TI-2026-034E

The Proxy Empire

How 150 Million Living Rooms Became Exit Nodes for Israeli Infrastructure
Series: The Invisible Nation (Letter E of H) ยท Published: June 2026 ยท Classification: CRITICAL

I. The Origin Story: A Free VPN With a Price

In late 2012, two Israeli entrepreneurs launched a product that would eventually control more residential IP addresses than any government's surveillance apparatus.

Ofer Vilenski and Derry Shribman were not newcomers. Their track record was a masterclass in building things that get acquired:

1998
KRFTech โ€” First startup
2000
Jungo โ€” Embedded networking
$107M
Jungo sold to NDS/Cisco, 2006
2012
Hola VPN โ€” The real play

Hola VPN was beautiful in its simplicity. Instead of routing traffic through expensive data centers like every other VPN, Hola used a peer-to-peer architecture. Your traffic went through another user's device. Their traffic went through yours. No servers needed. Free for everyone.

The investors understood the scale potential immediately:

Hola VPN Investment Round: $18M

  • DFJ (Draper Fisher Jurvetson) โ€” The same VC behind Skype and Hotmail
  • Horizons Ventures โ€” Li Ka-shing's fund (Asia's wealthiest man at the time)
  • Magma Venture Partners โ€” Israeli VC that backed Waze
  • Israel Chief Scientist Fund โ€” Israeli government R&D support
Source: Wikipedia, Hola VPN corporate history

By November 2016, Hola had 100 million users. Free, frictionless, viral. The product was perfect.

But the product was never the VPN. The product was the users.

II. The Monetization: $20 Per Gigabyte of Your Bandwidth

In 2014, two years after Hola launched, a new company quietly appeared: Luminati Networks. It was a division of Hola. And it sold something that Hola's 100 million users didn't know they were providing.

Luminati offered residential proxy services. Clients could route their web traffic through real residential IP addresses โ€” IP addresses that belonged to real people, on real ISP connections, in real homes.

The price: $20 per gigabyte.

The source of those residential IPs: every free Hola user's device.

How It Worked

When you installed Hola VPN for free, your device became an exit node for Luminati's commercial proxy network. Other paying Luminati customers could route their traffic through your home internet connection, using your IP address, consuming your bandwidth. You appeared as the source of whatever they were doing โ€” web scraping, ad verification, price comparison, or anything else.

Hola's FAQ mentioned this. Barely. In language that almost nobody read or understood.

Source: Wikipedia โ€” "Free users act as exit nodes for other users... bandwidth was sold at $20 per gigabyte"

The economics were extraordinary. Hola had zero infrastructure cost for its proxy network. Every user WAS the infrastructure. The margins approached those of a software company with the scale of a telecom.

And for over a year, almost nobody noticed.

III. The Exposure: 8chan and the Forced Disclosure

In May 2015, Fredrick Brennan โ€” founder of the imageboard 8chan โ€” noticed something alarming. His website was being hit by a DDoS attack. When he traced the source, the traffic was coming from Hola users' devices.

Hola's peer-to-peer architecture meant that anyone who paid Luminati could direct traffic through any Hola user's connection. Including attack traffic. Including DDoS floods. Brennan's 8chan was being attacked through Hola users who had no idea their computers were participating.

Vilenski's Response

"It was always part of the agreement," Ofer Vilenski told reporters. The company claimed the FAQ had always disclosed that free users' bandwidth would be shared.

But the FAQ was only updated AFTER Brennan's exposure. And security researchers found additional vulnerabilities that allowed malware delivery to Hola users โ€” the proxy architecture could be used to serve malicious code to any device running the extension.

Source: Wikipedia, Hola VPN โ€” "criticized for various security practices" (May 2015)

The exposure created a brief scandal. Tech media covered it. Some users uninstalled. But Hola's growth barely paused. By 2016, they hit 100 million users anyway. The lesson was clear: disclosure doesn't stop growth when the product is free.

But something else happened. Luminati's commercial value had been proven. And someone with deep pockets noticed.

IV. The Acquisition: London Private Equity Buys the Network

In August 2017, EMK Capital โ€” a London-based private equity fund โ€” acquired 75.6% of Luminati Networks from Hola for $125 million, valuing the entire proxy business at $165 million.

Read that again. A London PE fund paid $125 million for the right to sell other people's bandwidth.

$125M
Price for 75.6% of Luminati
$165M
Total company valuation
London
EMK Capital jurisdiction
Netanya, IL
Operations remain in Israel

The pattern should look familiar to readers of this series. An Israeli-founded company, performing Israeli operations, with Israeli personnel โ€” but majority ownership registered in London. When regulators come looking, they find a British PE fund. When the technology is traced, it leads to Israel. The jurisdiction gap is the product.

In March 2021, Luminati Networks was renamed Bright Data. New name. Same network. Same model. And under CEO Or Lenchner, a dramatically expanded ambition.

By 2026, Bright Data claims 400 million residential IPs, of which 150 million+ come from its SDK. Revenue estimated at $500 million+ per year.

The $20/gigabyte exit node scheme had become a half-billion-dollar enterprise.

V. The Smart TV Infiltration: 250 Million Households

On June 5, 2026, Include Security and independent researcher Buchodi published findings that redefined the scale of Bright Data's infrastructure. They had reverse-engineered the iOS SDK that Bright Data embeds in consumer apps.

What they found went beyond phones.

Bright Data SDK in Smart TV Apps โ€” June 2026

The SDK was discovered in apps on Samsung, LG, Roku, and Comcast smart TV platforms. The partner manifest (exposed via an unauthenticated configuration endpoint at clientsdk.bright-sdk.com) revealed:

PartnerPlatformReach
PlayWorks DigitalSamsung, LG, Comcast, Roku, Sky250M TV households, 400+ CTV games
CloudTV125+ TV brands, 15+ OEMsMajor CTV platform provider
Viber / RakutenMobile250Mโ€“820M MAU
Moonfrog LabsMobile~10M MAU (Teen Patti Gold)
LongvisionSmart TVCTV app developer
Hola NetworksMobile / Desktop100M+ users (the original)
Source: Include Security / CybersecurityNews, June 2026 ยท The Hacker News, June 6, 2026

A smart TV is the perfect proxy node. It is:

The SDK configuration confirmed this design philosophy: ignore_screen_on=true, ignore_on_call=true. The device operates as a proxy even while you're watching television. The default bandwidth allocation: 200 GB per month per device on WiFi.

Bright Data notified of the research on May 11, 2026. No response before publication.

After the research was published, Google, Amazon, and Roku restricted background proxy SDKs. Bright Data dropped those platforms. But as of June 2026, it still lists Samsung's Tizen and LG's webOS as supported.

VI. The SDK Architecture: Designed for Invisibility

The Include Security analysis revealed an SDK architecture that goes beyond simple proxy functionality. It is engineered to be invisible โ€” to users, to security tools, and to network monitoring.

Technical Architecture (from Include Security reverse engineering)

FeatureImplementationPurpose
CommunicationWebSocket to proxyjs.brdtnet.com:443 via AWS Global AcceleratorPersistent connection, CDN-masked
TLS Certificate*.luminatinet.com (pre-2018 domain)Legacy infrastructure, harder to attribute
VPN BypassNWParameters.requiredInterface โ€” binds to physical WiFi/cellularCircumvents user-configured VPN
Instrumentation DefeatCFHTTPMessage instead of URLSessionInvisible to standard iOS security tools
Config Endpointclientsdk.bright-sdk.com (unauthenticated)Full partner manifest exposed publicly
Binary SymbolsBrdWebSocketFacade, BrdNetwork.DNSResolverCustom network stack, not system APIs
Source: Include Security / Buchodi, June 5, 2026

Two features demand special attention:

The VPN bypass. On iOS, the SDK uses Apple's NWParameters.requiredInterface API to bind directly to the physical WiFi or cellular adapter. If the user has a VPN configured โ€” even a corporate VPN โ€” the SDK's traffic bypasses it entirely. Bright Data called this "an unintended bug" and said they would fix it. But the code was specifically written to use a non-standard API that accomplishes exactly this bypass.

The instrumentation defeat. The SDK uses CFHTTPMessage instead of the standard URLSession for its control plane. This means standard iOS security monitoring tools โ€” the tools that enterprises and security researchers use to inspect app network traffic โ€” cannot see it. This is not a bug. This is architecture.

In some countries (Uzbekistan, Oman), the SDK configuration set far higher bandwidth limits, allowing devices to relay traffic almost until the battery died. Bright Data called these "temporary legacy rules" that had been removed.

Detection: How to Block

Block these domains at router level (Pi-hole, NextDNS, or firewall):

  • proxyjs.brdtnet.com
  • proxyjs.luminatinet.com
  • proxyjs.bright-sdk.com
  • clientsdk.bright-sdk.com
  • clientsdk.brdtnet.com

TLS SNI patterns: *.brdtnet.com, *.luminatinet.com, *.luminati.io

Note: On mobile connections, the SDK sidesteps office WiFi entirely. A network block alone won't catch it.

Source: The Hacker News, June 6, 2026

VII. The Philippines Attack: Proxy Infrastructure as Weapon

In August 2021, Karapatan โ€” a Philippine human rights organization that documents extrajudicial killings โ€” came under a sustained DDoS attack. It lasted 25 days.

Qurium Media Foundation, a Swedish digital forensics organization, investigated. What they found connected the attack directly to Bright Data's infrastructure.

Qurium Forensic Investigation โ€” August 2021

  • 30,000 IP addresses participated in the attack
  • Of these, 8,000 "unknown" IPs were traced to Luminati/Bright Data proxy network
  • Identification: HTTP 407 responses with header X-Luminati-Error: Proxy Authentication Required
  • Authentication: Proxy-Authenticate: Basic realm=Luminati
  • Attack IPs sourced from Russian and Ukrainian mobile operators: MTS, MegaFon, T2 Mobile, Kyivstar
  • IPs rotated hourly in blocks of 50 โ€” consistent with proxy pool rotation
  • Super-proxy infrastructure identified: domains lum-superproxy.io and l-cdn.com
  • Super-proxies had ports 7547, 5000โ€“44818 open
  • DNS resolution from Choopa/DigitalOcean addresses
Source: Qurium Media Foundation โ€” "Israeli firm Bright Data (Luminati Networks) enabled the attacks against Karapatan"

Read the Qurium headline again: "Israeli firm Bright Data (Luminati Networks) enabled the attacks against Karapatan."

This is not speculation. This is forensic evidence. The HTTP headers identified Luminati infrastructure. The IP rotation patterns matched commercial proxy pool behavior. The super-proxy domains were Luminati-registered infrastructure.

A Philippine human rights organization documenting government killings was attacked for 25 days using infrastructure built from the bandwidth of people who thought they had a free VPN.

Bright Data's position: they are a neutral infrastructure provider and do not control how customers use the network. This is the identical argument made by every bulletproof hosting provider we've documented in 30+ dossiers.

In January 2023, Meta Platforms sued Bright Data for scraping Facebook and Instagram data. The lawsuit contained a devastating irony: Meta had previously hired Bright Data to scrape competitor websites.

In January 2024, a San Francisco federal judge ruled that Bright Data had not breached Meta's terms of use. Denied Meta's summary judgment.

In July 2023, X Corp (Twitter) sued Bright Data for data scraping. In May 2024, the judge dismissed the case entirely, ruling:

Federal Court Rulings โ€” 2024

  • Meta v. Bright Data (Jan 2024): No breach of terms of use. Scraping public data is permissible.
  • X Corp v. Bright Data (May 2024): Case dismissed. Judge ruled restricting scraping could lead to "information monopolies" and that X's concerns were "more about financial compensation than protecting user privacy."
Source: Federal Court decisions, San Francisco / Wikipedia

Two of the world's largest social media platforms โ€” with combined legal budgets in the billions โ€” sued the same Israeli proxy company. Both lost.

The legal precedent is now established: residential proxy scraping is lawful. Courts have validated the infrastructure. The business model that started by selling free VPN users' bandwidth at $20/GB now has legal immunity from the companies it scrapes.

Bright Data maintains a "Trust Center" with PwC audit reports, AppEsteem certification, and ISO/SOC 2 attestations. CEO Or Lenchner told The Hacker News: "A device in its network is a device whose owner said yes, understood what they were saying yes to, and can say no again at any moment with two steps."

Whether a smart TV owner reading "occasionally use free resources" understands they're consenting to 200GB/month of proxy traffic is an open question the courts haven't been asked.

IX. The AI Scraping Machine: Why Scale Matters Now

What changed between 2015 and 2026 is the buyer.

In 2015, Luminati's customers were ad verification companies, price comparison services, and SEO analysts. In 2026, the primary demand driver is AI training data collection.

The AI-Proxy Feedback Loop

Modern AI models (GPT, Claude, Gemini, Llama) require massive web-scraped datasets. But anti-bot defenses (Cloudflare, DataDome, Akamai) block datacenter IP addresses. The solution: route scraping through residential proxy networks where traffic appears to come from real homes.

Bright Data explicitly markets to the AI industry. Its 400M IP pool and consent-based SDK model provide exactly what AI companies need: massive-scale, residential-IP scraping that looks like real users browsing from real homes.

Source: The Hacker News โ€” "data business Bright Data markets heavily to the AI industry" (June 2026)

The ecosystem context makes this clearer:

Bright Data's argument: their SDK-sourced IPs are opt-in, unlike criminal botnets. That consent screen is the line between "legitimate business" and "criminal network." But both turn consumer devices into exit nodes for commercial traffic. Both use residential IPs to bypass anti-bot defenses. Both serve the same AI training data market.

The difference is a dialog box.

X. The Killed Competition: GeoSurf and Patent Warfare

Bright Data didn't just build a monopoly through growth. It eliminated competitors through litigation.

GeoSurf: Shut Down December 2023

GeoSurf, another Israeli proxy service provider, permanently ceased operations on December 20, 2023, following a legal defeat against Bright Data in patent litigation.

An Israeli company killed another Israeli company using US patent law. The result: one fewer competitor in the residential proxy market.

Source: AIMultiple Research โ€” "GeoSurf has permanently ceased operations following a legal defeat against Bright Data"

Bright Data also won a $7.5 million patent judgment against Oxylabs (Lithuanian competitor). The pattern: Bright Data patents the proxy infrastructure model, then uses US courts to extract settlements or kill competitors.

The residential proxy market is increasingly an Israeli near-monopoly:

CompanyHQIP PoolStatus
Bright DataIsrael (Netanya)400M+ (150M SDK)Market leader
OxylabsLithuania100M+Active, lost $7.5M to Bright Data
SmartproxyLithuania55M+Active
GeoSurfIsraelโ€”SHUT DOWN Dec 2023 (Bright Data patent suit)
NetNutIsrael85M+Active

Three of the top five residential proxy companies are Israeli. One was killed by another Israeli company. The survivor controls more IPs than any nation-state surveillance program has ever documented.

XI. The Honeypot Connection: We've Seen This Model Before

Our honeypot doesn't contain Bright Data IPs directly โ€” and it shouldn't. Bright Data is the infrastructure provider, not the attacker. But we have documented the exact same operational model in the wild.

TI-016: Phantom Pipes โ€” The Residential Proxy Verification Botnet

In our investigation TI-016, we documented a residential proxy verification botnet using AsyncSSH 2.1.0 with HASSH fingerprint fda360b1b4f4d3455cb75c6e7edb1d11. This botnet operated across Vietnamese Viettel CGNAT pools.

What it did: connect to honeypots using credentials (admin:admin, root:admin, test:test), then verify the exit IP via ip-who.com. This is how residential proxy networks test their nodes โ€” by verifying that traffic exits from the expected residential IP address.

We caught the quality assurance process of residential proxy infrastructure. The same model that Bright Data commercializes at 150M+ IP scale.

Source: LSN Honeypot TI-016, Phantom Pipes investigation

The connection goes deeper. In TI-002, we documented residential botnet nodes across Armenia, Russia, South Korea, Indonesia, and Thailand โ€” all on residential ISPs. These are the same type of nodes that compose Bright Data's "consent-sourced" pool: residential connections, residential IPs, residential bandwidth.

The difference between a criminal residential proxy botnet and Bright Data's SDK is a consent dialog. The infrastructure is identical.

XII. The Invisible Map: Kape + Bright Data = The Privacy Circle

This is where the 034 series connects.

Kape
034C: Owns 4 VPNs + review sites
Bright Data
034E: Operates 150M+ proxy IPs
Unit 8200
034D: The talent pipeline
Invisible
034B: Never registered "Israel"

Israeli-founded companies now control both sides of internet privacy infrastructure:

LayerCompanyWhat They ControlScale
VPN ProductsKape TechnologiesExpressVPN, CyberGhost, PIA, ZenMate4 of top 10 VPNs
VPN ReviewsKape TechnologiesvpnMentor, WizcaseMajor review sites
Proxy NetworkBright DataResidential proxy infrastructure150M+ IPs (SDK), 400M total
User AcquisitionHola NetworksFree VPN โ†’ exit node pipeline100M+ users
CombinedIsraeli-foundedThe tools, the reviews, AND the plumbingBillions of connections daily

A user who installs a Kape-owned VPN for privacy may have their traffic routed through infrastructure that Bright Data's SDK has turned into proxy nodes. The VPN they trust is Israeli-founded. The proxy network their traffic travels through is Israeli-founded. The review site that recommended the VPN is Israeli-owned.

This is not conspiracy. This is documented corporate structure. The privacy ecosystem is circular, and Israeli-founded companies own the circle.

Cross-reference with 034A: Israel appears in our honeypot with 7 IPs and zero hits. But Israeli-founded companies control infrastructure that touches hundreds of millions of devices globally. The absence isn't absence. It's architecture.

XIII. Investigative Q&A

Q: Is Bright Data's SDK truly "opt-in"?

Technically, yes. The SDK shows a consent screen that mentions Bright Data by name and links to a privacy policy. Users can decline and still use the app. CEO Or Lenchner says users "understood what they were saying yes to." But the consent screen says "occasionally" use resources โ€” while the configuration allows 200GB/month. In Uzbekistan and Oman, the SDK was configured to relay almost until battery death. Bright Data calls those "temporary legacy rules." The question is whether anyone reading "occasionally use free resources" on a TV game understands they're consenting to serve as an exit node for commercial web scraping. The courts haven't been asked this specific question yet.

Q: How is this different from a botnet?

The architecture is identical. Residential devices route traffic for third parties using the device owner's IP address. The difference is a consent dialog. Criminal botnets (IPIDEA, Aisuru) hijack devices. Bright Data's SDK asks permission. Both produce the same result: residential IPs serving as proxy exit nodes for commercial customers. Google dismantled IPIDEA in January 2026 as criminal infrastructure. Bright Data won two federal lawsuits validating its model. The consent screen is the entire legal distinction.

Q: Why did Meta and X/Twitter both lose?

Meta's case was fatally undermined by the fact that Meta had previously hired Bright Data to scrape competitors. You can't sue someone for doing what you paid them to do. X/Twitter's case failed because the judge ruled that restricting scraping of public data creates "information monopolies" โ€” a precedent that now protects the entire residential proxy industry. Neither court addressed the consent quality or the smart TV deployment.

Q: Does Bright Data have connections to Israeli intelligence?

No direct 8200 connections have been documented for Vilenski or Shribman (unlike Kape's Koby Menachemi). Bright Data's founders come from commercial tech (Jungo/NDS/Cisco). However, the Israel Chief Scientist Fund invested in Hola โ€” meaning Israeli government R&D money helped build the infrastructure that became the world's largest residential proxy network. And Israel's Deep Tech community is small enough that the distinction between "intelligence-adjacent" and "commercial" is measured in social connections, not organizational charts.

Q: What happened to the Philippines case?

Qurium published their forensic evidence. The DDoS against Karapatan was documented with HTTP header evidence directly identifying Luminati infrastructure. No legal action followed. No regulatory consequence. The attack against a human rights organization using commercial proxy infrastructure produced zero accountability. This is the enforcement gap that makes the business model work.

Q: How does this relate to AI training?

Anti-bot defenses block datacenter IPs. AI companies need to scrape the web at massive scale for training data. Residential proxy networks provide scraping that looks like real users from real homes. Bright Data explicitly markets to the AI industry. The Hacker News reports Bright Data "markets heavily to the AI industry." When your smart TV is an exit node, your living room is an AI training data collection point.

XIV. Conspiratorial Q&A

Q: When one company controls 150 million residential IP addresses, who controls the internet's identity layer?

IP addresses are the internet's identity system. When a website sees a request from 192.168.x.x in Ohio, it assumes a person in Ohio is browsing. But if that IP is a Bright Data exit node, the real requester could be an AI training pipeline in Tel Aviv, a corporate intelligence operation in London, or a state-sponsored scraping farm anywhere. 150 million residential IPs means 150 million false identities. Not forged documents โ€” forged locations, forged personas, forged intent. The identity layer of the internet is a service you can buy for $20 per gigabyte from an Israeli company owned by London private equity.

Q: If your smart TV is a proxy node, is your living room part of Israeli intelligence infrastructure?

No documented evidence links Bright Data directly to Israeli intelligence operations. But consider the architecture. An Israeli company with Israeli government R&D investment (Chief Scientist Fund) operates 150M+ residential exit nodes across every country on Earth. The SDK bypasses VPNs. It defeats instrumentation. It operates while you watch television. It uses military-grade evasion techniques documented by Include Security. Now ask: if Israeli intelligence wanted to route traffic through 150 million residential connections worldwide, would they build a different system than Bright Data already operates? The answer is uncomfortable because it's the same answer for every dual-use Israeli technology documented in this series: the capability exists whether or not it's being used for that purpose.

Q: Why did two federal judges rule in Bright Data's favor?

The legal outcomes are consistent with a system that cannot see what it's regulating. Courts evaluated "terms of use" and "public data" โ€” narrow legal questions. No court has ruled on: whether consent dialogs on smart TV games constitute meaningful informed consent, whether an SDK that bypasses VPNs and defeats instrumentation is compatible with user expectations, whether a 150M IP proxy network used to DDoS a human rights organization should face infrastructure-level regulation, or whether Israeli-founded companies should be able to patent the residential proxy model and use US courts to eliminate competitors. The courts ruled on what was asked. What wasn't asked is the actual story.

Q: What does it mean that the same nation produces both the VPN (privacy tool) and the proxy network (surveillance tool)?

This is the deepest finding of the 034 series. Israeli-founded companies now occupy both sides of the privacy equation. Kape sells you the VPN to hide. Bright Data operates the proxy network that uses residential connections as exit nodes. Hola provides the user acquisition. The 8200 pipeline provides the talent. The net effect: the nation with the highest per-capita cyber capability has built infrastructure that touches every layer of internet privacy โ€” from the tools that promise privacy to the networks that can compromise it. Whether these companies collaborate is irrelevant. The capability architecture exists. In intelligence, capability is what matters. Intent is what you can never verify.

Q: Is the residential proxy model the civilian face of state surveillance infrastructure?

Consider: NSO Group sells Pegasus to governments for targeted surveillance (034D). Bright Data sells residential proxy access to corporations for mass data collection. Both are Israeli. Both monetize access to other people's devices. Both operate under Israeli export control. The difference is granularity: Pegasus targets individual phones; Bright Data routes through millions. One is classified as a weapon. The other is classified as a data collection tool. But a 150M-node network that can route any traffic through any residential IP in any country is, by definition, a surveillance-capable infrastructure. Classification is a policy choice, not a technical fact.

Series Cross-References

Methodology

This investigation synthesizes: (1) Include Security's reverse engineering of the Bright Data iOS SDK (June 2026); (2) The Hacker News reporting including Bright Data's official response and CEO statement; (3) Qurium Media Foundation's forensic analysis of the Philippines DDoS attack (August 2021); (4) Wikipedia corporate histories for Bright Data, Hola VPN; (5) Federal court decisions in Meta v. Bright Data and X Corp v. Bright Data; (6) LSN honeypot data (TI-016 Phantom Pipes residential proxy verification); (7) Cross-reference with 034A-D investigations in this series; (8) Dossier vector database searches across 35+ published investigations. All sources cited. Where interpretation extends beyond documented evidence, it is marked as [INFERRED].

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Invisible Nation โ€” 5 / 8 Next โ†’