Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

U.S. authorities seized the LolekHosted.net domain on August 8, 2023, and federal prosecutors charged its alleged operator, Polish national Artur Karol Grabowski, with three crimes. Separately, Polish authorities reported five arrests and the seizure of hundreds of servers in their investigation. Those actions are related, but the public accounts do not establish that Grabowski was among the five people arrested in Poland.

What happened to LolekHosted?

The U.S. Department of Justice (DOJ) announced the case on August 11, 2023. According to its announcement, U.S. authorities seized LolekHosted.net on August 8 under a warrant issued by the U.S. District Court for the Middle District of Florida. The indictment was unsealed in Tampa the previous day.

The domain seizure and the criminal charges are distinct legal actions. The seizure removed the website domain from public use; it does not, by itself, prove the allegations in the indictment or establish guilt.

Who is Artur Karol Grabowski, and what is he charged with?

The DOJ identifies Grabowski as a Polish national and alleges that he operated LolekHosted. The indictment charged him with conspiracy to commit computer fraud, conspiracy to commit wire fraud, and international money laundering. The department says the indictment was unsealed on August 10, 2023.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These are allegations, not findings of guilt. The DOJ release states: “An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.”

What is bulletproof hosting?

Bulletproof hosting is a law-enforcement term for online hosting or VPN services intentionally designed to support criminal activity. In a 2020 DOJ release about a separate case, the department described practices such as evading detection, moving accounts or data among IP addresses, servers, or countries, and not keeping logs. That general definition is context, not an independent finding about LolekHosted.

What do prosecutors allege LolekHosted did?

Prosecutors allege that the hosting service helped clients conceal or sustain cybercrime. The DOJ says LolekHosted permitted customers to use false account details, did not keep client server IP logs, frequently changed server IP addresses, ignored third-party abuse complaints, and notified clients about law-enforcement inquiries.

According to the DOJ, clients used LolekHosted servers as intermediaries to access victim networks without authorization and to store hacking tools and stolen data. The agency also alleges the service was used in phishing, brute-force attacks, and ransomware activity. These claims remain allegations in the U.S. indictment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How was LolekHosted linked to NetWalker?

The DOJ says LolekHosted clients carried out approximately 50 NetWalker ransomware attacks using the service. It separately reports that NetWalker was deployed across approximately 400 victim company networks overall and generated more than 5,000 bitcoin in ransom payments. The DOJ valued those payments at approximately $146 million in its 2023 release; that is the department’s valuation at publication, not a current conversion.

The figures describe different scopes: the approximately 50 attacks are attributed to LolekHosted clients, while the 400 networks and ransom total concern NetWalker more broadly.

What did Polish authorities report?

Poland’s Central Bureau for Combating Cybercrime (CBZC), in a release dated August 10, 2023, said officers arrested five members of an organized group on August 8. The investigation was supervised by the Regional Prosecutor’s Office in Katowice. CBZC said the operation was coordinated through J-CAT, supported by Europol’s European Cybercrime Centre (EC3), and involved active cooperation with the FBI.

The Polish agency said investigators secured hundreds of servers used in the hosting operation, as well as computer equipment, phones, electronic storage media, and cryptocurrency. It described alleged uses including phishing, ransomware, spam, malware distribution, and fake online shops. Its release also reported the service’s promotional slogans, including claims of complete privacy and a no-logs policy; these were marketing claims, not verified findings about how the service operated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The CBZC account concerns a Polish investigation and infrastructure seizure. The DOJ account concerns the U.S. domain seizure and indictment. The cited Polish release does not identify Grabowski as one of the five arrested people, so the two accounts should not be collapsed into a claim that he was arrested in Poland.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about the U.S. case’s status?

The DOJ page was updated on February 6, 2025, and stated that Grabowski remained a fugitive at that time. That is the latest status established by the cited DOJ source; it does not establish his status on October 4, 2026. The available releases also do not establish a final court outcome.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.