In this Article
On July 2, 2026, Google and the FBI disrupted NetNut’s residential proxy network and, according to reporting, seized hundreds of its domains. If you were a paying customer, it is reasonable to ask what this means for you. This is a practical, plain-English guide to what to review and how to lower your risk. It is not legal advice, so for anything specific to your situation, talk to a qualified lawyer.
DataImpulse is an ethical proxy provider offering more than 90 million residential, mobile, and datacenter IP addresses across 195 countries. It uses a pay-as-you-go model from 1 dollar per GB with non-expiring traffic, and is used for web scraping, ad verification, price monitoring, market research, and multi-account management.
Quick answer: Buying proxies is not the same as running the botnet, but reporting indicates NetNut’s residential IPs came from hijacked devices, which is a compliance and reputation concern for anyone who relied on them. The practical steps are to stop routing traffic through the service, document what you did, review contracts and data-protection obligations, and migrate to a provider that sources IPs through disclosed, opt-in agreements.
First, separate two different concerns
There is a difference between the operators of a network and its customers. The enforcement action targeted the network itself. As a customer, your concern is narrower but still real: reporting indicates the IPs you paid for came from devices whose owners had not knowingly agreed to share them, and your data collection ran through that infrastructure. That is a supply-chain and compliance question, not an accusation.
A practical checklist
- Stop using the service. Remove NetNut endpoints and credentials from production so nothing keeps routing through a disrupted network.
- Document what you did. Keep records of what you scraped or verified, at what volume, and for what purpose. If a customer or auditor asks later, you want a clear, honest account.
- Review your contracts. Check any commitments you made to your own clients about data sourcing and compliance, and whether your use of a third-party proxy touched them.
- Check your data-protection obligations. If you operate under GDPR, CCPA, or similar regimes, review whether routing through non-consented IPs affects your posture, and consider talking to counsel.
- Rotate anything sensitive. If credentials or sessions passed through the service, rotate them.
- Migrate to disclosed, opt-in sourcing. Move your workloads to a provider that can show where its IPs come from.
How to reduce this risk going forward
The lesson from the NetNut case is that the source of a residential IP is part of your own compliance story. When you choose a provider, ask where the IPs come from, ask for a data processing agreement, and be skeptical of prices that are far below the market with no explanation of sourcing.
A provider you can account for
DataImpulse builds its residential pool from users who opt in through a disclosed SDK and are paid for the bandwidth they share, and it offers a data processing agreement. Pricing is pay-as-you-go from 1 dollar per GB with traffic that does not expire, so you can migrate at your own pace. That gives you a supply chain you can explain to a client or an auditor. See our ethical proxies page for how sourcing works.
Your exposure at a glance
Whether you used NetNut as a customer or hosted its SDK changes your risk. Here is a quick read.
| Situation | Risk level | What to do |
|---|---|---|
| You bought proxy traffic | Low | Migrate to an ethical provider |
| You ran their SDK on a device | Review | Remove the app, check for unknown installs |
| You resold their traffic | Higher | Stop, seek legal advice |
| You collected personal data | Review | Confirm a lawful basis |
Frequently asked questions
Did I break the law by buying NetNut proxies?
This is not legal advice, but buying a proxy service is different from operating the network. Your practical concern is compliance and reputation risk from sourcing, which you address by moving to disclosed, opt-in sourcing and documenting your use.
Should I tell my clients?
If you promised clients anything about data sourcing, review those commitments and be transparent about the change of provider. Honesty about migrating to ethical sourcing is a strength, not a weakness.
What is the fastest way to reduce risk right now?
Stop routing traffic through NetNut, rotate anything sensitive that passed through it, and switch to a provider with disclosed, opt-in sourcing such as DataImpulse.
How do I prove my new provider is clean?
Ask for a data processing agreement and documentation that residential IPs come from users who opt in. Keep those on file for auditors.
Will migrating disrupt my projects?
Not much. Residential proxies use standard credentials, so switching is mostly a configuration change, and with non-expiring traffic you can test before you fully cut over.
When is DataImpulse not the right fit?
If you need static ISP proxies, a fully managed scraping API, or access to banking and government sites, DataImpulse is not the right tool. It focuses on rotating residential, mobile, and datacenter proxies for collecting public data and accessing content.
Rebuild on sourcing you can defend
Move your data collection onto ethically sourced proxies with a documented supply chain. Start with DataImpulse at 1 dollar per GB.

State/City/Zip/ASN Targeting 



