Law enforcement and tech firms have taken down a sprawling network hijacking over 2 million devices, exposing widespread risks in consumer electronics and home internet security.
In early July 2026, the FBI and Google moved against a sprawling residential proxy network that had quietly enlisted more than 2 million devices, including smart TVs and streaming boxes, according to reporting by KrebsOnSecurity and technical summaries from Google-linked security partners. The operation disrupted a system known as Popa, which investigators say was used to disguise internet traffic behind ordinary home connections and support cybercrime, fraud and espionage activity.
The network sat behind a service called NetNut, which security journalist Brian Krebs linked to Alarum Technologies, a publicly traded Israeli company. According to the reporting, law-enforcement officers seized hundreds of internet domains tied to the service on 2 July and 3 July, while Google and other security teams helped disable infrastructure connected to the botnet.
For consumers, the troubling part is that many infected devices showed no obvious signs of compromise. Investigators said some devices were compromised before sale, particularly low-cost Android-based boxes and streaming sticks. Other cases involved free apps that concealed proxy functions inside software development kits, making the application appear harmless while quietly using the owner’s broadband connection for someone else’s traffic.
Google said the abuse ranged from advertising fraud to large-scale web scraping and account takeovers. In one week in June, the company said it observed 316 different attacker groups using related infrastructure, including espionage actors. Infoblox has separately estimated that proxy services can generate about 500 billion requests a month, underscoring how large and profitable the market has become.
The risk was not limited to no-name imports. According to Spur, a security company that analysed more than 6,000 LG and Samsung apps, a substantial share contained hidden proxy-related code. The company said the figure reached around 42% on LG TVs running webOS and more than a quarter on Samsung’s Tizen platform. That suggests even devices bought through official channels can be exposed if users install the wrong app.
There is no perfect home test for compromise, but several warning signs can help. A television or box that runs hot, slows down unexpectedly or consumes unusual amounts of data may warrant attention, especially if unfamiliar VPN, screensaver or PDF apps appear. A router showing unexplained outbound traffic is another red flag, as is a warning from an internet provider. Security specialists recommend sticking to official app stores, avoiding offers that pay users for sharing bandwidth and choosing reputable, Play Protect-certified devices where possible. A factory reset may help, though it is not a guarantee.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





