, let you test that pool before committing money, and stand behind its numbers with data it didn't generate itself. Everything below breaks that down into checks you can actually run.

What to CheckWhy It Matters
How the IP pool is sourcedAsk directly whether IPs come from consenting device owners or partner ISPs, and whether that's documented anywhere public, not just asserted in marketing copy.
Whether the "brand" is actually independentIPIDEA operated as 13 outwardly separate brands from shared infrastructure. A cheap or unfamiliar name isn't automatically suspect, but check who actually operates it before assuming it's unrelated to a known bad actor.
Self-serve dashboard and API accessA provider you can sign up for, test, and cancel yourself, without a mandatory sales call, is easier to audit and exit quickly if something changes.
Independent benchmark dataLook for third-party testing (Proxyway and similar) rather than relying only on a vendor's self-reported success rate and latency numbers.
Free trial before commitmentTest the actual pool against your real target sites before paying for volume, rather than trusting a sales pitch.
Billing transparencyClear per-GB or per-IP pricing you can see without a quote request is easier to budget and easier to walk away from.

Red Flags That Show Up Before the Takedown

Neither IPIDEA nor NetNut collapsed without warning signs a careful buyer could have caught. Enrollment disclosure buried inside an app's terms rather than a clear opt-in prompt, "ethically sourced" claims with no linked policy or documentation behind them, and a pool size that only ever gets described in cumulative "nodes since [year]" terms rather than a concurrently active figure are all patterns that showed up in the reporting on both networks.

Provider Trust Criteria: Illustrative Comparison
Sourcing Transparency Self-Serve Access Billing Transparency Independent Benchmarks TorchProxies NetNut (pre-shutdown) Editorial synthesis based on sourced facts below, not a separately measured index
Verdict
A provider that lets you sign up, test with a free trial, and see published pricing without a sales call is easier to verify and easier to leave quickly if you ever need to. That's a lower bar than "prove your sourcing is perfect," but it's the bar NetNut's self-serve tiers cleared while its underlying sourcing model apparently did not.
TorchProxies Residential & ISP Proxies
Ethically Sourced, Self-Serve, No Sales Call Required.
TorchProxies runs a self-serve dashboard and full API today, with a free 1GB trial and no credit card required, so you can test against your own target sites before committing to volume.
✓ Free trial, no card required✓ Self-serve dashboard✓ 195+ countries
Start Your Free Trial ✓ Instant self-serve signup
Rack of servers in a data center, illustrating the kind of infrastructure a legitimate proxy provider discloses and operates transparently.

Why This Checklist Exists: Two 2026 Case Studies

The timeline runs faster than most infrastructure stories, and it doesn't start with NetNut. Google disrupted IPIDEA, a network controlling 13 ostensibly independent proxy brands, on January 29, 2026. NetNut absorbed a meaningful share of the customers displaced by that takedown. Five months later, NetNut was seized too.

Timeline: IPIDEA and NetNut Disruptions, January-July 2026
Jan 29, 2026 Google disrupts IPIDEA network Jun 19, 2026 Researchers publish Popa botnet link Jul 2, 2026 FBI + IRS-CI seize NetNut domains Jul 8, 2026 Alarum's site seized; stock -67% Source: Google Cloud Blog, Jan 2026; Krebs on Security, Jul 2026
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Benjamin Brundage, founder of proxy-tracking service Synthient, told Krebs on Security. NetNut, he said, "was on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."

Case One: IPIDEA, 13 Brands, One Undisclosed Network

📡
IPIDEA Takedown
A residential proxy operation Google identified as controlling 13 ostensibly independent brands from a shared set of Hong Kong-registered entities, disrupted via legal action against command-and-control domains, Google Play Protect enforcement, and coordination with Cloudflare and industry partners (Google Cloud Blog, "Disrupting the World's Largest Residential Proxy Network", Jan 29, 2026).

Google's Threat Intelligence Group documented over 600 Android applications with code connecting to IPIDEA's command infrastructure, plus more than 3,000 unique Windows executable file hashes doing the same. Devices were enrolled through four SDKs Google attributed to IPIDEA's operators (branded Castar, Earn, Hex, and Packet), bundled into free utility and game apps, and in some cases through trojanized software impersonating tools like OneDriveSync and Windows Update, or VPN apps (Galleon VPN, Radish VPN) that didn't disclose their proxy functionality. Google stated plainly that "many of the malicious applications we analyzed in our investigation did not disclose that they enrolled devices into the IPIDEA proxy network."

The scale of abuse mirrored what NetNut would face five months later: over 550 distinct threat groups, including clusters Google tracks as based in China, North Korea, Iran, and Russia, used IPIDEA exit nodes in a single tracked week in January 2026.

If You Recognize One of These Brand Names
Google identified 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, Door VPN, Galleon VPN, IP 2 World, Ipidea, Luna Proxy, PIA S5 Proxy, PY Proxy, Radish VPN, and Tab Proxy as commonly controlled brands under the same infrastructure. If you were a customer of any of these, the same evaluation checklist above applies to you, not just to NetNut buyers.

Case Two: NetNut, the Popa Botnet Connection

📡
Popa Botnet
A network Google estimated at more than 2 million compromised devices, primarily smart TVs and streaming boxes, turned into "always-on residential proxy nodes" and rented out to relay third-party internet traffic without meaningful user consent (Krebs on Security, Jul 2, 2026).

On July 2, 2026, the FBI and IRS Criminal Investigation division seized hundreds of domains associated with NetNut and replaced its homepage with a federal seizure banner. The action was carried out with Google, Lumen, and Shadowserver as supporting partners (Krebs on Security, "FBI Seizes NetNut Proxy Platform, Popa Botnet", Jul 2, 2026). A second wave of seizures on July 8 hit Alarum Technologies' main corporate website directly. Alarum (Nasdaq: ALAR), the publicly traded Israeli company that operates NetNut, saw its stock drop 67% over that week. Legal counsel for the company said it would cooperate with investigators, per the same reporting.

The mechanism researchers described is close to what happened at IPIDEA, just under a different brand: software components (SDKs) that promise device owners payment for "sharing unused bandwidth" get bundled into free streaming apps or preinstalled on unofficial Android TV boxes, often with little disclosure of what the bandwidth is actually used for. Once enrolled, the device becomes an exit node in someone else's proxy network, whether the owner understands that or not. Google's Threat Intelligence Group reported observing 316 distinct threat-actor clusters using suspected NetNut exit nodes in a single week in June 2026, for activity including password-spraying campaigns, credential stuffing, advertising fraud, and unauthorized data scraping (Krebs on Security, citing Google's findings).

Proxyway, an independent proxy-industry review site with no apparent stake in the outcome, updated its standing NetNut review to reflect the shutdown directly: "In July 2026, the FBI and Google disrupted NetNut, shutting down its website and proxy network," and the service is now marked "currently not in business" (Proxyway, In-Depth NetNut Review, updated Jul 7, 2026).

What's Confirmed vs. Not
Confirmed by multiple independent sources: the domain seizures, the law enforcement agencies involved, the botnet-to-NetNut link researchers published, and Alarum's stock decline. Not confirmed: any criminal charges filed against Alarum Technologies as a corporate entity, or a final determination of the company's culpability. Treat NetNut's current status as "seized and non-operational, under investigation" rather than "convicted."

Why This Keeps Happening: A Structural Problem, Not Two Isolated Incidents

Two of the industry's largest networks failing the same way, six months apart, is a pattern, not a coincidence. Both cases trace back to the same business model: pay device owners (or the app developers who bundle an SDK) for "sharing unused bandwidth," then resell that bandwidth as a residential IP pool, with disclosure to the actual device owner treated as optional rather than required.

The distinction matters for buyers: neither takedown was researchers flagging a few bad actors misusing an otherwise-clean service. In both cases, researchers characterized the sourcing model itself as the structural problem, not an isolated misuse case layered on top of legitimate infrastructure.
Why This Is Different From a Typical Outage
A server crash or a billing dispute is recoverable in days. A takedown tied to researcher-documented non-consensual device enrollment is not something a buyer should wait out, and it's not specific to one vendor's bad luck. If a disrupted network resumes operation under new ownership, or under a new brand name entirely, treat that as a genuinely new evaluation, not a return to the status quo. This is also why the checklist above should be a standing habit, not a one-time vetting step: NetNut cleared enough of a basic trust bar to absorb IPIDEA's displaced customers, then failed the same underlying test five months later.

What This Means If You Were a NetNut or IPIDEA-Family Customer

Practically, three things are true right now, whichever network you were on. First, your dashboard and API access are almost certainly gone; seized or dismantled infrastructure means account management isn't under the original operator's control anymore. Second, any active billing arrangement is in limbo; if you're on a recurring subscription, check your card or bank statement directly rather than waiting for a cancellation email that may never arrive, and dispute charges through your payment provider if needed. Third, if your workflows (scraping, ad verification, brand monitoring, account management) depended on the affected residential or ISP pool, they're down now, not degrading gradually, so treat migration as urgent rather than something to plan for next quarter.

There's also a compliance angle worth taking seriously if you run a business that used either network for anything client-facing or regulated: ad verification vendors, brand-safety monitoring firms, and compliance-tracking teams that routed traffic through infrastructure now tied to non-consensual device enrollment may want to document when they stopped using the service, for their own audit trail.

Migrating Off NetNut or an IPIDEA-Family Provider Without Losing Your Workflow

1
Audit What You Were Actually Using
Check your last invoice or usage logs for proxy type (residential, static/ISP, mobile, datacenter), rough monthly volume, and which target sites mattered most. You'll need this to pick an equivalent plan elsewhere.
2
Match the Proxy Type, Not Just the Provider
If you ran rotating residential traffic, look at a Standard or Premium residential plan. If you relied on a static/ISP pool for account-based work, look at ISP proxies. Note honestly: TorchProxies does not currently offer a mobile proxy product, so if your workload was specifically mobile-carrier traffic, you'll need to source that piece from elsewhere.
3
Test Against Your Real Targets Before Committing Volume
Use a free trial to run your actual scraping, monitoring, or account workflows against the new pool before buying at scale. A provider's aggregate success rate doesn't guarantee performance against your specific target sites.
4
Update Firewalls, Allowlists, and Hardcoded Endpoints
Swap any hardcoded gateway addresses or IP allowlist entries in your scraping scripts, RPA tools, or ad-verification pipelines, and rotate any credentials that were tied to the old account, whether it was with NetNut or one of the IPIDEA-family brands.
5
Dispute Active Billing Directly With Your Payment Provider
Don't wait for a cancellation confirmation from a seized domain. Contact your card issuer or bank about any recurring charge if you can't reach the company directly.

Summary

01
Ethical sourcing is verifiable, not just claimed. Documented consent or a direct ISP lease, self-serve testing, independent benchmarks, and clear brand ownership are the four checks that matter most.
02
Two major networks failed that test in 2026. Google disrupted IPIDEA (13 brands) on January 29; the FBI and IRS-CI seized NetNut on July 2, after NetNut had absorbed a wave of displaced IPIDEA customers.
03
If you had an active subscription with either network, migration is urgent, not optional. Dashboard and API access are almost certainly gone, and billing disputes should go through your payment provider directly.
04
Treat vetting as ongoing, not a one-time check. A provider that passes today can still fail this test later, which is exactly what happened to NetNut.

For a deeper look at how residential and ISP proxies differ structurally, see our datacenter vs. residential proxies breakdown or static vs. rotating proxies guide. If you're rebuilding a scraping pipeline from scratch after this, our complete guide to proxies for web scraping is a reasonable starting point.

Frequently Asked Questions

What's the single biggest red flag when evaluating a proxy provider? +
A sourcing claim you can't verify. "Ethically sourced" with no linked consent policy, no named SDK partners, and no way to confirm who actually owns the brand is the pattern both IPIDEA and NetNut shared before their respective takedowns.
Is IPIDEA the same company as NetNut? +
No, they were separate operators with no stated ownership connection. What links them is the pattern: both built large residential proxy pools using SDKs bundled into apps with weak or no disclosure to device owners, and both were disrupted in 2026 as a result. Some NetNut customers were previously IPIDEA customers, per on-record reporting, which is why this article treats them as one story rather than two.
Was my traffic affected just by using NetNut or IPIDEA, even if I didn't know about the botnet issues? +
The botnet allegations concern how device-side IPs were reportedly sourced (compromised smart TVs, streaming boxes, and apps with undisclosed SDKs), not the buyer side of the marketplace. There's no public reporting suggesting proxy customers themselves face legal exposure for having purchased the service. If your business has compliance obligations, documenting when you stopped using either network is still a reasonable precaution.
How is TorchProxies' IP sourcing different? +
TorchProxies markets its residential IPs as ethically sourced across a 30M-120M+ pool depending on plan, and its ISP proxies as leased directly from real internet service providers. As with any provider, including TorchProxies, buyers should ask directly about sourcing documentation rather than taking any single vendor's claim at face value, which is the core lesson of this whole situation.
What proxy type should I switch to if I don't know which one I need? +
Start with what plan you were on: rotating residential traffic maps to a Standard or Premium residential plan, static/ISP-style traffic maps to ISP proxies. If you're unsure, our datacenter vs. residential comparison walks through the structural differences before you commit to volume.