Rahman Ravelli
Syedur Rahman

Syedur Rahman | 26 May 2026
Share on:
Contact The Author >

Sanctions enforcement against digital infrastructure operators

On 22 May 2026, the Dutch Fiscal Intelligence and Investigation Service (FIOD) seized 800 servers from a web hosting provider. The action marks a significant step in enforcing sanctions on those operating digital infrastructure.

What is emerging is new sanctions enforcement aimed not at malware operators directly, but at the digital infrastructure providers that enable them.

European regulators appear to be moving toward a position that hosting capacity, colocation, and connectivity services are not merely passive technical functions. Instead, they may constitute “economic resources” made available to sanctioned actors under EU sanctions law.

That represents a material conceptual shift with consequences for datacentres, carriers, hosting firms, and internet infrastructure brokers operating across Europe and, potentially, the UK.

Summary of the Stark Industries situation

The hosting company in question is Stark Industries Solutions Limited. Among other things, it ran two data centres in the Netherlands.

The EU had imposed sanctions on Stark Industries on 20 May 2025 for supplying infrastructure to people and entities aligned with Russia. For example, it was discovered that a pro-Russian hacktivist organisation was using the infrastructure that was seized. A substantial share of the customer base was Russian and Belarusian.

Customers were using the servers for cyberattacks, interference operations, and disinformation campaigns.

Stark Industries is known as a “bulletproof” hosting operation. In other words, it turns a blind eye to illicit activities. Its modus operandi was to ignore any complaints about abuse, refuse to cooperate with law enforcement requests outside of the Netherlands, and rent capacity to anybody who pays. It is essentially a safe haven for cybercriminals.

Digital infrastructure now treated as an economic resource

When the EU sanctions an entity, member states are required to act immediately to freeze its assets and prohibit making funds or economic resources available to them.

As this incident demonstrates, the enforcement of sanctions has expanded beyond physical goods. It now includes intangible assets such as intellectual property, algorithms, and source code.

The core allegation in the Stark Industries investigation is not simply that malicious cyber activity passed through European infrastructure. Authorities appear to argue that the infrastructure itself formed part of the prohibited support ecosystem.

Under traditional enforcement approaches, hosting providers and connectivity operators have often been treated as neutral intermediaries. They were digital utilities analogous to telecommunications carriers or landlords. Liability generally attached only where operators actively participated in criminal conduct or knowingly facilitated unlawful activity.

This case suggests regulators are now testing a broader theory: that digital infrastructure services themselves can amount to sanctionable economic support where operators know, suspect, or wilfully ignore the beneficial ownership or operational control structures behind sanctioned entities.

In practical terms, this potentially expands sanctions exposure well beyond direct financial transactions. Hosting environments, colocation, routing services, and IP address leasing may all now fall within the scope of enforcement analysis.

That has major implications for infrastructure operators whose compliance programmes were historically designed around abuse management rather than sanctions risk.

Connectivity brokers face direct exposure

In this matter, Mirhosting allegedly supplied colocation operations and high-capacity connectivity into European internet exchanges, allowing traffic associated with the network to enter major European routing environments through legitimate infrastructure channels.

That potentially places connectivity providers, transit operators, and datacentre intermediaries directly within the sanctions enforcement perimeter.

Historically, these firms have often viewed themselves as infrastructure wholesalers rather than regulated gatekeepers. But if regulators adopt the position that connectivity itself can constitute a prohibited economic resource, operators may face heightened obligations to assess who ultimately benefits from the infrastructure they provision.

The legal threshold may no longer be active participation in cyber operations. It may instead become whether providers ignored indicators that sanctioned actors retained operational benefit from the services supplied.

That is a lower and broader compliance risk threshold.

About The Author

Syedur Rahman
Partner

+44 (0)203 910 4566 vCard

Syedur Rahman is known for his in-depth experience of serious fraud, white-collar crime and serious crime cases, as well as his expertise in worldwide asset tracing and recovery, international arbitration, civil recovery, cryptocurrency and high-stakes commercial disputes.

View Author Profile >