Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals — FBI
An official website of the United States government. Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
Menu
Search FBI
Home
Most Wanted
News
What We Investigate
How We Investigate
How We Can Help You
Submit a Tip
About
Contact Us
Crime Statistics
Photos
Video
Outreach
History
FOIA
Scams & Safety
FBI Kids
FBI Jobs
Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals
What We Investigate
Terrorism
Counterintelligence and Espionage
Cyber
Public Corruption
Civil Rights
Transnational Organized Crime
White-Collar Crime
Violent Crime
Environmental Crime
Weapons of Mass Destruction
How We Investigate
News
Partners
Cyber Alerts
SEC Reporting Requirements
Most Wanted
Public Service Announcement
Share on X X.com<br>Share on Facebook Facebook<br>Email Email
March 12, 2026
Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals
Alert Number: I-031226-PSA
Questions regarding this PSA should be directed to your local FBI field office.
The Federal Bureau of Investigation (FBI) is publishing this public service announcement (PSA) to raise awareness of residential proxies, the risks they pose, and steps the public can take to safeguard their devices from becoming part of a residential proxy network. Cyber threat actors use residential proxies to facilitate illicit activities, while obfuscating their true identities and locations by routing internet traffic through home and small business internet networks.
What is a residential proxy?<br>A residential proxy is an intermediary server between individuals and websites they visit to make their connections appear to originate elsewhere. Legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumers' Internet of Things (IoT)1 devices, such as TV streaming devices, digital picture frames, smartphones, tablets, and routers are used to route traffic. Once an internet-connected device is compromised, the device's IP address can be used by threat actors to mask their online illegal activity, making the consumer appear responsible.
Understanding how residential proxies work<br>A residential proxy is used to route users’ requests through another IoT device, typically located elsewhere in the world. When selecting an IP address, users can choose which country they would like the IP address from, down to the city and state. Doing so alters the users' IP address from the perspective of the website to that of the device the traffic was routed through.
How your device can become part of a residential proxy network<br>Many individuals do not realize their internet connection could be used by someone else without their permission. Residential proxies obtain residential IP addresses from devices in two ways: The owner of the device provides consent, or the owner of the device does not provide consent and is unaware their IP address is being used.<br>The following methods can be used to acquire residential IP addresses for a residential proxy network:<br>Software development kit (SDK)2 partnerships: Proxy services convince mobile application developers to include their SDK in applications in exchange for payment for each person who downloads the application. Individuals download the application and accept the terms and conditions, allowing the SDKs to run in the background and route proxy traffic through users' devices.
Virtual private network (VPNs)3 with hidden terms of service: Free VPN services may enroll users' devices in a residential proxy network, without obtaining their consent. The details are often hidden in the terms of service, which most users do not read prior to download, or the language is difficult for the user to understand.
Compromised IoT devices: Criminals gain unauthorized access to home networks through compromised IoT devices, such as TV streaming devices, digital projectors or picture frames, aftermarket vehicle infotainment systems, and other products connected to the internet. Criminals configure the device with malicious software prior to it being purchased or infect the device with a backdoor4 while it downloads required applications.
Malware: Free online video game content, free sports/tv shows/movies, free software that normally costs money, and torrented content5 can all contain malware that makes a device part of a residential proxy network.
Passive income schemes: Proxy services convince people to download applications on their device that promise to pay them for their internet bandwidth. People often do not realize that criminals use their internet connection to commit cyber...