Netherlands (NL) Threat Intelligence

NL

Netherlands has 146,140 malicious IP addresses with 5,829,765 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: DigitalOcean, LLC (48,661 IPs), Google LLC (6,758 IPs), 1337 Services GmbH (5,890 IPs). Data collected since 2022-12-05, last activity 2026-08-15.

Threat Assessment: Netherlands is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by DigitalOcean, LLC and Google LLC.

Total Reports
5,829,765
Unique IPs
146,140
First Seen
2022-12-05
Last Activity
2026-08-15

Top Threat Categories

Suspicious Activity 55,837
Severe Abuse 41,578
Ssh Bruteforce 33,193
Moderate Threat 4,856
High Threat 3,686

Top Attacking Networks

AS14061 DigitalOcean, LLC
48,661 IPs
AS396982 Google LLC
6,758 IPs
AS210558 1337 Services GmbH
5,890 IPs

Most Reported IPs in Netherlands

45.148.10.141 1,415 reports
45.148.10.152 1,406 reports
45.148.10.157 1,399 reports
45.148.10.151 1,368 reports
45.148.10.147 1,363 reports

Access this data via API

Get Netherlands threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NL

View full API documentation

See how we classify and verify threats →

Check any IP from Netherlands

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS396982 Intelligence AS210558 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...