An estimated 20 million U.S. Internet Protocol (IP) connections are exposed to exploitation after users give illicit actors access to them, often unknowingly. So says a report researched by risk3sixty and released by the Digital Citizens Alliance (DCA), which explains how devices such as smart doorbells, streaming boxes, routers, and free Virtual Private Network (VPN) applications are used by illicit actors to route malicious online activity through American households.
DCA estimates that more than an 20 million U.S. IP connections are part of residential proxy networks that allow questionable actors to disguise their real location and identity online by routing activity through residential Internet addresses.
While originally developed for legitimate business purposes such as ad verification and website testing, these services are also used to facilitate fraud, credential theft, cyberattacks, child exploitation, and state-sponsored espionage.
Connection to piracy
Americans who said they downloaded free apps – such as VPNs or other services – were 15 times more likely to be warned by their Internet service provider about suspicious activity on their home network and 3 times more likely to report a breach of financial or personal information. Likewise, Americans who said they connected a so-called piracy device to their home network were twice as likely to report being a victim of malware or having their Internet connection accessed without their permission.
Android boxes
Researchers purchased popular Android streaming boxes, including the VSeeBox V5 Pro sold through Walmart’s online marketplace. They discovered that the devices immediately connected to servers in China, transmitted device information, and accepted remote commands capable of installing or removing software.
Cybercriminals and foreign adversaries exploit these networks because traffic originating from a legitimate American household appears trustworthy to websites, banks, and security systems. That allows illicit actors to avoid detection while carrying out attacks that may ultimately be traced back to innocent consumers. U.S. intelligence and cybersecurity officials are increasingly concerned that nation-state actors are using residential Internet connections to target American critical infrastructure.
In one example, the Chinese company IPIDEA built one of the world’s largest residential proxy networks, controlling millions of consumer devices — PCs, smartphones, and smart TVs — that it enrolled largely without their owners’ knowledge through malicious software development kits (SDKs) and “free” VPN and game apps. In January 2026, Google’s Threat Intelligence Group disrupted the network by obtaining court orders to seize dozens of its command-and-control and marketing domains
Awareness campaign
In late June 2026, the Digital Citizens Alliance launched a consumer awareness campaign to help consumers shield their households from cybercriminals and foreign threat actors looking to hijack U.S. Internet connections to commit a wide range of criminal and other illicit activities.
Most American consumers are unaware of how more than 2 billion Internet-connected devices in their homes can be exploited,” said Tom Galvin, executive director of DCA. “When residential IP connections are hijacked, it enables illicit actors to disguise their real location and identity to commit crimes, putting Americans’ Internet security at risk. Americans need to know the risks to protect themselves.”
Prior research has found that residential proxy infrastructure has been used by hundreds cyber threat groups, including actors linked to Russia, China, Iran, and North Korea.
What DCA recommends
- Tools are available to analyze whether an IP connection is part of a residential proxy network and compromised
- Avoid streaming devices that claim to provide free sports, TV shows, and movies, as they may contain malware or backdoors that hijack your IP connection.
- Be skeptical of “free” apps. Free VPNs, pirated software, and other apps from unofficial marketplaces expose users to risk. Steer clear of “earn money by sharing your bandwidth” offers.
- Replace routers or other household devices older than 5 to 7 years. When a hardware device is end of life, the manufacturer no longer sells the product and is not actively supporting
the hardware, which means software updates or security patches are no longer released.
Also change the default admin username and password all devices in your home.
Why it matters
The target is enormous: there are roughly 2 billion Internet- connected devices in American households, of varying vulnerabilities. Devices over three years old or that are no longer technically supported are considered the most vulnerable.
Existing laws and industry standards have not kept pace with the growing threat posed by compromised consumer devices and residential Internet connections. Policymakers, manufacturers, and service providers must work together to strengthen protections for consumers and national security. U.S. laws fail to hold Internet providers and device manufacturers to a standard.
There is no international certification for Internet connections, even though they enable state-sponsored attacks against the United States and billions in cybercrime. Given the threats that residential Internet-connected products pose to American interests – consumers, businesses, and national security – it’s time for policymakers to learn what those threats are.
Further reading
Cybercrime by Doorbell: How Illicit Actors “Borrow” the Internet Connections of Millions of Americans for Profit and Harm. Report. June 2026. Digital Citizens Alliance
Digital Citizens Alliance launches national campaign to prevent hijacking of home Internet devices by cybercriminals and foreign threat actors. Landing page with press release and link to report. June 25, 2026. Digital Citizens Alliance
MPA: The criminal infrastructure hiding in plain sight: Unmasking Residential Proxies. Article (Two parts). September 24, 2025. By: Larissa Knapp, EVP and Chief Content Protection Officer, Motion Picture Association, and Noopur Davis, Executive Vice President, Chief Information Security and Product Privacy Officer, Comcast Corporation. Published by Piracy Monitor
Are all residential proxy services criminal organizations? Landing page and link to Report. July 2025. hCaptcha









