NetNut is reportedly offline after a law-enforcement seizure tied to the alleged "Popa" botnet. Here is what to check when choosing a proxy provider — and where NinjaProxy stands, using only claims you can verify.

NetNut, one of the more established residential-proxy networks, is currently unavailable to buyers. In early July 2026, Google, the FBI, Lumen, and Shadowserver reportedly seized several NetNut-associated domains in an action tied to the alleged "Popa" residential-proxy botnet — and as of August 3, 2026, netnut.io still displays a law-enforcement seizure banner. NetNut's parent, Alarum Technologies (NASDAQ: ALAR), has reportedly begun implementing cost-reduction measures expected to affect around a third of its workforce — a mix of employees facing possible termination through a hearing process and others placed on unpaid leave — over the same period, and has seen its share price fall sharply, and several law firms have announced securities-fraud investigations on behalf of ALAR shareholders. (See sources below.)
We are not going to pile on. If you relied on NetNut, the useful question isn't "who's cheapest" — it's "how do I choose a provider I can actually trust with my traffic?" The seizure put one question at the center of the buying conversation: *where do a network's IPs actually come from, and is that network legitimate?* This page walks through what to check, then shows — using only statements you can verify on this same website — where NinjaProxy stands. We would rather be candid about what we do and don't publish than overclaim.
Evaluate any provider — including us — against criteria you can verify yourself, not marketing adjectives.
Only statements you can verify on this site. We have deliberately left out anything we can't back up.
We publish an ethical residential-proxy sourcing standards explainer, and we will walk you through how our network is sourced in detail on request via our contact form. We also say openly, in that same explainer, that "ask us directly" is not the same as "published on our website," and that we are working to make it more transparent. We would rather tell you exactly where we are than dress it up. What we do commit to in writing: we do not route traffic that would constitute illegal activity, attacks on systems or infrastructure, bulk credential testing, or content that exposes end users to harm — and those prohibitions are enforced at the network level. As stated in that explainer, NinjaProxy has no public legal actions, DMCA litigation, or law-enforcement matters related to our IP network.
Our Acceptable Use Policy is public and specific. We aim to acknowledge abuse reports within 24 hours, complete an initial investigation within 72 hours, and take action or close the report within 7 days. High-severity abuse — explicitly including botnet routing, malware command-and-control, active attacks, credential stuffing at scale, and urgent law-enforcement matters — is escalated for priority response. The policy names prohibited uses, maintains a repeat-infringer policy on a rolling 12-month window, and states that large-scale data collection violating GDPR, CCPA, or other data-protection law is prohibited. Abuse, DMCA, and law-enforcement reports have a real channel: the NinjaProxy contact form.
Our capabilities matrix is, in its own words, "sourced from the live product, not marketing copy," and we deliberately do not publish unaudited pool-size figures like "millions of IPs" — exact pool composition for your account is shown in the customer portal instead. Our metrics methodology publishes the *measurement method first* and refuses to collapse availability into a single vanity uptime number. If a figure can't be measured from the live system, we name the missing data feed rather than estimate it.
Our status page shows component-level health with 90-day history, auto-refreshes every 30 seconds, and lets you subscribe to incident notifications by email. It is a live feed, not a static badge.
NinjaProxy is operated by IPNinjas LLC, a US entity, with public Terms of Service and a Privacy & Cookie Policy.
We do not hold a third-party security certification, and we won't imply one. We are not going to tell you our network is "GDPR/CCPA compliant" as a marketing slogan — compliance depends on your use case as much as our controls. If audited compliance or a signed DPA is a hard procurement requirement for you, tell us through the contact form and we'll be straight about what we can and can't provide today.
Reported facts only, as of August 3, 2026. Cells are left blank where we have no sourced fact rather than filled with speculation.
| What you can check | NinjaProxy | NetNut (reported) |
|---|---|---|
| Current service availability | Live public status page, component-level, 90-day history | Reported offline; netnut.io still shows a law-enforcement seizure banner |
| Network legitimacy in the news | No public law-enforcement matters against our IP network (our stated position) | Domains reportedly seized in an action tied to the alleged "Popa" residential-proxy botnet |
| Published abuse-response policy | Public AUP: 24h acknowledge / 72h initial investigation / 7d action; botnet routing explicitly escalated | — |
| Corporate standing | Operated by IPNinjas LLC (US) | Parent Alarum (NASDAQ: ALAR) reportedly implementing cost-reduction measures affecting ~1/3 of workforce (hearing-process terminations + unpaid leave); securities-fraud investigations announced |
| Metrics posture | Publishes methodology; declines unaudited pool-size and uptime figures | — |
| Proxy types offered | ISP / static residential, datacenter, and 4G/5G mobile | — |
There is no fabricated scoreboard here on purpose. The point isn't that we "win" a spec race — it's that every claim in the NinjaProxy column links to something you can read for yourself.
Moving off NetNut doesn't have to be disruptive. In most setups a switch is a configuration change, not a rewrite — you point your existing tooling at a new gateway and carry your session settings across.
No annual contract, no lock-in. NinjaProxy plans are month-to-month — there is no annual commitment and no enforced minimum spend, so you can cancel anytime if it isn't the right fit. That's deliberate: a provider you can leave easily is one that has to keep earning your traffic. See the current pricing plans for ISP, residential, datacenter, and mobile options.
NetNut is reportedly offline: as of August 3, 2026, netnut.io still displays a law-enforcement seizure banner following an action that reportedly seized several NetNut-associated domains in early July 2026. Because the situation is active and the details are still emerging, the practical answer for most buyers is that NetNut isn't currently a service you can rely on. Evaluate any replacement on verifiable trust criteria, not just price.
Per public reporting, in early July 2026 Google, the FBI, Lumen, and Shadowserver seized several NetNut-associated domains in an action tied to the alleged "Popa" residential-proxy botnet. NetNut's parent company, Alarum Technologies (NASDAQ: ALAR), has reportedly begun implementing cost-reduction measures expected to affect around a third of its workforce — a mix of employees facing possible termination through a hearing process and others placed on unpaid leave; its share price has fallen sharply, and several law firms have announced securities-fraud investigations on behalf of shareholders. These are reported/alleged facts — see the linked sources for the primary coverage.
The best alternative is the provider whose trust posture you can actually verify. NinjaProxy publishes a specific acceptable-use and abuse-response policy (24h/72h/7d timeframes, with botnet routing explicitly escalated), a live status page, a capabilities matrix "sourced from the live product," and a metrics methodology that declines unaudited vanity numbers — and it's operated by an identifiable US entity, IPNinjas LLC. Start a free trial and check each of those claims yourself.
Ask the provider directly how its residential and ISP addresses are sourced and whether device owners consented. Read its acceptable-use policy for whether botnet or compromised-device routing is prohibited and how abuse reports are handled. Confirm any audit or certification by asking for the certificate itself, and be skeptical of unaudited "millions of IPs" or "99.99% uptime" figures you can't independently check.
*Reporting reflects publicly available coverage as of August 3, 2026. NetNut and Alarum statements are described as reported or alleged; nothing here should be read as a factual assertion beyond what those sources support.*