Executive Summary
Every bulletproof hosting provider profiled in this library depends on a chain of commercial services it does not own: transit connectivity, IP address allocations, physical rack space, corporate registration, and payment rails. Each link in that chain is operated by a company that is, in most cases, entirely lawful, frequently European, and under no legal obligation to look at what its customer is doing.
This page addresses the question the individual provider profiles do not: not who the operators are, but why the service is permitted to remain reachable. The state protection question, the Russian security services relationship and the tolerated safe harbour model, is assessed separately in Section 07 of each provider profile. This analysis covers the other half of the problem, which sits almost entirely inside Western and EU jurisdictions.
Bulletproof hosting persists less because of Russian protection than because the commercial layer above it has no legal duty to act, no reputational cost for inaction, and a well-established business rationale for neutrality. Russian tolerance explains why operators are not arrested. Western intermediary liability law explains why their servers stay online. Analyst Inference
Key Findings
| Finding | Detail | Confidence |
|---|---|---|
| Upstream concentration is the single largest structural vulnerability | Recorded Future's Insikt Group identified more than a dozen assessed threat activity enablers taking upstream connectivity from one German carrier, aurologic GmbH, including sanctioned Aeza. Several downstream networks route exclusively through it, creating single points of failure that have never been exercised. | Confirmed |
| Registry policy freezes resources but does not reclaim them | RIPE NCC freezes registration of number resources held by sanctioned parties but does not deregister them or terminate membership, on guidance from the Dutch Ministry of Foreign Affairs. Sanctioned providers retain their allocations and can move them to new, unsanctioned legal entities. | Confirmed |
| EU intermediary liability law makes inaction legally correct | Under the Digital Services Act mere conduit provisions and the German DDG, transit providers carry no general monitoring obligation and incur liability only on actual knowledge. Providers structure their terms of service around this, acting only on formal notice. | Confirmed |
| Sanctions designate the entity, not the infrastructure | Aeza reallocated US-facing IP resources to a newly registered Serbian entity within 24 hours of the July 2025 OFAC designation, and to a new UK entity within three days. Stark Industries migrated resources weeks before the May 2025 EU listing and rebranded to THE.Hosting under a Dutch company. | Confirmed |
| Company registry integrity powers have outperformed sanctions authority against the shells | Hypercore Ltd was struck off in December 2025 and Aeza International Ltd in March 2026, both for false or misleading incorporation information rather than under sanctions authority. This is the one enabling layer where an existing, unglamorous power has actually removed entities. | Confirmed |
| The upstream lever is not available against every provider | Five of seven published profiles have at least one upstream inside an EU, UK, or US jurisdiction, and two of them depend on the same German carrier. Media Land and Bearhost/PROSPERO route through Russian carriers and, in the Bearhost case, a Russian security vendor's ASN, placing them outside the reach of Western transit pressure. | Credible |
| Upstream termination works when it is used, and it is almost never used | The November 2008 McColo de-peering by Global Crossing and Hurricane Electric removed the network within a day and cut global spam volume by two thirds or more. No comparable voluntary upstream action against a major BPH has been documented since. | Confirmed |
| Scope | Commercial and governance infrastructure sitting above bulletproof hosting providers. Excludes state protection, which is covered per-profile in Section 07. |
|---|---|
| Providers referenced | Aeza Group, Bearhost / PROSPERO, DEDBROPRO, Media Land, Stark / THE.Hosting, Virtualine / Railnet, ZServers / XHost |
| Enabler jurisdictions | Germany, Netherlands, Bulgaria, United Kingdom, United States, Russia, Montenegro, Serbia, Seychelles, Turkey |
| Governing legal instruments | EU Digital Services Act (Regulation 2022/2065) Article 4; German Digitale-Dienste-Gesetz (DDG); RIPE NCC Standard Service Agreement; EU restrictive measures regulations |
| Primary evidence base | Recorded Future Insikt Group (Nov 2025); Spamhaus Project (Jun 2026); Binding Hook / Virtual Routes (Oct 2025); KrebsOnSecurity; Qurium; RIPE NCC published policy and transparency reporting |
| Last reviewed | 31 July 2026 |
The Enablement Stack
A bulletproof host is not a self-contained business. It is an assembly of purchased dependencies, each obtainable from a limited number of suppliers, and each representing a distinct point at which the service could be denied. The two panels below show that position as the ecosystem map records it: what feeds the hosting layer, and what the hosting layer feeds.
The five dependencies in full
The map models the enablement layer as three nodes, because those are the three that can be given a distinct owner and a distinct disruption pathway. The full dependency chain has five links. The list below expands the three that appear in the panels above, and adds the two the map does not model separately: physical facilities, which are covered by the hosting jurisdiction rather than by a supplier relationship, and payment rails, which are treated as a financial node elsewhere in the map.
Read downward. The ordering is by disruption leverage, highest first, and it is not the order in which enforcement has actually been attempted.
Enforcement activity to date has concentrated on Layers 3, 4, and 5, which are the layers where legal authority is clearest. Layer 1, which carries the highest disruption value, has been almost untouched because it depends on voluntary commercial decisions by companies that are not themselves accused of wrongdoing. Analyst Inference
Upstream Transit: The Intermediary Layer
Cross-profile upstream dependency map
Upstream chains as documented in Section 04 of each published profile. Jurisdiction here refers to the transit provider, not the bulletproof host. This table and every count derived from it are generated from a shared data file, so a newly published profile appears here as soon as it is registered there.
| Provider | Documented upstream chain | Reachable jurisdiction | Transit lever |
|---|
Transit pressure is a jurisdiction-dependent tool, not a universal one. It is available against Aeza, Stark, ZServers, DEDBROPRO and Virtualine, and unavailable against Media Land and Bearhost. Disruption planning that assumes a uniform upstream lever will misallocate effort against exactly the two providers where seizure and designation are the only options. Analyst Inference
Case study: aurologic GmbH as concentration point
Recorded Future's Insikt Group published the most detailed available assessment of upstream concentration on 6 November 2025. The findings establish that the concentration problem is not theoretical. Confirmed
- aurologic GmbH has existed as a legal entity since October 2015, but emerged in its current form in October 2023 when combahton GmbH's fastpipe network and AS30823 transitioned into it, with the rebrand formally announced in November 2023. It operates from Tornado Datacenter GmbH & Co. KG in Langen, Germany. Both companies are headed by the same individual.
- Insikt Group identified more than a dozen assessed threat activity enablers taking upstream connectivity from aurologic, including Aeza International Ltd, Railnet LLC, Global-Data System IT Corporation, Femo IT Solutions Ltd, and WAIcore.
- Approximately 50 percent of Aeza International's announced prefixes routed via aurologic at the time of publication, after US and UK sanctions.
- All eleven of Global-Data System IT Corporation's IPv4 prefixes routed solely through aurologic, with no diversification. Roughly 95 percent of Railnet's nineteen prefixes did the same.
- Approximately 13.5 percent of DDoSia tier 1 command-and-control addresses observed between July 2024 and July 2025 were announced either by aurologic directly or by networks taking transit from it.
The concentration is visible without leaving this profile set. Two of the seven providers profiled here, Aeza and Virtualine, depend on aurologic as their primary upstream, and Virtualine routes roughly 95 percent of its backbone traffic through it. One of those two is designated by three authorities and the other by none, yet both are carried by the same German company, over the same period, with no distinction in treatment. A single termination decision at one carrier would reach two of the seven providers in this library at once. Analyst Inference
Aeza's dependence on aurologic was itself the product of an earlier upstream decision. After Qurium published its Doppelganger investigation in July 2024, UK provider DataCamp Limited (AS60068) terminated its contract with Aeza. Aeza publicly stated it then partnered with aurologic to continue operations. One upstream acted; the customer moved to another that did not. Confirmed
The stated rationale for non-intervention
The aurologic CEO's public position, documented across forum posts, an interview with the German investigative outlet CORRECTIV, and the company's own terms of service, is consistent: action follows formal legal notice, and neutrality is a principled stance rather than a commercial convenience.
Insikt Group's own framing of the resulting problem is that the distinction between negligence and complicity becomes meaningless from the perspective of the victim, because the outcome is identical: the malicious infrastructure remains globally reachable. Confirmed
No public reporting alleges that aurologic knowingly facilitates crime, and the company has not been sanctioned, charged, or named in any enforcement action. The assessment here concerns structural position and demonstrated behaviour, not criminal intent. The same analytic caution applies to Hetzner, Hurricane Electric, Zayo, Belcloud, Hostkey, and MIRhosting, each of which appears in a documented upstream chain above.
Registry Governance: Freeze, Not Revoke
Address space is the second dependency and the one that determines whether a designated provider can reconstitute. RIPE NCC's position, developed in consultation with the Dutch Ministry of Foreign Affairs, is that registration of internet number resources constitutes an economic resource for sanctions purposes, which requires freezing, but that deregistration is not required and will not be performed. Confirmed
| Trigger | RIPE NCC action | Practical effect on the provider |
|---|---|---|
| EU sanctions designation | Registration frozen. No new allocations, no transfers. Membership retained. Resources not reclaimed. | Existing space keeps routing. Provider retains its ASNs and prefixes. |
| Falsified or incorrect information supplied to the registry | Permanent deregistration of number resources available under RIPE NCC closure and deregistration procedure RIPE-858. | Terminal, where detected and pursued. |
| Non-payment of membership fees | Deregistration available. | Terminal, where it occurs. |
| Dutch court order | Deregistration available under RIPE-858 section B.1. | Terminal, but requires litigation in the Netherlands. |
| Documented abuse or criminal hosting | No specific policy trigger. | None. |
A member sanctioned by the European Union for enabling cyber operations faces a freeze. A member that submits incorrect paperwork can be fully deregistered. As long as fees are paid and records are accurate, the use of registry resources to support state-aligned cyber operations does not put those resources at risk. RIPE NCC has publicly stated that internet resources should be kept separate from political disputes and has said it will continue to investigate the possibility of a blanket exemption for number resources from EU sanctions regulation. Note the counterpoint: this same integrity power, applied through the UK company register rather than RIPE, is what ultimately removed both Hypercore Ltd and Aeza International Ltd. Confirmed
Local internet registry autonomy as the reconstitution mechanism
Bulletproof providers that hold LIR status can assign prefixes to customer organisations and update registry records themselves. That autonomy is the mechanism by which designation is survived: register a new entity, assign the space to it, update the record. Each step is procedurally ordinary and none of it breaches registry policy.
Why routing security is not the lever it appears to be
A reader familiar with BGP will ask the obvious question: if the registry issues the cryptographic certificates that networks use to validate route announcements, why not revoke a designated provider's certificates and let route filtering do the work? The answer is that this does not function as an off switch, for three separate reasons.
A freeze does not reach the certificates. RIPE NCC's certification terms give an exhaustive list of revocation triggers: inconsistency with the registration records, technical or security compromise, violation of the terms, and voluntary termination. Sanctions designation is not among them, and the certification practice statement omits it as well. Because a freeze preserves the registration record rather than altering it, the inconsistency trigger never fires. Whether a frozen member retains day-to-day access to manage its own route origin authorisations is undocumented, and no published RIPE NCC position addresses it. Confirmed
Revocation would not remove reachability. A prefix is treated as invalid only when a valid authorisation covers it and the announcement fails to match. Revoking a member's certificate destroys all of that member's authorisations at once, so nothing covers the prefix and its status falls back to unknown, which every network accepts, including those that discard invalid routes. Certificate revocation therefore strips a provider of protection against hijacking rather than taking it offline. Prefixes only become invalid once the space is deregistered and reallocated to a different holder who authorises it to a different network, a sequence that runs on months to years. Confirmed
The community has already considered and rejected the idea. A March 2022 multistakeholder statement on internet sanctions, circulated on the RIPE list and signed by senior figures including a then member of the RIPE NCC Executive Board, examined manipulating routing security attestations as a sanctions instrument and concluded that it "could risk the withdrawal of networks from the system entirely" and constituted an unacceptable risk. The reasoning is that a security mechanism repurposed for enforcement stops being one that operators voluntarily adopt. Confirmed
This is the strongest form of the counterargument to this page's central claim. The registry layer's refusal to act is not simple inertia at this particular point: it reflects a documented judgement that converting routing security into an enforcement tool would degrade the security system itself. That judgement is defensible on its own terms, and it further narrows the registry lever to the falsified-data route described above, which bites slowly and through reallocation rather than through anything sudden. Analyst Inference
Sponsoring LIR abuse
Where a network cannot or will not become an LIR itself, it obtains space through a sponsoring LIR. Insikt Group documented a Turkish LIR sponsoring several suspicious ASNs all created during 2025, and prefixes sub-allocated from Iranian and Omani registrants appearing under UK-incorporated shells routing exclusively through a German carrier. Identity verification at the point of registration is the control that failed in these cases: at least one registration used a falsified end-user agreement that a basic check against public company records would have caught. Confirmed
Intermediary Liability: Why Inaction Is the Compliant Choice
The legal question is not whether transit providers are permitted to disconnect abusive customers. They are. The question is whether anything obliges them to, and in the European Union the answer is essentially no until they possess actual knowledge of specific illegality.
| Instrument | What it establishes | Effect on bulletproof hosting |
|---|---|---|
| EU Digital Services Act, Article 4 (mere conduit) | A provider transmitting information is not liable for it where it does not initiate the transmission, select the receiver, or select or modify the content. | Transit carriers are shielded by default. Carriers cite the DSA directly in their terms of service to disclaim responsibility for customer-leased infrastructure. |
| DSA general monitoring prohibition | No general obligation to monitor transmitted information or actively seek facts indicating illegal activity. | Proactive detection of criminal hosting is not merely optional, it is discouraged as a legal design principle. |
| German Digitale-Dienste-Gesetz (DDG) | National implementation establishing a reactive, notice-based compliance regime. | Obligations begin on receipt of valid notice. Incomplete abuse reports may be dismissed without action. |
| Data protection obligations | Restricts traffic inspection by carriers. | Cited by carriers as a reason not to examine downstream customer traffic. Legitimate as stated, and also available as cover for inaction. Analyst Inference |
| Sanctions regulations (EU, UK, US) | Prohibit making economic resources available to a designated person. | Creates the only current compulsion pathway, and only where the immediate customer is the designated entity. Reallocation to a non-designated affiliate defeats it. |
A transit provider remains fully compliant with national law while its network is repeatedly used by threat actors, provided it can claim lack of awareness of intent. The liability framework does not merely permit this outcome; it defines the boundaries of intervention such that inaction is the legally defensible position and proactive disconnection carries contractual and commercial risk that inaction does not. Confirmed
The asymmetry between designation and connectivity
Sanctions attach to legal persons. Connectivity attaches to autonomous system numbers and prefixes. Because the two are separable, and because registry policy permits the separation to be performed by the designated party itself, a designation removes a name from a contract without removing a route from the global table. Every documented case in this library follows that pattern. Analyst Inference
Corporate Formation and Jurisdictional Arbitrage
Registry membership, transit contracts, and datacenter agreements all require a legal entity. The speed and low cost of obtaining one determines how quickly a designated provider reconstitutes. Applying the jurisdictional separation discipline used in the provider profiles, the enabling jurisdictions divide as follows.
A recurring pattern across Insikt Group reporting is the reuse of a small number of London virtual office addresses by multiple assessed threat activity enablers, and the impersonation of legitimate companies during ASN registration. In at least two documented 2025 cases, the name of a real, unrelated European business was used to register an autonomous system that then announced substantial malicious infrastructure. Confirmed
UK Companies House identity verification for directors and persons of significant control began rolling out from 18 November 2025. Whether it materially raises the cost of shell formation depends on the treatment of formation agents, and no measurable effect has yet been published. Credible
Datacenters and Internet Exchanges
Physical facilities are the layer where Western enforcement has been most effective, because the legal authority is unambiguous and does not depend on a commercial partner's willingness to act.
- February 2025, Amsterdam: ZServers infrastructure seized following coordinated US, UK, and Australian designations. The action went directly to sanctions and physical seizure without any documented attempt at upstream de-peering. Confirmed
- May 2026, Netherlands: Dutch FIOD seized more than 800 servers and arrested two individuals connected to the Stark successor infrastructure on suspicion of sanctions violations. Over 200 prefixes remained active afterwards. Confirmed
- Russia-based facilities: The Data Center Kirishi model, where the provider holds or leases physical rack space inside Russia, is not accessible to Western action at all. Confirmed
Internet exchange points occupy an ambiguous position. Stark-linked infrastructure reached AMS-IX and DE-CIX Frankfurt through its Netherlands colocation provider. No public reporting documents an exchange disconnecting a member in response to a sanctions designation, and no exchange policy requiring it has been identified. This is an unresolved question rather than a negative finding. Analyst Inference
Both Amsterdam actions removed hardware while leaving the routing relationships and address allocations intact. In both cases the provider or its successor continued announcing prefixes afterwards. Physical seizure degrades capacity; it does not remove reachability. Analyst Inference
When the Backbone Acts
What upstream termination actually does
One distinction the field tends to blur. Transit is a smaller network paying a larger one to carry its traffic to the rest of the internet. Peering is two networks exchanging traffic directly, usually without money changing hands. The term de-peering is commonly applied to both, but the action that removes a bulletproof host is termination of transit.
A network is reachable because its upstream carrier announces to everyone it connects to that traffic for a given set of addresses should be sent through it. That announcement propagates outward until every major network on the internet knows the path. End the contract, the carrier stops making the announcement, and the route drains out of the global routing table within seconds to a few minutes.
Nothing is confiscated. The servers keep running, the disks still hold the data, and the operator can still reach the machines locally. The addresses simply cease to exist as far as the rest of the internet is concerned. It is not a seizure, it is a refusal to carry, and that is precisely why it outperforms every other instrument available: it takes minutes rather than months, it reaches every hosted service at once rather than one brand at a time, it requires no warrant, and it avoids the jurisdictional problem entirely because the carrier is only deciding who its own customers are. Confirmed
The evidentiary case for this lever rests on a small number of instances, because upstream action is rare. Those instances are consistent.
| Event | Date | Action | Outcome |
|---|---|---|---|
| McColo | November 2008 | Upstream providers Global Crossing and Hurricane Electric terminated connectivity on 11 November 2008. | Immediate. Global spam volume fell by two thirds or more. A brief reconnection via a backup peer on 19 November 2008 was cut off again; spam volumes did not recover to pre-takedown levels until around April 2009. Confirmed |
| Aeza and DataCamp | Disclosed Aug 2024 | UK provider DataCamp Limited terminated its contract with Aeza following the Qurium Doppelganger report of July 2024. Aeza disclosed the termination in August 2024; the termination date itself is not stated in the source. | Partial. Aeza publicly stated it moved to aurologic and continued operating. Effect displaced rather than eliminated. Confirmed |
| Media Land post-designation | Nov 2025 to Jul 2026 | No upstream action taken by any of the four observed peers. | All four peers remained in place across the latest BGP snapshot, through sanctions, indictment, and EU designation. Confirmed |
| Aeza post-designation | Jul 2025 to date | No upstream de-peering by aurologic. Routing continued after US, UK, and Australian designations. | Approximately half of announced prefixes still routed via the same German upstream at last published assessment. Confirmed |
Upstream termination is the highest-yield single action available against a bulletproof host, and the evidence that it works is eighteen years old because it has essentially not been attempted since at comparable scale. Where a single upstream has acted in isolation, the customer has relocated to a more permissive carrier within weeks. This suggests the effective form of the lever is coordinated rather than unilateral: simultaneous refusal by the realistic set of alternative carriers, not termination by one. Analyst Inference
Why the lever is not pulled
The instrument is fast, cheap, and effective, and it sits unused. That is not an oversight. Every incentive acting on a transit carrier points away from using it.
| Disincentive | Mechanism |
|---|---|
| The law rewards inaction | A carrier that does not inspect what it carries has no liability for it, and no obligation to go looking. Acting on suspicion rather than formal notice moves the carrier out of that shelter. Doing nothing is not merely permitted, it is the legally optimal position. |
| The customer holds a contract | Terminating a paying customer without a clear breach or a legal instrument invites a breach of contract claim. Carriers want an instrument that makes disconnection safe: a court order, a designation naming that specific customer, or a formal law enforcement notice. |
| The designated entity is usually not the customer | Sanctions name a legal person; the carrier's contract is frequently with a different legal person one or two steps removed. This is the documented aurologic position on Aeza, where the public defence was that the designated entity was not the contractual customer. Accurate as stated, and it dissolves the obligation. |
| Revenue | High-abuse customers are often high-margin customers, and a carrier known for disconnecting on suspicion loses legitimate business as well. The aurologic CEO stated the trade-off publicly and without embarrassment. |
| Whoever moves first pays for nothing | A carrier acting alone bears the entire cost, in lost revenue, legal exposure, and public argument, while the customer relocates to a more permissive carrier within weeks. DataCamp terminated Aeza and Aeza moved to aurologic. The first mover produces displacement rather than disruption and subsidises a competitor. |
| Nobody owns the decision | Sanctions authorities designate entities; they do not route traffic. No regulator is tasked with directing a carrier to disconnect a customer, so the action falls between institutions and rests on a voluntary commercial judgement by a company that has not itself been accused of anything. |
| The neutrality objection is genuine | Carriers making judgements about who deserves connectivity establishes that carriers can make such judgements, which is the precedent an authoritarian government wants. This is the same reasoning the RIPE community used to reject routing security as a sanctions instrument in 2022. It serves as convenient cover, and it is also a position held in good faith. |
The disincentives are not equally weighted. Most could be overcome by a determined carrier, but the first mover problem cannot be overcome by any carrier acting alone, because it is a property of the market rather than of the firm. Unilateral action is, from the carrier's own perspective, correctly identified as pointless: it costs real money and achieves relocation rather than removal. That is the finding with the clearest policy implication on this page, and it means that appeals to individual carriers to behave responsibly are aimed at the wrong unit of analysis. Analyst Inference
What would change the calculation
- Designate the carrier, not only the host. Converts a voluntary decision into a compliance obligation and removes the contract problem entirely. Politically significant, since it would set precedent affecting lawful European carriers.
- Coordinate across the realistic alternative set. Removes the first mover penalty and leaves the customer nowhere to relocate. This is the form the lever needs to take, and it requires a convening authority that does not currently exist.
- Create safe harbour for acting on verified evidence. Removes the asymmetry whereby acting carries more legal risk than not acting. The cheapest of the three, and the one that requires no new enforcement capacity.
The facilitator model
Spamhaus published its own formulation of this argument in June 2026, framing IP address brokers, network carriers, and datacenters as facilitators whose services are essential, difficult to obtain independently, and available from a finite number of sources. Its stated position is that pursuing individual bulletproof hosts without pursuing facilitators treats symptoms rather than causes. The mechanism Spamhaus describes is escalation of SBL listing against the facilitator's own network, combined with the observation that clustering bulletproof customers increases a facilitator's attractiveness to law enforcement. Reputational cost is a consequence of that approach rather than the stated lever. Confirmed
Leverage Points and Measurable Indicators
| Leverage point | Owner | Action | Assessed yield | Constraint |
|---|---|---|---|---|
| Coordinated upstream refusal | Transit carriers, prompted by regulators and industry bodies | Simultaneous termination by the realistic alternative carrier set, not one carrier alone | HIGH | Voluntary. No legal duty exists to compel it in the EU. |
| Registry policy reform | RIPE NCC membership | Extend deregistration triggers to sanctions designation, or tighten sponsoring LIR verification | HIGH | Requires community policy change against a stated neutrality position. |
| Registration integrity enforcement | RIPE NCC | Deregister resources obtained through falsified end-user agreements or corporate impersonation, using existing SSA powers | MEDIUM-HIGH | Already permitted under current policy. Requires detection capacity, not new rules. |
| Designating the enabler, not only the host | OFAC, EU Council, UK FCDO | Extend designations to upstream carriers and sponsoring LIRs with demonstrated repeat knowledge | HIGH | Politically significant. Would set precedent affecting lawful European carriers. |
| Formation agent verification | UK Companies House and equivalents | Extend identity verification to formation agents and beneficial owners | MEDIUM | Rollout began November 2025. Effect unmeasured. |
| Physical seizure | National law enforcement | Datacenter raids and asset seizure in cooperating jurisdictions | MEDIUM | Proven and repeatable, but degrades capacity without removing reachability. |
Indicators to track
- Upstream diversity per profiled ASN. Count of distinct transit providers announcing a BPH's prefixes. A count of one is a single point of failure; rising counts indicate the provider is hardening against the transit lever.
- Time from designation to first prefix reallocation. Currently measured in hours. Any lengthening would indicate registry or formation friction is taking effect.
- Share of a BPH's prefixes routed through EU, UK, or US jurisdictions. Determines whether the transit lever exists at all for that provider.
- Count of new LIR or ASN registrations sponsored by LIRs with prior abuse association. Direct measure of the sponsoring-LIR pathway.
- Documented voluntary upstream terminations per year. Currently near zero. This is the headline metric for whether the enablement layer is changing behaviour.
- Registry deregistrations executed for falsified registration data. Measures whether existing powers are being used.
Intelligence Gaps
PROTON66 transit is undocumented in open sources, and ZServers transit beyond Hostkey is unknown. Both require historical BGP analysis or network operator community records. Priority: HIGH, because the presence or absence of a Western upstream determines which disruption tool applies.
No published AMS-IX or DE-CIX policy on disconnecting designated entities has been identified, and no instance of an exchange doing so has been documented. Whether this reflects absence of policy or absence of reporting is unresolved.
Voluntary terminations are commercially sensitive and rarely announced. The DataCamp and Aeza case became public only because Aeza itself disclosed it. The true rate of upstream action is likely higher than the documented rate, by an unknown margin.
Rollout began 18 November 2025. No published assessment of whether it has slowed shell formation by these networks. Measurable from mid-2026 onward.
RIPE NCC stated in November 2021 that it would continue to investigate the possibility of a blanket exemption for internet number resources from EU sanctions regulation, after the Dutch Ministry of Foreign Affairs indicated there was no legal basis for one. If such an exemption were ever granted, the freeze mechanism weakens further. Status as of July 2026 not confirmed in this pass.
No published RIPE NCC position states whether a member under a sanctions freeze can still create or modify route origin authorisations. A 2020 board announcement described frozen members as unable to access RIPE NCC services, which would imply they cannot, but every transparency report since 2022 defines the freeze narrowly and never mentions the certification service. No one in the RIPE community appears to have asked. Low operational significance given the analysis in Section 04, but it is an open question that a direct request to RIPE NCC would settle.
This analysis is RIPE-weighted because the profiled providers are RIPE-region. ARIN and APNIC policy on sanctioned members has not been assessed to the same depth.