Earlier this month, the European Union sanctioned the Russian hosting provider Media Land and associated individuals and companies, following US criminal charges that the company knowingly operated a ‘bulletproof hosting’ service for ransomware groups including LockBit, BlackSuit, and Play.
The case reflects a broader shift: governments are increasingly willing to treat the businesses enabling cybercrime as enforcement targets in their own right. This means seizing servers, taking down domains, and dismantling command-and-control networks. When individual offenders cannot immediately be reached, disrupting the infrastructure they rely on can make their operations harder to sustain.
Law enforcement operations like Endgame, which combines the disruption of malware infrastructure with a dedicated effort to identify and target bulletproof hosting providers as key enablers of cybercrime, illustrate how seriously this approach is now taken.
This tactic makes sense, but it also creates a legal dilemma that rarely receives attention. The same legal framework that enables rapid disruption can also remove some of the evidence needed to prove that the hosting companies behind that infrastructure knowingly facilitated those crimes, making it more difficult to hold providers accountable.
A legal shield
European law treats hosting providers as intermediaries, not investigators. The Digital Services Act (DSA) limits general monitoring obligations and protects providers from liability when they have no knowledge of illegal activity on their platforms. That protection exists for a good reason. Without it, hosting providers would face constant pressure to surveil their customers in order to avoid legal exposure. A provider cannot reasonably know everything its customers do, and it should not function as a private regulator of the internet.
This protection is not unconditional, however. The DSA makes clear that sufficiently precise abuse notifications can establish actual knowledge of illegal content, while providers that intentionally cooperate with users carrying out illegal activities cannot rely on the liability exemption in the first place.

The bulletproof problem
Most hosting providers operate within that framework without difficulty. The problem is a subset providing ‘bulletproof hosting’ services that do not. They ignore abuse complaints, design infrastructure to resist law enforcement action, and, in some cases, structure their operations around clients whose activity would be removed anywhere else.
The difficulty is proving it. Establishing that a provider is genuinely operating as a bulletproof hoster requires demonstrating that it knowingly facilitated criminal activity rather than only providing neutral hosting services, a hard evidentiary bar for prosecution.
The US Media Land indictment illustrates how high this bar is. Rather than relying simply on the presence of criminal infrastructure, prosecutors cited forum advertisements, abuse handling practices, infrastructure designed to resist takedowns, internal administration systems, customer databases, and financial records dating back to at least 2012. It is this broader pattern of conduct, rather than any individual phishing campaign or malware server, that distinguishes knowingly facilitating cybercrime from inadvertently hosting criminals.
Under the DSA, stripping a provider of its liability exemption requires showing it had actual knowledge of illegal content and chose not to act. Proving that depends on the same evidence as the indictment, specifically a demonstrable pattern of abuse observations that were reported and ignored.
The Dutch example
The Netherlands has long been a significant location for cybercrime-related hosting activity and provides a particularly clear illustration of this tension. Article 54a of the Dutch Criminal Code limits criminal liability for hosting providers that comply with an order from the Public Prosecution Service to make illegal data inaccessible. Article 125p of the Code of Criminal Procedure gives prosecutors the power to issue that order.
Both provisions make perfect sense on their own. It is important that not every hosting provider that has illegal activity on their infrastructure is immediately treated as a criminal enterprise. However, together they can produce an unusual paradox when the hosting provider itself is under investigation.
When evidence disappears
Consider what happens when investigators identify a hosting provider whose infrastructure is supporting a large phishing operation. A public prosecutor orders the provider to take the relevant data offline. The provider complies, the infrastructure disappears, and the immediate threat is contained.
Dutch law says that a hosting provider cannot be criminally prosecuted for content on its infrastructure if it complies with the order. But it does not protect against prosecution for other offences, such as actively facilitating crime or participating in a criminal organisation.
Complying with a takedown order may, however, remove an important source of evidence needed to establish those other offences. While investigators may preserve parts of the infrastructure or obtain evidence through other means, disrupting an operation can make it considerably harder to document an ongoing pattern of abuse, provider responses, and failures to act.
Building a criminal case against a hosting provider requires showing the provider knew what was happening, looked the other way, or actively helped, systematically failing to address abusive content. Not all of that evidence sits on the infrastructure taken offline, but once an operation is disrupted, access to it becomes considerably harder.
The Media Land indictment included 70 pages of evidence against a prolific hoster – investigators won’t always have the opportunity to assemble such a clear record, especially when operational priorities require criminal infrastructure to be dismantled much earlier.
A troublesome outcome
A provider that has operated for years and complied with each order it received can also point to that compliance history as evidence of good faith. The stronger the provider’s record of complying with individual orders, the easier it becomes to portray each incident as an isolated compliance issue, and the harder it becomes to argue the case for deliberate tolerance or facilitation. The framework designed to disrupt criminal infrastructure can end up generating a record that works in the provider’s favour.
This tension leads to a proportionality issue. When a hosting provider is already under investigation, a public prosecutor may choose not to issue a takedown order in service of building the criminal case.
However, the more serious the underlying crime, the harder it is to justify leaving infrastructure online while the case against the provider is built. That is understandable, but it leads to a strange dynamic: providers who facilitate the most serious forms of cybercrime may face the least legal accountability. This is not because investigators lack interest, but because the pressure to act quickly takes precedence, effectively creating an evidentiary problem.
Infrastructure disruption and prosecution of facilitators look like complementary objectives. In practice, they can pull in opposite directions. Dutch policy already reflects this trade-off. Where investigators already have indications that a provider is actively facilitating criminal activity, issuing a takedown order may no longer be the proportionate course of action – it risks strengthening the provider’s legal position while complicating the criminal investigation.
No easy fix
Frameworks designed to protect legitimate intermediaries are struggling to account for providers whose business model depends on facilitating crime while presenting themselves as ordinary hosting organisations. Expanding investigative powers is the obvious response – but probably the wrong one. Powers introduced for serious crime rarely stay limited to it, and lower evidentiary thresholds tend to produce problems that take far longer to fix than the ones they solve.
The challenge, then, is not to make disruption easier but to ensure that accountability survives disruption. That requires preserving evidence before infrastructure is dismantled, documenting persistent patterns of non-compliance outside the criminal process, and ensuring that a provider’s record of complying with individual takedown orders is assessed alongside any broader evidence of deliberate criminal facilitation.
Existing law already contains elements of that approach. The EU’s e-Evidence regulation allows investigators to preserve relevant data before a takedown rather than having to try to reconstruct it afterwards. The DSA’s administrative enforcement regime enables authorities to investigate and document structural failures to address illegal content without having to prove criminal intent. Neither mechanism eliminates the underlying tension, but together they reduce the risk that successful disruption comes at the expense of future accountability.
A structural gap
The gap between what investigators can disrupt and what they can prove in court is not a technical problem awaiting a technical fix. It is the product of legal frameworks applied to a context they were not designed for.
Governments have increasingly embraced infrastructure disruption as a strategy for tackling cybercrime, and rightly so. But disruption should not become a substitute for accountability. A legal framework that repeatedly removes criminal infrastructure while leaving the companies that knowingly enable it beyond reach is not fully achieving its purpose. Unless that evidentiary gap is addressed, governments risk winning minor battles against cybercriminal infrastructure while losing the longer-term war against the business models that sustain it.






