Netherlands (NL) Threat Intelligence

NL

Netherlands has 96,527 malicious IP addresses with 3,988,478 abuse reports. Top threat categories include ssh bruteforce, generic bruteforce, malware c2, web attack, mail bruteforce. Top attacking networks: DigitalOcean, LLC (37,807 IPs), DIGITALOCEAN-ASN (14,389 IPs), 1337 Services GmbH (3,584 IPs). Data collected since 2022-12-05, last activity 2026-04-16.

Threat Assessment: Netherlands shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are ssh bruteforce, generic bruteforce, malware c2. The majority of threats originate from networks operated by DigitalOcean, LLC and DIGITALOCEAN-ASN.

Total Reports
3,988,478
Unique IPs
96,527
First Seen
2022-12-05
Last Activity
2026-04-16

Top Threat Categories

Ssh Bruteforce 24,117
Generic Bruteforce 2,269
Malware C2 1,220
Web Attack 570
Mail Bruteforce 60

Top Attacking Networks

AS14061 DigitalOcean, LLC
37,807 IPs
AS14061 DIGITALOCEAN-ASN
14,389 IPs
AS210558 1337 Services GmbH
3,584 IPs

Most Reported IPs in Netherlands

45.148.10.240 1,984 reports
178.16.54.200 1,167 reports
45.148.10.121 1,111 reports
45.148.10.157 871 reports
45.148.10.151 826 reports

Access this data via API

Get Netherlands threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NL

View full API documentation

See how we classify and verify threats →

Check any IP from Netherlands

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS14061 Intelligence AS210558 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...