Skip to content
ProxyForge

Your proxy provider shut down: a 72-hour recovery playbook

ProxyForge engineeringUpdated 8 min read

If your proxy provider shut down without warning, spend the first four hours confirming the failure, stopping retry loops that waste budget and flood logs, scrubbing credentials from logs and informing the people who depend on the data. Use the next twenty hours to restore the most critical jobs on a replacement provider and record every data gap. Spend the remaining two days restoring everything else, backfilling what can be backfilled and reviewing what made the failure so expensive.

This is no longer a hypothetical: a top-tier residential provider was seized by federal authorities in July 2026 after its network was found to be built on compromised devices, and its customers lost access with no notice. The playbook below is written for that situation, but most of it applies to any sudden, permanent loss of a proxy vendor.

Hours 0 to 4: confirm, contain, communicate

The first hours decide how much the incident costs. The aim is not yet to restore service; it is to stop making things worse and to make sure the right people know.

Confirm that it is a shutdown, not an outage

A regional outage and a permanent shutdown look similar from inside a scraper. Check:

  • Whether every gateway, pool and protocol fails, or only some.
  • Whether the gateway hostnames still resolve, and whether connections are refused, time out or return authentication errors.
  • The provider's status page, dashboard, support channels and account manager.
  • The provider's website itself. A seized domain often shows a notice from the authorities.
  • Public reporting and statements.

If the evidence says your proxy provider shut down for good, act on that assumption. Waiting a day for a provider that is not coming back costs a day of data.

Freeze retries that burn budget

Proxy clients faced with a dead gateway retry, and schedulers re-queue failed jobs. Left alone, this fills queues, exhausts worker pools, floods logs and, once any fallback is configured, can drain a replacement account's balance in minutes by replaying a backlog at full speed. Pause or circuit-break the affected jobs explicitly. Stopping them cleanly is better than letting them fail noisily for three days.

Stop credentials leaking into logs

Proxy URLs carry credentials, and many HTTP clients include the full proxy URL in exception messages. A shutdown produces thousands of those exceptions, which then land in log aggregators, alerting channels and tickets. Search recent logs for the provider's hostname, purge or restrict what you find, and fix the logging so the replacement's credentials do not follow the same path.

Also consider what else crossed the failed network. With HTTPS through a CONNECT tunnel, the proxy sees the destination host but not the content. Anything sent over plain HTTP, including logins to target sites or API keys in query strings, was visible to the provider's infrastructure, which in a seizure is now in someone else's hands. Rotate those secrets.

Inform stakeholders

Tell the owners of downstream dashboards, models and reports that data will be missing or late, and for which feeds. Tell finance that any prepaid balance is probably unrecoverable. If the provider was seized over how its network was built, tell legal and security as well: your traffic may have exited through devices whose owners never consented, and they will want to assess that and decide what to preserve.

Hours 4 to 24: restore what matters most

Rank workloads by the cost of a missing day

Not everything needs to come back today. Rank workloads by what a gap costs: data that can never be re-collected, such as a day's prices or search rankings, outranks data that can be fetched later. Contractual deliveries to clients outrank internal analytics. Pick the top few and restore those first.

Stand up a replacement for the critical jobs

Choose a replacement you could defend in a week's time, not just one that can take a card payment in five minutes. A short due-diligence pass is possible even under pressure: ask how addresses are sourced, whether sourcing is independently audited, and whether the provider publishes a supply-chain policy naming what it prohibits. Our guide to verifying a proxy provider's IP sourcing lists the documents that answer those questions quickly.

A short list to send to candidates on day one:

  1. Which channels supply your residential and mobile addresses, and where is the policy that names prohibited channels published?
  2. When was sourcing last audited by an independent party, and can we see the attestation under NDA?
  3. For datacenter and ISP addresses, which organization is the registrant of the ranges and which ASN announces them?
  4. Can you replicate our previous endpoint, session and authentication format, or what exactly will change?
  5. What is the maximum sticky session duration, and what happens when an exit address drops mid-session?
  6. Can we pay as we go, set a hard spend cap, and start today without a long-term commitment?
  7. How do you meter usage, and are failed requests billed?
  8. Who do we contact when something breaks in the first week, and how fast do they answer?

Answers that are vague on the first three questions are a reason to keep looking, however quickly the account can be opened.

Match the proxy type to the job rather than to whatever the old provider sold you. Stateless fetches on tolerant targets may run well on ISP or datacenter addresses; strict targets may need residential. Our comparison of residential vs ISP vs datacenter proxies covers the trade-offs. Bring jobs back behind a single configuration value per pool rather than editing job code, so the next change is a configuration change. Restart them with reduced concurrency and a daily budget you watch, then raise both once validated success looks normal.

Update IP allowlists at partners

If partners, data vendors or client APIs allowlisted the old provider's static egress addresses, those integrations are down until they allowlist new ones. This is usually the longest lead time in the whole recovery, so request the change today. Replacement static addresses from ISP or datacenter pools can be issued immediately; residential and mobile addresses cannot be allowlisted at all, because they change.

Log every data gap as you go

For each feed, record the window that is missing, which targets and markets it covers, and whether it can be backfilled. Mark the gap in the dataset itself, not only in a ticket, so nobody later reads a missing day as a zero. This log becomes the backfill plan and the evidence for the review.

Hours 24 to 72: restore the rest and review

Restore remaining workloads

Bring back the remaining jobs in priority order. For each, validate content rather than trusting HTTP status codes; a new provider can return 200s full of challenge pages until targeting and session settings are right. Handling 403 and 429 errors covers the classification.

Backfill what can be backfilled

Some data can be re-collected: catalog pages, public filings, archives, listings that stay up. Schedule those backfills at a controlled rate so they do not trigger blocks on targets that also carry your live jobs. Some data cannot: a Tuesday's prices, rankings or ad placements are gone. Record those gaps as permanent and tell the people who use the data.

Run a post-incident review

Keep it blameless and specific. Useful questions:

  • How long did it take to confirm the shutdown, and what would have shortened it?
  • Which jobs had hard-coded provider details, and why?
  • Which third-party allowlists did nobody know about?
  • What did the lost prepaid balance and missing data cost?
  • What did we know about the provider's sourcing before buying, and what did we fail to ask?

Hardening so the next shutdown costs less

Teams whose proxy provider shut down in July learned that the expensive part was rarely the provider itself. It was the single point of failure, the hard-coded details and the missing due diligence that the event exposed.

Add a second provider

Keep a second provider warm with a small share of real traffic, so failover is a configuration change to a network you already know works on your targets. The guide on how to switch proxy providers describes the traffic-splitting layer that makes this cheap to maintain.

Put an abstraction in front of providers

Every job should read its proxy settings from one place, labeled by provider in logs and metrics. Recovery then means changing configuration, not searching repositories at midnight.

Negotiate exit terms into contracts

Ask for notice periods for service termination, treatment of prepaid balances, data deletion on exit, and whether large prepaid commitments can be replaced with pay-as-you-go or monthly billing. A large prepaid balance is an unsecured loan to your vendor.

Do provenance due diligence before you buy

The customers of the seized network did not lose service because of an engineering failure. They lost it because the network rested on devices that were never legitimately acquired. The strongest protection is buying from a provider whose supply would survive scrutiny: a public supply-chain policy, independent sourcing audits, consent records you can sample, and datacenter ranges you can check against registry records. Our proxy provider due diligence checklist and the explainer on residential proxy botnet risk set out what to ask.

Recovering onto ProxyForge

If you are recovering from a shutdown now, our engineers can map your previous setup and mirror its endpoint structure, session syntax and authentication format on our gateway, so jobs come back with minimal change. Accounts are pay-as-you-go from a prepaid wallet with no monthly minimum, so a replayed backlog can only spend what the wallet holds. ISP and datacenter addresses are static and can be given to partners for allowlisting.

Our residential network is built from consented, compensated opt-in peers, under a public supply-chain policy that prohibits compromised devices, botnets and resold supply, and sourcing is audited independently twice a year. The migration page explains the process, and you can contact us to reach an engineer directly.

FAQ

Related questions

Can I get my prepaid proxy balance back after a provider is seized?

Rarely in the short term. Funds held by a seized business are usually frozen along with its other assets, so treat the balance as lost for planning purposes and record it for finance and for any later claims process.

Is my company liable because our traffic went through a network of compromised devices?

Using a commercial proxy service in good faith is different from operating a botnet, but the question belongs with your legal counsel. Preserve contracts, invoices and records of the due diligence you did before buying, since those show what you knew and when.

How can I tell if a proxy outage is temporary or a permanent shutdown?

Temporary outages usually come with status-page updates, partial service and responsive support. A permanent shutdown tends to show as every gateway failing at once, silent support channels, a changed or seized website, or public statements from the provider or authorities.

Should I rotate credentials that were only used with the failed proxy provider?

Yes. The proxy credentials themselves are worthless once the service is gone, but any secret that crossed the provider in plain text, such as target-site logins over unencrypted HTTP, should be treated as exposed and rotated.

Start with the evidence

Ask us to trace an address, send you the sourcing attestation, or price your current volume at our published rates. A named engineer will help with your technical and procurement review.

One business day, from a named engineer.