Launch pricing: every plan costs 30% less than the cheapest offshore competitor we track. See the benchmarkEvery plan 30% under the cheapest offshore host

Law & jurisdictions

Offshore vs bulletproof hosting: why the difference matters

Offshore hosting and bulletproof hosting are often confused. One chooses a legal system; the other sells protection from all of them. In 2026 that difference decides who gets sanctioned and seized.

7 min readBy the OffshoreServ team

Key takeaways

  • US and allied agencies define a bulletproof host as one that knowingly leases infrastructure to cybercriminals. Geography has nothing to do with it.
  • 2025 and 2026 brought sanctions against Zservers, Stark Industries, Aeza and Media Land, and Dutch seizures of hundreds of servers.
  • When a bulletproof host is seized, every customer goes offline, whatever they were doing.
  • Networks that host abuse end up on blocklists that other networks use to drop traffic.
  • A principled offshore host publishes what it never tolerates and how it handles court orders from its own jurisdiction.
On this page
  1. Two different businesses
  2. 2025 and 2026: the crackdown in dates
  3. Why legitimate users should stay away
  4. No KYC is not the same as bulletproof
  5. How to spot a bulletproof host before you pay
  6. What a principled offshore host looks like
  7. How OffshoreServ draws the line

Offshore hosting means running servers in a jurisdiction chosen for its laws, and following those laws. Bulletproof hosting means knowingly renting infrastructure to criminals and resisting abuse reports and law enforcement. The first is legal and useful. The second is now a target for sanctions, seizures and blocklists, and it takes innocent customers down with it.

The two are often marketed with the same words, "offshore", "no KYC", "DMCA ignored". This article explains how to tell them apart, what happened to bulletproof hosts in 2025 and 2026, and why legitimate users should stay well away from them.

Two different businesses

The US Cybersecurity and Infrastructure Security Agency, with the NSA, the FBI and international partners, published joint guidance on 19 November 2025 that states it plainly: "A BPH provider is an internet infrastructure provider that knowingly leases infrastructure to cybercriminals." The US Treasury describes the same providers as selling servers designed to help cybercriminals "evade detection and resist law enforcement attempts to disrupt their malicious activities".

Offshore hosting is something else: hosting in a country other than your own, chosen for its legal framework, its privacy law, its courts or its location. An offshore host still answers to the law where its servers run. It simply is not subject to the law of every country its customers or complainants come from.

The difference is behavior, not geography. The Russia-based bulletproof host Zservers had servers in Amsterdam, where Dutch police seized them. CyberBunker, a widely reported case, ran from a former NATO bunker in Germany until a 2019 raid; in December 2021 a court in Trier convicted eight defendants of forming or belonging to a criminal organization.

Offshore hostBulletproof host
Relationship with the lawFollows the law of the server's countryBuilt to evade or resist enforcement
Abuse reportsHandled; malware, spam, phishing and child abuse material removedIgnored, or sold as a feature
Court orders from the server's countryComplied with; customer informed where allowedResisted; infrastructure moved or rebranded
Typical customersPrivacy-minded businesses, publishers, developersRansomware, phishing, botnet and fraud operators
IP reputationKept clean by acting on abuseListed and filtered by other networks
Main risk for customersA court order in the server's countrySanctions, seizures, sudden shutdowns

2025 and 2026: the crackdown in dates

DateWhat happened
11 to 12 February 2025The US, the UK and Australia sanctioned Zservers for supporting LockBit ransomware affiliates. The next day, Dutch police took down 127 of its servers in Amsterdam.
20 May 2025The EU sanctioned Stark Industries Solutions and its owners, Iurie and Ivan Neculiti, for enabling Russian state-linked information manipulation and cyberattacks.
1 July 2025The US Treasury's OFAC designated Aeza Group, three affiliated companies and four individuals for hosting infostealer panels, ransomware infrastructure and a darknet drug market.
12 November 2025Dutch police seized about 250 physical servers of a no-KYC VPS and RDP service linked to more than 80 investigations, taking thousands of virtual servers offline.
19 November 2025The US, the UK and Australia sanctioned Media Land and the companies Aeza had set up to evade its designation. The same day, CISA and partners published their bulletproof hosting guide.
18 May 2026The Dutch fiscal investigation service FIOD arrested two people and seized more than 800 servers in a case about indirect support to EU-sanctioned entities, including infrastructure moved from Stark Industries to a new brand.

Two patterns stand out. Enforcement now uses sanctions law, not only cybercrime law, which reaches anyone who pays or supplies a designated company. And rebranding does not reset the clock: the entities Aeza created after July 2025 were sanctioned in November, and the infrastructure Stark moved to a new brand was seized a year after the original designation.

Why legitimate users should stay away

A seizure takes everyone offline

Police do not seize "the bad customers". They seize the servers, the storage and often the whole data-center footprint of the provider. In the November 2025 Dutch operation, thousands of virtual servers went dark at once, whatever their owners were running. Seized hardware becomes evidence, and whatever was stored on it is in the hands of investigators. There is no warning and usually no way to retrieve your data.

Blocklists do not distinguish

Spamhaus's DROP list covers netblocks "leased or stolen by professional spam or cyber-crime operations" and advises networks to drop all traffic from them. The joint CISA guidance asks internet providers to build lists of bulletproof infrastructure and filter it. If your server sits in a range that ends up on such lists, your email bounces, your website fails to load for some visitors and your API calls time out, even though you did nothing wrong.

Paying a sanctioned host can be illegal

An OFAC designation blocks the company's property and generally prohibits US persons from dealing with it; EU sanctions prohibit making funds available to listed companies and people. Paying in crypto does not change the rule. A cheap server from a designated provider can become a legal problem for your business, not only a technical one.

The operator's incentives are not yours

A business that earns its money from ransomware crews and phishing kits has no reason to protect ordinary customers, keep networks clean or tell you when it is about to move, rebrand or be raided. The "protection" it sells is aimed at its criminal customers, and it disappears the day enforcement arrives.

No KYC is not the same as bulletproof

The service Dutch police took down in November 2025 advertised no-KYC and no-logs policies. That does not make privacy the problem. Paying without handing over identity documents is a legitimate choice, and many honest customers make it for good reasons: to keep their name out of one more database, to protect a publication, or simply because a server does not need a passport. That is the model of our no-KYC VPS and anonymous VPS: an email address and a password, and an acceptable use policy that is enforced.

What turns a host into a bulletproof host is what it tolerates, not what it asks at signup. A privacy-first host can skip identity checks and still act fast on what a server does: phishing pages, malware, spam, attacks. It judges behavior on its network, which it can see and verify, rather than paperwork, which criminals fake anyway. The danger is the combination of no identity checks and no abuse handling, because that combination attracts exactly the customers who bring raids.

How to spot a bulletproof host before you pay

  • Read what it promises. "Spam allowed", "botnets OK", "we ignore all abuse" or "safe from law enforcement" are descriptions of a bulletproof business, whatever the rest of the site says.
  • Check where it advertises. Hosts that recruit customers on cybercrime forums know who those customers are.
  • Look up the IP range. Before you commit, check the provider's announced ranges against public blocklists, or test a small server first. A range already listed for spam or malware will not get cleaner with you on it.
  • Follow the corporate trail. Frequent rebrands, new companies with the same staff and the same network, or owners on a sanctions list are all warning signs.
  • Ask a direct question. Send the sales team a hypothetical: what happens if a phishing page is reported on my server? A principled host answers with a process. A bulletproof one answers with a wink.

What a principled offshore host looks like

  • Honest about the law. It names its jurisdictions and explains what can still happen in each, including court orders and, in the EU, the Digital Services Act.
  • Clear about what it never tolerates. Child sexual abuse material, malware, botnets, phishing, spam and fraud are listed and removed quickly.
  • A working abuse channel. Reports of real abuse get a response and an outcome.
  • A written process for local orders. Customers are informed and can respond before action, unless a court forbids it.
  • Verifiable transparency. A transparency report and a signed warrant canary, kept up to date.
  • No immunity marketing. No "bulletproof", no "untouchable", no "anything goes".
  • Clean supply chain. No sanctioned owners, upstreams or partners.

How OffshoreServ draws the line

We are an offshore, privacy-first host, and we never describe our service as bulletproof. Our acceptable use policy has zero tolerance, with immediate action and no due-process delay, for child sexual abuse material (reported to the competent authorities), malware, botnet command-and-control, stealers, ransomware panels and exploit kits, spam and phishing, attacks from our network, and fraud against real people. Outbound SMTP on port 25 is closed by default and opened on request from the client area, which helps keep our IP ranges off spam blocklists.

For everything else, we follow the law where the server runs. US DMCA notices are answered, not enforced, as our DMCA policy explains and our guide to DMCA-ignored hosting covers in depth. A valid court order from the server's jurisdiction, or a notice that meets EU DSA requirements in our EU locations, can require action, and we inform the customer first unless a court forbids it. Requests and outcomes appear in our quarterly transparency report, and our warrant canary is PGP-signed and renewed every quarter.

That is the difference in one sentence: offshore hosting is a choice of law, not an exemption from it. If you want the broader picture of what offshore hosting can and cannot do for you, start with why offshore hosting.

Host it where the law is on your side.

Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions. No KYC, paid in crypto.

Welcome back

Sign in to manage your servers and your balance.

No KYCHuman check by Cloudflare TurnstileNo tracking