The 2026 Proxy Purge: What Really Happened to 922, PIA S5 and LunaProxy
If you run scraping pipelines or multi-account infrastructure, your Twitter feed in 2026 has looked like an obituary column: 922Proxy — dead. PIA S5 — client shut down. LunaProxy, PyProxy, IP2World, 360Proxy — domains not even resolving.
This wasn't a coincidence, and it wasn't a market downturn. Here's what actually happened, verified from registry data and public threat-intelligence reports — and what it means for anyone whose infrastructure depends on residential proxies.
One takedown, many brands
In January 2026, Google's Threat Intelligence Group disrupted the network behind IPIDEA. What most users never knew: IPIDEA wasn't one provider. Analysts published a list of affiliated brands, and it reads like the entire budget-S5 aisle: 922Proxy, 360Proxy, LunaProxy, PIA S5, ABCProxy, IP2World and more.
These "different providers" with different logos, different dashboards and different Telegram support channels were, at the infrastructure level, largely one pool. When the core got disrupted, the storefronts died together. We ran DNS checks across the brand list in July 2026: 922proxy.com, 922s5.com, lunaproxy.com, pyproxy.com, abcproxy.com — NXDOMAIN, all of them.
The zombie-brand problem
Here's where it gets dangerous. The demand didn't die with the brands — Google autocomplete still suggests "s5 proxy 922" as the top completion for "s5 proxy". That orphaned demand attracts predators:
- Clone sites registering hyphenated or swapped-TLD variants of dead brands, selling "the same service" through a lookalike dashboard. We found several already ranking. Before you trust a "revived" brand, check the domain's registration date via RDAP — a "10-year-old provider" on a domain registered in March 2026 is not the provider you knew.
- Balance-recovery scams targeting users whose prepaid IPs got locked inside dead clients.
The 9Proxy scare — a different story
9Proxy went dark on June 28, 2026 and the community immediately filed it under "seized like the rest". The registry data never supported that: routine registrar lock, nameservers untouched, domain paid through 2027. It came back in mid-July — an unexplained outage, not a takedown. Different failure mode, same lesson: you can't tell an outage from a seizure from the inside, and your balance is hostage either way.
Engineering takeaways
- Treat proxy providers like any other third-party dependency. Two suppliers minimum, health-checked, with traffic you can shift in minutes. If your scraper has retry logic but your proxy layer has a single vendor, you've just moved the SPOF.
- Prefer non-expiring, pay-as-you-go balances. Subscriptions and time-boxed GB packs maximize your loss in a shutdown. Non-expiring GB means your exposure is only what you haven't burned yet.
- Buy through channels with conversion paths. PIA S5's desktop client died, but the network's GB API kept working — users who bought per-IP through the client got stuck; users on the API just kept going. When we route customers at ProxyUniverse, we now explicitly prefer API-deliverable products for exactly this reason.
- Vet suppliers with registry data, not marketing. RDAP is free. Domain age, registrar history, nameserver stability — five minutes of checking beats a locked balance.
The uncomfortable conclusion
The budget residential proxy market runs on infrastructure whose ownership you can't audit, sold through brands that are sometimes just skins. That's not a reason to avoid it — the economics are unbeatable for a lot of legitimate work — but it is a reason to architect for provider death as a routine event, not an exception.
The next purge will come. The only question is whether your pipeline notices.
I aggregate and monitor a dozen residential networks at ProxyUniverse — one panel, per-GB pricing, no subscriptions. If your provider died this year, the catalog is a decent place to rebuild from.

Top comments (0)