Netherlands (NL) Threat Intelligence

NL

Netherlands has 161,848 malicious IP addresses with 7,059,095 abuse reports. Top threat categories include tcp scan, high threat, suspicious activity, malware distribution, severe abuse. Top attacking networks: DigitalOcean, LLC (52,477 IPs), Google LLC (10,471 IPs), 1337 Services GmbH (5,920 IPs). Data collected since 2022-12-05, last activity 2026-10-05.

Threat Assessment: Netherlands is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are tcp scan, high threat, suspicious activity. The majority of threats originate from networks operated by DigitalOcean, LLC and Google LLC.

Total Reports
7,059,095
Unique IPs
161,848
First Seen
2022-12-05
Last Activity
2026-10-05

Top Threat Categories

Tcp Scan 798,055
High Threat 455,429
Suspicious Activity 356,749
Malware Distribution 127,716
Severe Abuse 41,578

Top Attacking Networks

AS14061 DigitalOcean, LLC
52,477 IPs
AS396982 Google LLC
10,471 IPs
AS210558 1337 Services GmbH
5,920 IPs

Most Reported IPs in Netherlands

45.148.10.230 3,972 reports
45.148.10.141 2,261 reports
45.148.10.152 2,257 reports
45.148.10.157 2,246 reports
45.148.10.151 2,220 reports

Access this data via API

Get Netherlands threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NL

View full API documentation

See how we classify and verify threats →

Check any IP from Netherlands

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS396982 Intelligence AS210558 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...