Netherlands (NL) Threat Intelligence

NL

Netherlands has 127,873 malicious IP addresses with 5,184,327 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: DigitalOcean, LLC (46,174 IPs), Google LLC (5,496 IPs), 1337 Services GmbH (4,275 IPs). Data collected since 2022-12-05, last activity 2026-07-05.

Threat Assessment: Netherlands is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by DigitalOcean, LLC and Google LLC.

Total Reports
5,184,327
Unique IPs
127,873
First Seen
2022-12-05
Last Activity
2026-07-05

Top Threat Categories

Suspicious Activity 55,837
Severe Abuse 41,578
Ssh Bruteforce 29,768
Moderate Threat 4,856
High Threat 3,686

Top Attacking Networks

AS14061 DigitalOcean, LLC
46,174 IPs
AS396982 Google LLC
5,496 IPs
AS210558 1337 Services GmbH
4,275 IPs

Most Reported IPs in Netherlands

45.148.120.78 983 reports
45.148.10.141 847 reports
45.148.10.157 837 reports
45.148.10.152 833 reports
45.148.10.147 819 reports

Access this data via API

Get Netherlands threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NL

View full API documentation

See how we classify and verify threats →

Check any IP from Netherlands

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS396982 Intelligence AS210558 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...