Netherlands (NL) Threat Intelligence

NL

Netherlands has 152,897 malicious IP addresses with 6,235,335 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, tcp scan, moderate threat. Top attacking networks: DigitalOcean, LLC (49,800 IPs), Google LLC (7,097 IPs), 1337 Services GmbH (5,890 IPs). Data collected since 2022-12-05, last activity 2026-09-06.

Threat Assessment: Netherlands is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by DigitalOcean, LLC and Google LLC.

Total Reports
6,235,335
Unique IPs
152,897
First Seen
2022-12-05
Last Activity
2026-09-06

Top Threat Categories

Suspicious Activity 55,837
Severe Abuse 41,578
Ssh Bruteforce 34,932
Tcp Scan 15,159
Moderate Threat 4,856

Top Attacking Networks

AS14061 DigitalOcean, LLC
49,800 IPs
AS396982 Google LLC
7,097 IPs
AS210558 1337 Services GmbH
5,890 IPs

Most Reported IPs in Netherlands

45.148.10.152 1,671 reports
45.148.10.141 1,670 reports
45.148.10.157 1,658 reports
45.148.10.151 1,630 reports
45.148.10.147 1,499 reports

Access this data via API

Get Netherlands threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NL

View full API documentation

See how we classify and verify threats →

Check any IP from Netherlands

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS396982 Intelligence AS210558 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...