Ordinary American home internet connections have become foundational infrastructure for fraud, credential theft, and state-sponsored espionage — and no federal agency currently has authority to do anything about it.
That’s the central finding of Cybercrime by Doorbell, a 26-page investigation published Wednesday by the Digital Citizens Alliance and cybersecurity firm risk3sixty. The report combines original field testing — purchasing and forensically monitoring hardware sold on Walmart’s marketplace, subscribing to criminal proxy services, and analyzing millions of IP connections — with a synthesis of recent federal enforcement to document how the residential proxy market has industrialized the exploitation of consumer devices.
An estimated 20 million U.S. IP connections are harvested for use in proxy networks annually, the report finds. When risk3sixty tested connections available from seven providers, 85 percent carried prior fraud indicators. The problem spans the FCC, FTC, DOJ, CISA, and Commerce — and the report’s core policy argument is that no single agency has clear ownership or mandate to regulate it.
[See Related: Smart TV Apps on LG and Samsung Are Running Residential Proxy Software]
A brief note on the source: DCA is a 501(c)(6) that does not disclose its funders publicly, though its own about page acknowledges support from “the health, pharmaceutical, and creative industries.” The group has worked issues ranging from online pharmacies selling drugs to minors and steroid sales on social media to domestic extremism and, heavily, piracy — where entertainment industry money has historically driven the research agenda. In 2014, Google alleged in litigation that DCA was “lobbying and manufacturing press at the behest of the MPAA.” That history is worth knowing. It doesn’t change what the data in this report shows.
The report lands two days after Security Point Break’s own reporting that roughly one-third of LG and Samsung smart TV apps embed residential proxy SDK code — the same underlying mechanism the report describes.
Test buys and security research
Devices Most Likely Working Against You
- Off-brand Android TV boxes — Pre-loaded with malware at the factory. Connect to Chinese C2 servers on first boot. Sold on Walmart, Amazon, eBay for $25–$75. FBI-warned, January 2026. Cannot be patched clean.
- Smart TVs — LG, Samsung — Not pre-infected; SDK-infected apps. ~34% of scanned LG and Samsung apps carry proxy SDK code. Neither platform bars the practice. Roku and Fire TV do.
- Home routers — Especially 3–5+ years old with default credentials or unpatched firmware. Used by Volt Typhoon and the basis of the DOJ’s March 2026 SocksEscort takedown.
- Smart doorbells and security cameras — Spamhaus documented doorbells generating ~1M daily connections to blocklists. Risk spikes sharply once firmware support ends.
- Free VPN apps — 28 Google Play apps found enrolling phones via a library called PROXYLIB. Disclosure buried as “sharing idle resources” in terms of service.
- Bandwidth-sharing apps — Opt-in but opaque (Honeygain, similar). DCA found traffic through a shared Honeygain connection tied to a Treasury-sanctioned Russian bank.
- Digital projectors and picture frames — Documented by the FBI and Google IPIDEA research as BADBOX 2.0 vectors. Mostly China-manufactured, sold through unverified third-party sellers.
- Aftermarket vehicle infotainment systems — FBI-listed March 2026. Same factory-firmware risk as off-brand streaming boxes.
Prior research established that residential proxies are widely abused; the 2019 IEEE paper “Resident Evil” and a 2024 Sekoia analysis documented the ecosystem in detail. What DCA and risk3sixty add is hands-on market testing.
Risk3sixty subscribed to seven residential proxy providers — identified by scouring criminal forums and threat actor communications — and analyzed the IP connections each was selling.
Using IPQualityScore, an industry-standard fraud intelligence platform, they found an average of 85 percent of those connections carried prior fraud indicators. Addresses flagged were associated with repeated suspicious or criminal activity, according to the report. One provider, Proxy.fo, came in at 99 percent. Across all seven, over 80 percent of connections resolved to actual residential addresses.
Tracking roughly 26 million unique residential IPs over 30 days, DCA also found nearly half appeared across multiple providers — meaning once an IP enters the ecosystem, it tends to get resold and reused.
The second original finding involves a Walmart purchase. Investigators bought a VSeeBox V5 Pro Android streaming box from Walmart’s online marketplace and monitored what it did when powered on. The device immediately connected to a server in China, authenticated using its hardware ID, pinged that server every 60 seconds, transmitted device information, and awaited remote commands — including the ability to install or remove apps, reboot, or factory reset the device. Two preinstalled apps disguised as Netflix were repackaged versions with obfuscated code, neither signed by Netflix. Walmart removed the listing after being contacted and said it expects third-party sellers to meet its standards. VSeeBox was not contacted.
The third original finding involves Honeygain, a bandwidth-sharing app that pays users small amounts to share idle internet capacity. Investigators enrolled and monitored traffic flowing through their connection. They observed incoming traffic from entities in China and Russia, including traffic tied to Tinkoff Bank (now T-Bank), which is sanctioned by the U.S. Treasury. The report is careful to note it found no evidence Honeygain was aware of those connections; Trend Micro has separately classified the app as “riskware.”
The mechanism and the criminal use case
The residential proxy ecosystem exploits the fact that traffic from a data center IP gets scrutinized or blocked and traffic from a home IP typically gets waved through. Retailers, banks, and fraud detection systems treat residential addresses as real customers.
“They have no choice but to allow it,” DCA executive director Tom Galvin said in a briefing with Security Point Break. “If they start really stopping residential IP connections, they might be blocking out legitimate customers. So, it starts there by allowing it in — and then if they catch up to you, they don’t catch the criminal, they catch up to the person whose IP connection is being used.”
Steven Guris, threat intelligence lead at risk3sixty’s Armada division, said credit card fraud is the most common criminal application. Proxies are used to route a stolen Chicago card transaction through a Chicago residential IP, and the geographic fraud check passes. Credential stuffing follows the same logic.
“This is almost a foundational aspect of cybercrime,” Guris said. “It is considered like one of the things that you need to have on lock before you do anything.”
The report also flags use as Tor exit nodes — a scenario where a victim’s device becomes the last visible hop in an onion-routed chain. If law enforcement traces illegal activity back to that exit point, the trail leads to the device owner’s front door, not the threat actor.
“When you are the exit point — if some Russian threat actor is uploading CSAM (Child Sexual Abuse Material) material to the dark web — what the FBI could see is that material coming from their IP address,” Guris said. “Because an American’s home has been basically unwittingly enrolled as a residential proxy.”
The state-sponsored dimension
The report synthesizes existing intelligence on nation-state use, drawing primarily on Google’s January 2026 IPIDEA disruption, which identified 550 distinct threat groups using the network’s exit nodes in a single week — including state actors linked to Russia, China, Iran, and North Korea.
Volt Typhoon, the Chinese state-linked group targeting U.S. critical infrastructure since at least 2021, routes traffic through compromised home routers to make its operations appear to originate from legitimate residential addresses near targets, defeating geographic filtering. The FBI dismantled a Volt Typhoon-associated botnet of residential routers in January 2024, but officials say the group maintained access to water, energy, and transportation systems afterward.
What enforcement has looked like
In March 2026, the DOJ dismantled SocksEscort, a residential proxy network that infected home routers with malware and sold access to the hijacked connections. Prosecutors tied it to bank and cryptocurrency account takeovers and pandemic fraud costing Americans millions. The same month, the FBI issued a consumer warning that device owners whose IPs are traced to criminal activity can face scrutiny even without malicious intent.
The largest case in the space remains in legal limbo. YunHe Wang, charged with operating the 911 S5 botnet, allegedly compromised 19 million IP addresses and earned $99 million selling access. The DOJ linked those connections to $5.9 billion in fraudulent pandemic unemployment claims. Wang was arrested in Singapore in May 2024 and is still contesting extradition.
The policy ask
The report calls for an interagency task force spanning the FCC, FTC, DOJ, CISA, and Commerce — arguing that no single agency currently has authority or mandate to regulate the space. It draws on the Kimberley Process as a supply-chain certification model: require proxy services selling to U.S. customers to verify buyer identity and intended use, the way the diamond trade was required to certify conflict-free sourcing.
The Dutch Data Protection Authority opened an investigation into “IP leasing without informed consent” in early 2026. The United States has no equivalent framework.
What to check and who to call
Spur.us lets users look up whether their IP address has been flagged as a proxy node. The FBI’s IC3 is the reporting destination for suspected device compromise. DCA says it is building a free consumer lookup tool, though it isn’t available yet.
Practical steps from the report: avoid off-brand Android TV boxes promising free sports or movies; don’t install free VPNs from unofficial stores; be skeptical of any app offering cash for unused bandwidth; replace home routers older than five to seven years and change their default credentials.
Photo by Bernard Hermant on Unsplash