You open the 922 S5 client, hit “connect,” and nothing happens: no spinning wheel, no authorization error. Just emptiness. You go to the PIA S5 website—it won’t load. Same story with ABCproxy. The first (and reasonable) thought: the server is down, they’ll fix it by morning, it happens, no big deal.
But no. These three services didn’t just go down—they were taken down. All on the same day, along with a dozen other lookalikes. At the helm were Google and the FBI, and the reason was that all these proxy services had been one big botnet for years. And if you’ve been running traffic through them, this story concerns you directly—even if you’re no longer worried about your lost account balance.
Let’s break it down: what happened, why it’s legal, where it all started, and where to move next so you don’t step on the same rake in six months. And the odds you’ll have to deal with this again are never zero.
What happened in January 2026
On January 28, 2026, the Google Threat Intelligence Group, together with the FBI, carried out an operation against a network called IPIDEA—calling it one of the world’s largest residential proxy networks. A residential proxy is when your traffic goes out to the internet through someone else’s home connection: the system on the other side sees the IP address of a regular resident, not a datacenter machine. That’s exactly why they’re valued in affiliate marketing—anti-fraud systems see this as a real person on a couch.

The problem is, IPIDEA isn’t just one service. It’s a single backend powering about 13 different brands. Almost every name an affiliate has ever seen in chats was hit:
- 922 S5 Proxy (aka 922proxy)
- PIA S5 Proxy
- ABCproxy
- LunaProxy
- PyProxy
- IP2World
- 360Proxy
- Cherry Proxy, Tab Proxy
- plus related VPN brands—Galleon, Radish, Door
Different websites, different logos, different prices in the catalog—but under the hood, it was all the same engine. Google estimated that the operation knocked about 9 million infected devices offline and enabled the seizure of dozens of domains that managed all this traffic. The sites and clients didn’t go down one by one—they all died at once, because it wasn’t just individual services being cut, but the common root.
Why This Was a Botnet, Not a Proxy Service
Here’s the key question to ask: where does the service get millions of “residential” IP addresses from?
A legal provider has a network of volunteers: a person installs a conditionally free app or extension on their phone, agrees that their internet connection will occasionally be used as an exit node (an exit node is a point through which someone else’s traffic leaves), and gets something in return—money, a premium subscription, ad removal. They know, they consent, they’re compensated, and that’s why it’s called ethical sourcing.

IPIDEA operated differently. According to Google’s investigation, devices joined the network via infected apps: developers were offered ready-made SDKs (software development kits—Castar SDK, Earn SDK, and others), promising earnings for “traffic monetization.” The developer integrated the SDK, and the phones and computers of their users silently turned into those very “residential IPs” that others later bought. Device owners knew nothing and gave no consent.
| Simply put: when you paid 922 or PIA for residential traffic, you were renting access to someone else’s hacked phones. Not a “volunteer’s home internet,” but a retiree’s tablet who downloaded a free flashlight app. |
And the company ended up in a very bad neighborhood. According to Google’s report, over 550 tracked hacker groups—including state APT teams—and well-known botnets like BADBOX 2.0 were running through IPIDEA’s infrastructure in a single week. In other words, your campaigns were running on the same engine as targeted cyberattacks.
For antifraud, this isn’t a “clean residential IP,” but an address with a very shady reputation—which, by the way, explains why conversions on these proxies have dropped for many in recent months.
Lineage: from 911 S5 to IPIDEA
If you feel like you’ve seen this before — you’re not mistaken. IPIDEA is not the first and, unfortunately, probably not the last name on this market.
The originator of this whole scheme is the 911 S5 service, which operated since 2014 and was once the most notorious “residential” dump on the market. In 2022, the operator took it underground, in 2023 the network resurfaced as Cloud Router, and in May 2024 the FBI stepped in. The result: the administrator, Chinese national YunHe Wang, was arrested, and investigators estimated the network at 19 million infected IPs worldwide. According to the charges, these addresses were used for fraudulent schemes worth billions of dollars — just the fake COVID relief claims in the US totaled $5.9 billion.

The scheme is simple and repeatable: build a botnet, sell access as “residential proxies,” operate for a couple of years, get hit by a crackdown, shut down — and reopen under a new name. 911 became Cloud Router. Fragments of the ecosystem evolved into IPIDEA with its 13 brands. Today IPIDEA is busted — tomorrow something new will pop up with a fresh logo and “the best prices on the market.”
| Speaking of “resurfacing.” Right after 922’s demise, sites like 922proxy.app and 922proxy.org appeared online, claiming to be the same service and offering to “log in with your old email, we’ve migrated the database.” Don’t fall for it. These are clones, exploiting the dead brand’s recognition: at best, they’ll scam you for a deposit, at worst — steal your data or infect you with another malicious client. The original is dead, it has no “mirrors.” |
What happens to your money and accounts now
Bad news for those who had money left on their balance: it’s most likely gone.
According to user reviews, after the shutdown, the sites and apps stopped working along with personal accounts — there’s nowhere and no one to request your deposit from. A criminal network under FBI operation doesn’t send out refund notifications.

What to do about it: accept the loss and write it off — contacting “support” for a dead service is pointless.
But losing your balance isn’t the main risk. What matters more is what you did through these proxies. Go through this short checklist:
- Don’t look for “mirrors” or “alternative clients.” Any site today promising a resurrected 922 or PIA is a trap. The same advice applies to Telegram channels offering “working builds.” This also goes for any other services in a similar situation.
- Change your passwords if you reused them. If you logged into a dead service with an email and password you use elsewhere, change them. You gave your data to a company that was shady by definition.
- Check what was running on those IPs. Accounts you farmed and ran through IPIDEA residential proxies were on addresses with a bad reputation. If those accounts got banned or put on hold, it’s not platform paranoia—it’s just the consequences. Move valuable accounts to proper proxies before the platform does it for you.
- Audit your setups. Where else in your infrastructure are these services integrated—API connections, auto-uploads, third-party guides like “get proxies from 922.” All of that is now dead code.
Where to migrate: legal providers in 2026
I have two pieces of news for you:
- Good news. The residential proxy market doesn’t end with IPIDEA, and you can realistically migrate in a day or two.
- Bad news (for your wallet): legitimate traffic costs more than stolen. If you’re used to “unlimited for pennies,” get ready to pay per gigabyte—but at least you won’t risk your provider ending up in an FBI press release tomorrow.
The market in 2026 is roughly split into three tiers by price and use case. Prices below are as of July 2026. Rates change, so check the current price before buying.
- Enterprise — maximum transparency and compliance. This is for when you need volume, stability, and a clean legal record. Leaders are Bright Data and Oxylabs: both have documented ethical sourcing, KYC (know your customer), and GDPR compliance. Premium pricing—residential traffic starts at a few dollars per gigabyte and goes up with requirements. This isn’t for test runs; it’s for those running serious, long-term operations who want no nasty surprises.
- Mid-tier — balance of price and quality. Decodo (formerly Smartproxy), SOAX, DataImpulse — about $3–6 per gigabyte, decent pools, responsive support. Optimal for most solo buyers and small teams: cheaper than enterprise, but with clear sourcing and reputation.
- Budget tier — when entry price matters. IPRoyal, Webshare, Evomi — starting at about $1.75 per gigabyte, with Evomi’s entry rate around $0.49 per gigabyte. These are honest budget providers, not shady operations—but the lower the price, the more carefully you should check where their IPs come from (more on that below).
A quick note on related types, so you don’t get confused. Residential proxies aren’t the only option, there are also:
- mobile proxies (mobile proxy) — traffic via real SIM cards and mobile operators, often even more reliable than residential for account farming, but more expensive;
- ISP proxies (also known as static residential) — fast addresses registered to a home provider but hosted in a data center and do not change.
What to choose depends on your vertical and what your platform checks. The rule is simple: the stricter the offer’s anti-fraud, the more “real” the IP needs to be.
How to tell a legit proxy from the next botnet
The most important part of this article is this section. Because a brand name guarantees nothing.

Recent example: on July 2, 2026, Google together with the FBI and Lumen took down another major residential network — NetNut. This is not IPIDEA, a different story, but the point is the same: even a big, well-known name can turn out to be a network of infected devices. So you should choose not by logo, but by checklist.
Run any provider — whether from the list above or a new one — through these five questions:
- How do they explain the origin of their IPs? A legitimate provider clearly states they use an opt-in volunteer network or partner SDKs with explicit consent. If the website is vague and just says “millions of residential IPs worldwide” with no word on where they come from, that’s a red flag.
- Is there consent and compensation for IP owners? The key sign of an ethical network: the person on the other end knows their channel is being used, has agreed to it, gets something in return, and can opt out with one click. If there’s no explanation about consent and benefit for the peer, the traffic is likely stolen.
- Is there KYC and a clear legal framework? Client verification, a public acceptable use policy, GDPR compliance. A serious provider is transparent about this. A company that lets anyone do anything without a single question is also serving those who will later ruin your IP reputation.
- What is the service’s history and reputation? How many years on the market, are there real independent reviews, is there an actual company behind it. A service that popped up six months ago with a perfect landing page and no traceable history is a risk.
- And the main test — the price. Here’s a rule that will save your nerves: if you’re offered unlimited residential traffic at datacenter proxy prices, with no gigabyte counter and almost for free — that’s not generosity. Genuine residential traffic is expensive because it comes from real people who get paid. “Unlimited residential for a couple of dollars” almost always means you’re not paying with money, but with someone else’s infected devices. Exactly what got IPIDEA taken down.
If a provider passes the first four points and isn’t suspiciously cheap on the fifth — you can work with them. If they stumble on even a couple — keep looking, no matter how attractive their price list looks.
In short
Free “residentials” are gone not because you got unlucky with a service. They’re gone because cheap unlimited residential traffic is almost always someone else’s hacked devices, and that setup will eventually get crushed by the law. 911 became Cloud Router, the fragments became IPIDEA, then NetNut went down — the cycle repeats with uncanny precision.
Those who switched to transparent providers long ago didn’t even notice this week: they paid a bit more per gigabyte and sleep well. Those still searching for a “working 922 mirror” are just getting ready to lose money again. Don’t choose by logo or price tag, but by one question: where does the service get its IPs? Good luck and clean conversions!
FAQ
Not in their previous form. These were brands on a shared infrastructure that was seized by court order. Some brands might reappear under a new name someday, but it’ll be a different service and should be treated as a stranger. Sites now claiming to be the “resurrected 922” are clones.
Almost never. The user accounts and payment systems of these services are unavailable, and the network itself is under law enforcement operation. It’s smarter to write off the deposit as a loss and not waste time on “support.”
Free residential traffic almost always means you’re not the one paying — it’s people whose devices are used without their consent. “Free residentials” are at best bait, at worst an entry into another botnet. If a residential IP is free, someone else is the product.
The tool itself is legal: they’re used for ad verification, analytics, parsing. What’s illegal is a specific implementation — when IPs are sourced by infecting devices without the owners’ consent. So the question isn’t “proxy or not,” but “where does the provider get the addresses.”
Yes, reputable providers offer GEO selection, including Russia and CIS countries. The same rule applies: don’t just look for the right GEO, but check how the service explains the origin of those IPs.
Nothing from the IPIDEA list. It’s better to pause your campaigns for a day or two and switch to a transparent provider than to run valuable accounts through dead or cloned services and get banned.

Comments (0)