On May 22, 2026, Dutch authorities seized approximately 800 servers operated by WorkTitans B.V., a hosting provider found to be a rebranded successor to a sanctioned Russian ISP that served as infrastructure for multiple Iranian threat groups. The operation simultaneously disrupted active campaigns by distinct groups including MuddyWater, Agrius, and Nimbus Manticore, which were conducting cyber espionage against organizations in Israel, defense, and aerospace sectors. The takedown demonstrates how a single law enforcement action against one hosting provider can disrupt multiple concurrent nation-state operations sharing the same underlying infrastructure.