How a Botnet Investigation Erased Millions from Alarum Technologies

[stock_market_widget type=”card” template=”basic2″ assets=”ALAR” realtime=”true” api=”yahoo-finance”]

A little known corner of the internet economy came under a harsh spotlight this week when U.S. federal agents moved against a business that most investors had never heard of until its share price collapsed. The FBI seized a batch of web domains belonging to NetNut, the residential proxy arm of Alarum Technologies Ltd. (NASDAQ: ALAR), an Israeli technology company that had spent the past year as one of the market’s quieter success stories. 

To understand why that matters, it helps to know what NetNut actually sells. A residential proxy network routes internet traffic through ordinary home devices, so that a request appears to come from a regular household rather than a corporate server. Legitimate customers, including large companies and the developers who train artificial intelligence models, use these networks to gather publicly available web data at scale without being blocked. Alarum had leaned into exactly that demand, and the AI boom turned a modest firm into a fast growing one.

The trouble is where those home connections come from. Roughly two weeks before the seizure, the security researcher Brian Krebs published findings from several firms tying NetNut to a piece of software called Popa, described as a botnet running on at least two million devices, including smart televisions and streaming boxes, that were compromised with little or no consent from their owners. When agents acted, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division, which credited Google, Lumen and other partners for their help.

Markets reacted the way they tend to with thinly traded names. Alarum carries a small public float of about 7.3 million shares, which means news travels straight into the price with little to cushion it. The stock closed yesterday down more than 20% at $6.35, then fell a further 38% in after-hours trading once the news spread. That is a punishing move for a company that only weeks earlier had reported 64% revenue growth to $11.7 million for the first quarter, growth it credited to surging demand from AI model developers.

Then came Friday’s update, which made the situation look more serious rather than less. Alarum said additional NetNut domains had been seized since its first statement, and that it was now experiencing disruptions to a portion of its services. The company warned that if those disruptions continue for an extended period, they are likely to have a material adverse effect on its operations, its financial results and its ability to serve certain customers. It also said that, as of that morning, neither it nor NetNut had been formally contacted by the FBI or any other authority. 

For its part, Alarum has framed itself as a potential victim as much as a target. The company said it is investigating whether its own network was used for malicious, fraudulent or unlawful purposes by outside parties, and that it will cooperate fully with law enforcement so that anyone who misused its infrastructure is held to account. Whether that stance holds up will depend on facts that are not yet public. 

What this episode really exposes is the uneasy foundation beneath a booming trade. The value of a residential proxy business rests on access to millions of everyday internet connections, and the line between connections that are willingly shared and ones that are quietly hijacked is exactly what investigators are now testing. For a company whose growth story was built on feeding data to the AI industry, a question about how that data is sourced is not a side issue. It sits at the center of the business, and for now it sits unresolved. 

Related posts

Subscribe to Newsletter