Summary

Artificial intelligence dominates the current cybersecurity debate. Deepfakes, synthetic identities and automated social engineering deserve that attention. But another structural change is receiving far less scrutiny: attackers are increasingly borrowing the trust attached to ordinary homes.

Residential proxy networks turn routers, televisions, streaming boxes, cameras, phones and other connected devices into exit points for traffic controlled by somebody else. The device may contain nothing the attacker wants to steal. Its value is the residential IP address, the normal-looking geography and the reputation of an innocent household.

I believe this will become one of the defining cybersecurity problems of the next decade. Not because botnets are new, but because compromised consumer devices are evolving from disposable attack tools into a persistent, commercial and globally distributed layer of infrastructure. We have created that infrastructure without deciding who is responsible for securing it.


Artificial intelligence dominates almost every cybersecurity discussion today. Governments are implementing new AI rules, researchers are studying deepfakes and synthetic identities, and organisations are preparing for phishing, fraud and social engineering at a scale that would previously have required far more people.

Those developments are real. They are also visible. We can point to the model, the generated image, the cloned voice or the automated message and recognise the new capability.

The change taking place inside ordinary homes is quieter.

A router still routes traffic. A television still streams video. A camera still records a driveway. Nothing obvious tells the owner that the same device, application or internet connection may also be carrying traffic for a criminal customer on another continent.

That is why I think the next major cybersecurity debate may not be about artificial intelligence alone. It may be about ownership.

Cybersecurity has entered a phase in which attackers do not always need to build suspicious infrastructure. They can borrow infrastructure that already looks legitimate. Society has not yet decided who is responsible when the borrowed trust belongs to a private household.

From compromised endpoints to commercial infrastructure

Botnets are not new. Infected personal computers were used for spam and distributed denial-of-service attacks long before the modern Internet of Things existed. Mirai demonstrated in 2016 how cameras and recorders protected by weak credentials could be assembled into a large attack platform.

The more important development today is not simply that connected devices can be compromised. It is that access to those devices and their internet connections can be packaged, resold and integrated into an ordinary-looking commercial service.

A residential proxy provider sells customers the ability to make traffic appear as though it originates from a household or small business. The customer may select a country, region or city. Behind the service sits a pool of consumer IP addresses obtained in several ways: malware, pre-installed backdoors, hidden software development kits, misleading VPN applications, bandwidth-sharing schemes or users who knowingly consent to sell spare capacity.

These categories matter legally and ethically, but they can look remarkably similar to the service being attacked. The destination often sees an IP address assigned by a familiar broadband provider and a request that appears to come from an ordinary home.

That changes the value of the compromised device. The attacker may have no interest in the photographs on a digital picture frame, the recordings stored by a camera or the programmes watched on a streaming box. The useful asset is the route through the household.

The device provides bandwidth, location and reputation. More importantly, it provides trust.

The scale is already difficult to dismiss

There is no reliable global census of residential proxy networks. Providers share capacity, resell access to one another and rebuild after disruptions. One device can appear under several brands, while one IP address may represent several devices behind the same router. Any single headline number should therefore be treated as an estimate, not a clean measurement of the market.

Even with that limitation, recent operations reveal infrastructure at a scale that should concern regulators and network defenders.

In 2024, US authorities disrupted 911 S5, a residential proxy service said to have compromised more than 19 million IP addresses across over 190 countries. Its customers used hijacked connections for fraud, cyberattacks and other crimes while the visible trail pointed back to victims whose devices had been enrolled in the network.1

In January 2026, Google disrupted IPIDEA, which it described as one of the world's largest residential proxy networks. Google said the action reduced the available device pool by millions. During one seven-day period, its researchers observed more than 550 tracked threat groups using IPIDEA exit nodes, including actors associated with cybercrime, espionage and information operations.2

In March, an international operation disrupted SocksEscort. According to the US Department of Justice and Europol, the service had offered access to approximately 369,000 IP addresses since 2020 and had compromised routers and connected devices across 163 countries. Around 8,000 infected routers were still listed for sale in February 2026.34

Then, in July, Google announced action against NetNut, another large residential proxy network. Google estimated that NetNut contained at least two million devices and observed 316 distinct threat clusters using suspected exit nodes during a single week in June. The company also described a market in which degraded operators buy capacity from competitors and reappear as resellers, making individual takedowns less final than they may initially seem.5

These figures are not a time series, and they do not prove a precise percentage increase from one year to the next. The ecosystem is too opaque for that. They do, however, establish three things.

First, residential proxy networks can reach millions of devices. Second, they are used by many different types of threat actor at the same time. Third, the market is interconnected enough that disrupting one operator does not necessarily remove the underlying capacity.

Google's own conclusion is unusually direct: the residential proxy industry appears to be rapidly expanding.25

What we are seeing from the other side

At WAYSCloud, we have seen a noticeable increase in coordinated abuse reaching our infrastructure through ordinary residential broadband rather than traditional hosting providers or obvious cloud infrastructure.

That observation does not identify who operated the connections. An IP address can reveal the network through which traffic arrived, but not who controlled the endpoint, whether the owner consented, or whether the route involved malware, proxyware or another intermediary. Attribution based on the visible exit address alone would be technically weak and potentially unfair.

The pattern is nevertheless significant for a provider trying to protect a service.

In a registration campaign against our Nordic email and collaboration platform, client-side observations, telephone verification and network geography pointed in different directions. The traffic reaching us came through ordinary German consumer broadband connections with no established history of abuse. The accounts were created, accessed briefly and then left dormant, consistent with the possibility that they were being aged before later use.

We published the technical details and the limits of what could responsibly be concluded in Your Connected Devices May Already Be Part of the Next Cyberattack.

The larger lesson was not that a particular German household had attacked us. We had no basis for saying that. The lesson was that identity, verification, geography and infrastructure had been separated into different layers. The visible residential connection was part of the camouflage, not a reliable description of the actor behind it.

Since then, the broader increase has become harder for us to ignore. We are not treating every residential address as malicious, and neither should anyone else. Most residential traffic is legitimate. The problem is that the old distinction between suspicious infrastructure and trusted consumer infrastructure is losing some of its value.

For a defender, an attacker no longer has to disappear. It may be enough to look normal.

Attackers are borrowing accumulated trust

Internet security systems have spent years building reputation models. A newly created server in a hosting network, an address range associated with automated abuse or infrastructure that changes repeatedly can be assigned more risk. A stable residential address belonging to a well-known internet service provider has historically carried a different prior probability.

That distinction remains useful. It is simply no longer sufficient.

Residential proxy networks allow an attacker to consume reputation accumulated by somebody else. The household paid the broadband bill, used the connection normally and kept the address free of abuse. The ISP operated the network. The destination service learned over time that traffic from similar connections was usually legitimate.

The attacker borrows all of that context for the price of a proxy session.

This is why the change is deeper than another generation of botnets. A classic botnet is often discussed in terms of compute, bandwidth or attack volume. A residential proxy network monetises legitimacy. Its product is not merely access to a machine. Its product is the ability to appear local, ordinary and previously unknown to defensive systems.

For financial fraud, that may mean logging in from the victim's city. For account creation, it may mean distributing registrations over thousands of unrelated consumer networks. For espionage, it may mean concealing access behind infrastructure that does not resemble a foreign operation. For password attacks, it may mean rotating through addresses quickly enough to weaken per-IP controls.

The FBI now describes residential proxies as a standard tool used for fake-account creation, phishing, account takeover, brute force attacks, command-and-control concealment and data exfiltration.6

The old Internet security question was whether an address had a bad reputation. The modern question is whether the complete sequence of identity, device, timing, verification and account behaviour makes sense for a legitimate user.

Why artificial intelligence makes the infrastructure more valuable

Artificial intelligence is not required to create a residential proxy network, and it would be careless to attribute the growth of these networks to AI alone. The commercial and criminal incentives existed long before the current generation of language models.

AI does, however, increase the value of distributed trusted infrastructure.

Automation can already create accounts, rotate sessions and vary timing. More capable models can help generate plausible identities, adapt language and behaviour to local context, interpret defensive responses and coordinate campaigns in which no individual event appears extraordinary.

A million residential exit points are useful when the operation behind them is crude. They become more useful when the software controlling them can vary its behaviour, learn which actions trigger intervention and maintain consistency across identities over time.

This creates a reinforcing relationship. AI makes abuse easier to personalise and scale. Residential infrastructure makes that abuse appear geographically and technically ordinary.

Public policy has begun to address the first half of that equation. Europe has debated synthetic media, transparency and high-risk AI systems in detail. The physical and software supply chain inside millions of homes has received less political attention, even though it can provide the delivery infrastructure for the very manipulation, fraud and intrusion campaigns that AI makes cheaper.

The point is not that society should pay less attention to AI. It is that digital trust can fail at more than one layer.

The Internet has an ownership problem

When a compromised home router is used in an attack against a hospital, bank, government agency or cloud provider, who failed?

The emotionally satisfying answer is often the consumer. Someone used a weak password, bought an inexpensive device or failed to install an update.

That answer does not survive contact with the actual consumer technology market.

Many users cannot tell whether a device receives firmware updates, how long support will continue or whether the software was already modified before purchase. Some devices have no usable update interface. Others depend on applications or cloud services that disappear while the hardware remains operational. Even technically competent consumers have limited visibility into ISP-supplied routers and closed embedded systems.

Ownership of the device does not imply meaningful control over its security.

Manufacturers are closer to the root of the problem. They choose components, default settings, update mechanisms and support periods. They also face strong incentives to minimise hardware cost, shorten development cycles and move engineering resources to the next product. The household may use a television, camera or router for ten years, while the commercial relationship that funded its software maintenance ended at the checkout.

Internet service providers occupy a more complicated position. They may supply and remotely manage the router, control access-network infrastructure and observe anomalies across a scale unavailable to the homeowner. They are therefore well placed to identify some forms of compromise and notify customers.

But an ISP is not automatically entitled to inspect everything passing through a household. Detection has to respect privacy, confidentiality of communications, proportionality and network-neutrality rules. Encrypted traffic further limits what can be inferred from content, leaving metadata and behavioural patterns that can be useful but are rarely conclusive on their own.

Cloud and online service providers see the attack at its destination. They can correlate accounts, devices, verification events and behaviour, but they usually cannot remediate the compromised television or router that supplied the exit address. Blocking the household may reduce abuse while also excluding innocent users. Accepting the traffic may expose the service and its customers.

Law enforcement can pursue criminal operators and seize infrastructure, but enforcement is episodic and international. The underlying devices remain distributed across jurisdictions and private homes. As the NetNut case illustrates, capacity can be resold and recombined after an individual network is disrupted.5

Every participant owns part of the problem. Nobody owns the outcome.

Europe has started regulating the product, not the whole chain

The European Union's Cyber Resilience Act is an important correction to the idea that software responsibility ends when a product is sold. It imposes horizontal cybersecurity requirements on products with digital elements and places obligations on manufacturers, importers and distributors.7

Manufacturers must design and maintain products with cybersecurity in mind, handle vulnerabilities and provide security updates during a defined support period. As a general rule, that support period must be at least five years unless the product is expected to be used for less time; for products expected to remain in use longer, the period should reflect that expected lifetime.8

The Act's vulnerability and severe-incident reporting obligations begin on 11 September 2026, while its main obligations apply from 11 December 2027. Compliance is enforced through national market-surveillance authorities, with CE marking used to indicate conformity.79

That is meaningful progress. It gives manufacturers a clearer duty of care and gives regulators a route to act against insecure products entering the European market.

It does not, by itself, solve the installed-base problem.

Millions of devices already in homes will never be redesigned under the new rules. Some will be unsupported before the main obligations apply. Others were purchased through supply chains that make the responsible economic operator difficult to identify. A secure product can also become part of a proxy network through a deceptive application or SDK installed later.

The legal framework is fragmented in the same way as the technical system.

The Cyber Resilience Act addresses product security and places the primary compliance burden on economic operators. NIS2 requires covered organisations, including providers of public electronic communications networks and many cloud services, to manage cybersecurity risks to their own network and information systems and report significant incidents.10 Data-protection and communications-privacy law constrain how providers monitor individuals. National market-surveillance authorities, cybersecurity authorities, data-protection authorities, telecom regulators, CSIRTs and law-enforcement agencies each see a different part of the chain.

There is no single European authority whose simple mandate is: prevent consumer devices from becoming infrastructure for attacks against unrelated third parties.

That may be the governance gap.

Regulation should follow capability, not convenient blame

The fact that responsibility is shared does not mean it should be distributed equally.

The consumer has the least information and often the least practical ability to intervene. Regulation should therefore resist the temptation to turn security into another unread warning or contractual clause. Consent hidden in terms of service is not meaningful control over a residential proxy exit node.

Manufacturers should carry the clearest responsibility for secure defaults, transparent support periods, vulnerability handling and update mechanisms that work without specialist knowledge. Connected products whose safe operation depends on a cloud service should disclose what happens when that service ends.

App stores and platform operators are well placed to identify applications and SDKs that secretly monetise bandwidth. Google's IPIDEA and NetNut actions show that platform-level enforcement can remove software and disrupt command infrastructure at a scale no household could achieve.25

ISPs should not become indiscriminate surveillance operators. They should, however, have clear legal authority and practical procedures for detecting strong network-level indicators of compromised customer equipment, notifying the subscriber, isolating known malicious control infrastructure where lawful, and helping replace or remediate ISP-managed devices. The boundary between useful network defence and intrusive monitoring must be explicit rather than left to informal risk tolerance.

Cloud providers and online services must assume that residential origin is a weak signal, not a guarantee of legitimacy. That means moving from simple address reputation towards layered detection based on account lifecycle, device continuity, verification patterns, timing and relationships across events. It also means giving users a way to recover when their household address has been tainted by activity they did not cause.

Regulators need a mechanism for the whole chain, not only its individual products. Market surveillance can remove a non-compliant camera from sale. It cannot necessarily tell an ISP that thousands of deployed cameras are contacting known proxy infrastructure, coordinate notification to owners and ensure that downstream services stop treating the affected households as criminals.

The next step should therefore be operational coordination between product-security authorities, telecom regulators, CSIRTs, platform providers, ISPs and cloud services. Shared indicators, privacy-preserving aggregate detection and defined remediation channels will matter as much as another label on the box.

The cost is paid by someone else

One reason this problem has remained underestimated is that the party making the insecure decision may not bear most of the loss.

A manufacturer saves money by shortening support. A developer earns revenue by embedding a bandwidth SDK. A proxy operator sells the resulting capacity. A criminal buys access. The household pays for the connection and may suffer degraded performance, investigation or blocking. The organisation attacked through that connection bears the fraud, incident response and service-abuse cost.

The externality crosses both industries and borders.

A cheap streaming box sold in one country can become an exit node used by an actor in a second country to attack a service in a third. No bilateral customer relationship connects the manufacturer to the eventual victim. Traditional consumer-protection logic therefore captures only part of the harm.

This is why connected-device security should be treated as digital resilience, not merely personal privacy.

The camera can expose its owner. The same camera can also provide infrastructure for an attack against somebody the owner has never met. Those are different harms, and the second one is much harder for a market based on individual purchasing decisions to price correctly.

A prediction worth placing on the record

I believe historians of cybersecurity may eventually describe the 2020s as the decade in which consumer devices stopped being treated merely as endpoints and became a recognised layer of attack infrastructure.

The shift will not happen on a single date. It is already visible in fragments: nineteen million IP addresses in one disrupted service, millions of devices removed from another, hundreds of threat groups using the same proxy ecosystem in a week, and providers such as ours seeing more abuse arrive through networks that look like ordinary homes.

The decisive change is not the number of compromised routers. It is the industrialisation of the trust attached to them.

For two decades, defenders learned to distrust unfamiliar servers. The next decade may require us to question activity arriving through familiar homes without treating the families inside them as suspects.

That is technically difficult. It is legally fragmented. It is politically uncomfortable.

It is also unavoidable.

We often describe cybercrime as an attack against infrastructure. Increasingly, it is an attack through infrastructure that belongs to ordinary people.

Once trust itself becomes something attackers can rent, cybersecurity stops being only a contest between attackers and defenders. It becomes a question of product design, market incentives, communications privacy, platform governance and public responsibility.

The question is no longer whether a router, television or camera can become part of an attack. Law-enforcement operations and threat-intelligence research have already answered that.

The question is who will be responsible for preventing it at scale.

About the observations

The WAYSCloud observations described here concern abuse patterns visible from infrastructure operated by WAYSCloud and its Nordic email and collaboration services. Network origin alone cannot establish whether an endpoint was compromised, knowingly enrolled in a proxy service or used through another intermediary. No claim is made that every residential address observed was a compromised household device.

A public account of the original registration campaign is available in the WAYSCloud Trust Center. Relevant authorities were notified before the earlier publication.

Sources

  1. FBI: The 911 S5 Cyber Threat
  2. Google Threat Intelligence Group: Disrupting the World's Largest Residential Proxy Network
  3. US Department of Justice: Authorities Dismantle Global Malicious Proxy Service
  4. Europol: International Partners Disrupt SocksEscort Proxy Service
  5. Google Threat Intelligence Group: Continued Disruption of Malicious Residential Proxy Networks
  6. FBI: Evading Residential Proxy Networks
  7. European Commission: Cyber Resilience Act
  8. EUR-Lex: Regulation (EU) 2024/2847, Cyber Resilience Act
  9. European Commission: Cyber Resilience Act Reporting Obligations
  10. EUR-Lex: Directive (EU) 2022/2555, NIS2