Advertisement
Digital Intelligence Hub

Someone Used My IP Address for Illegal Activity: What Actually Happens (2026)

Expert Analyst Sarah Thompson
Publish Date Aug 26, 2026
Advertisement

If someone used your IP address for illegal activity, the first thing that happens is administrative, not criminal: a copyright holder or an investigator asks your provider who held that address at that timestamp. Your provider answers with the account holder's name. That is you. Nothing at that stage establishes that you did anything, and courts have said so plainly.

The gap between "your account" and "you" is the entire subject of this guide. In 2018 the Ninth Circuit held that being the registered subscriber behind an infringing address, on its own, does not support a reasonable inference that the subscriber infringed. Eight years later that reasoning still governs — and it still does not stop the letter arriving.

Advertisement

Two things changed in 2026 and both matter to you. The Supreme Court decided Cox v. Sony Music in March, which shifted enforcement pressure off providers and back onto individual subscribers. And in March the FBI issued a public advisory on residential proxy networks — commercial services that route strangers' traffic through ordinary home connections, which is now one of the most common reasons an innocent household appears in a criminal log.

Sarah Thompson, Network Intelligence Analyst, explaining what happens when someone uses your IP address for illegal activity at TrustMyIP.com
Author: Sarah Thompson Network Intelligence Analyst

Most of my work is attribution: taking a logged address and a timestamp and working out what they actually support. Earlier this year a household came to me with a provider letter naming their account in a federal filing. Their line sat behind carrier-grade NAT, and a cheap streaming box on the network carried a proxy SDK. Two independent reasons the IP address proved almost nothing about who typed what.

I need to be direct about the limit of my expertise. I am a network analyst, not an attorney, and nothing here substitutes for one — deadlines in these matters are short and jurisdiction changes the answer. What I can give you is the technical half: what an address genuinely establishes, how the subscriber record gets pulled, and which evidence to preserve before it ages out of your provider's logs.

Quick Answer: When Someone Uses Your IP Address

An IP address identifies an internet account, not a person, so being the subscriber does not make you the offender under US law. Expect a provider notice or subpoena first, with a short window to respond before your identity is released. Start by documenting your own connection with an independent record of what your address resolves to.

What Does an IP Address Actually Prove About You?

An IP address proves that a particular internet account was assigned that number during a particular window. It does not identify a person, a device, or any intent to commit illegal activity. Every US court that has examined the question closely reaches the same conclusion, because a single address routinely serves a household, a guest network, a shared building, or thousands of mobile subscribers at once. The subscriber name is a starting point for an investigation, not a finding of fact.

Advertisement

The clearest statement of that principle came from the Ninth Circuit. In the appellate opinion in Cobbler Nevada v. Gonzales, the court affirmed dismissal of a copyright claim against a man whose only connection to the infringement was that he paid for the internet service and received the notices. The address belonged to an adult foster care home with an open connection used by residents and visitors alike.

Two details from that case deserve more attention than they usually get. Cobbler had sent roughly 400 infringement notices to the address before filing anything. And Gonzales, who did nothing wrong, still spent over $17,000 in legal fees to prove it, which the court later ordered the plaintiff to pay.

Attribution Versus Identification

Attribution — establishing which network a packet traversed — is a solved technical problem, and it is the only part an address answers well. Identification, meaning which human sat at which keyboard, is not, and no log solves it. Investigators bridge that gap with everything except the address: device forensics, account logins, payment trails, and physical presence. The address opens the file. Something else has to close it.

Geolocation makes the gap wider still. Commercial databases estimate a location from registry records and routing measurements, and when they cannot resolve one, they substitute a default. A Kansas farmhouse near Potwin became the default location for roughly 600 million addresses, and the residents spent years receiving federal agents, sheriffs and ambulances responding to activity that had nothing to do with them. If you want the boundaries of what an address discloses, our breakdown of what an address can and cannot reveal about a household covers the mechanics.

Advertisement

So an IP address is weak evidence on its own. Understanding exactly how yours ended up in somebody else's log is the next step, and there are more routes than most people realise.

How Did Your IP Address End Up Attached to Illegal Activity?

Your IP address reaches someone else's crime log through one of seven routes, and only one of them involves you. Someone on your Wi-Fi used it. A compromised device on your network routed strangers' traffic. Malware enrolled a device in a botnet. Your provider shares that address among thousands of subscribers. The address was reassigned and the timestamp belongs to a previous holder. Or an attacker forged it outright.

Route What Happened How Provable It Is
Open or weak Wi-Fi A neighbour, guest or passer-by used the connection Router logs help; most home routers keep almost nothing
Residential proxy SDK An app or smart device sells your bandwidth as an exit node Detectable — the address appears in proxy reputation feeds
Botnet infection Malware on a router, camera or DVR routes attack traffic Forensics on the device usually shows it
Carrier-grade NAT Thousands of subscribers share one public address Strong — the provider needs port-level logs to narrow it
Dynamic reassignment The address moved to your line after the logged event Strong — provider lease records settle it
Spoofing An attacker forged your address in packet headers Harder — depends on the protocol and what was logged
Someone in the household A resident, roommate or child did it Device forensics normally answers this quickly

Two of those routes carry unusual weight right now. Carrier-grade NAT — a provider technique that puts many subscribers behind one shared public address — is standard on mobile networks and increasingly common on fixed lines, and it makes single-address attribution close to meaningless without port and timestamp detail. Spoofing is rarer but real, and our guide to how an address can be forged to look like yours walks through where it works and where it fails.

The proxy route is the one growing fastest, and it deserves its own section. First, though, the process that most people actually encounter: the letter from the provider.

What Happens When a Copyright Holder Traces an IP to You?

A rights holder monitors file-sharing swarms, logs IP addresses, then sues an unnamed John Doe defendant identified only by that number. The court grants permission to subpoena your provider. Your provider notifies you and gives you a window — usually around 30 days — to object before releasing your name. If you do nothing, your identity goes to the plaintiff's attorneys and a settlement demand follows.

Advertisement

The volume here is larger than most people assume. Strike 3 Holdings has filed over 20,000 federal lawsuits since 2017, and reporting from March 2026 put its first-quarter filings at 807 cases across 22 states and the District of Columbia. Fresh waves landed through April and May 2026, and new Southern District of New York filings appeared as recently as 21 August 2026. Initial demands commonly run from $3,000 to $30,000 depending on how many titles appear in the exhibit.

Stage What Occurs Your Position
Monitoring A vendor logs your address in a sharing swarm You know nothing yet
John Doe filing Suit filed against the address, not a name Still anonymous
Subpoena granted Court authorises the provider to disclose the subscriber Still anonymous
Provider notice Your provider writes to you with a deadline Decision window opens — roughly 30 days
Disclosure Name and address released to plaintiff counsel Anonymity ends
Demand or naming Settlement demand, or you are named and served Ignoring a summons risks default judgment

Does a Motion to Quash Work?

A motion to quash — a request asking the court to void the subpoena before your provider answers it — keeps you anonymous while the court considers it, typically four to eight weeks. Defense practitioners are consistent and blunt about the odds: federal courts usually find these subpoenas procedurally sound and deny the motion. Some judges also require the movant to file under their real name, which defeats the purpose entirely.

The timing detail nobody mentions

There is no federal law requiring US providers to retain address-assignment logs for any set period. Publicly disclosed figures cluster between roughly six and eighteen months, and cases have been dismissed because the records had already aged out. If you need to establish which address your line held on a given date, gather that proof early — and keep your own dated record of which IP addresses your line has held from now on.

Copyright is the civil track and the most common one. The route that puts genuinely innocent households into criminal logs is different, and it grew sharply this year.

Is Your Connection Being Used as a Residential Proxy Exit?

A residential proxy routes a paying stranger's traffic through your home connection so their activity appears to originate from your address. Some households consent through an app's terms. Most never learn it happened. When that traffic includes fraud, credential stuffing or intrusion attempts, the IP address in every investigative log is yours — which is precisely why criminals pay for the access.

The FBI treated this as urgent in 2026. The Bureau's March 2026 public service announcement warned that threat actors route illicit traffic through home and small-business networks using ordinary consumer devices — streaming boxes, digital picture frames, tablets, routers — and noted that many owners never consented and never knew.

Scale figures from this year make the problem concrete. Gen Digital reported 7.4 million malicious incidents tied to residential proxy traffic since January 2026, affecting 572,000 users in its own telemetry alone. GreyNoise analysed 4 billion sessions between late November 2025 and February 2026 and found that 39% of unique addresses hitting network edges came from home connections, with 78% disappearing before any reputation system could flag them.

Where the Proxy Code Comes From

Three supply routes dominate. Developers embed a proxy SDK in a free app in exchange for payment per install. Cheap consumer hardware ships with the software already present. And malware enrolls devices the owner never chose to volunteer.

  • Smart TVs. Researchers at Spur Intelligence scanned thousands of apps across LG webOS and Samsung Tizen and found proxy SDKs embedded in 42.5% of LG webOS apps examined, reported in July 2026.
  • Takedowns keep finding more. Google and partners disrupted the IPIDEA network in January 2026; on 3 July 2026 the FBI, Google, Lumen's Black Lotus Labs and the Shadowserver Foundation dismantled NetNut, built on over two million hijacked devices.
  • The supply survives the takedown. Nokia's 2026 threat reporting estimates 8 to 9 million residential proxy endpoints worldwide across more than twenty botnet families.

Why this matters legally, not just technically

A residential proxy exit produces the exact evidentiary picture an investigator expects from a guilty household: a real consumer address, on a real consumer provider, behaving like a person. Nothing in the traffic announces that the address does not belong to whoever is behind it. The only way to surface it is to test the address against proxy reputation data and inspect the devices. Start by checking whether you can see if your connection is being flagged as a proxy exit, and read our explainer on what a residential proxy network actually is to understand the market behind it.

That is the technical landscape as of August 2026. The legal landscape shifted underneath it in March, in a way that affects you more than it affects your provider.

Did the 2026 Supreme Court Ruling Change Anything for Subscribers?

Yes, though not in the direction the headlines suggested. On 25 March 2026 the Supreme Court decided Cox Communications v. Sony Music Entertainment unanimously, holding that a provider is not contributorily liable merely for continuing to serve accounts it knows are associated with infringement. Liability now requires intent, shown through inducement or through a service tailored to infringement. The pressure came off providers. It did not come off subscribers.

The background matters. Sony's monitoring vendor sent Cox 163,148 notices over roughly two years, a Virginia jury found Cox liable, and the award reached $1 billion before the Fourth Circuit vacated it. Justice Thomas wrote for the Court, and Justice Sotomayor's separate opinion argued the majority left providers free to serve known infringers without consequence. You can read the full opinion on the Supreme Court's site.

What It Means at Your Kitchen Table

Justice Thomas described the technical reality precisely: providers know which address maps to which account, and cannot distinguish the individual people using it. That observation, coming from the Supreme Court, is useful language for any subscriber arguing that the account record is not an identification.

Practically, though, the consequence runs the other way. Rights holders who can no longer squeeze providers have one remaining target — the subscriber. Strike 3's filing pace through 2026 is consistent with exactly that shift. Expect more direct John Doe actions, not fewer, and expect your provider to feel less obligation to fight the subpoena on your behalf.

Civil claims are one track. A criminal investigation runs on different rules and a much lower entry threshold, which is where most of the fear in this topic actually lives.

Can Police Search Your Home Based Only on an IP Address?

In most US jurisdictions, yes. Courts have generally held that tracing illegal activity to an IP address supported by subscriber records gives probable cause to search the residence and its devices, even where the network was unsecured, on the reasoning that residents are the likeliest users. Probable cause means reasonably likely. It is a far lower bar than the standard required to convict anyone.

That distinction is the single most important thing to understand, and it is where public discussion of this topic usually goes wrong. Courts saying an address is not a person, and courts approving searches based on one, are not in conflict. They are answering different questions at different stages, with different evidentiary thresholds.

Stage Standard Applied Is the IP Address Enough?
Subpoena to the provider Relevance to the case Yes — routinely granted
Search warrant for the home Probable cause — reasonably likely Usually yes, per most courts
Civil copyright liability Preponderance of the evidence No — Cobbler requires more
Criminal conviction Beyond a reasonable doubt No — device evidence carries the case

Read the right-hand column downward and the pattern is clear. The IP address gets investigators through the door. What they image off your devices becomes the case. By trial, the prosecution has usually stopped relying on that number entirely.

The wider Fourth Amendment position is still moving. The Supreme Court granted review in Chatrie v. United States in January 2026 and heard argument on 27 April 2026 on whether a geofence warrant violated the Fourth Amendment. That case concerns location data rather than addresses, but it sits in the same doctrinal territory, and as of August 2026 no decision has issued.

Knowing the standards is one thing. Knowing what to do in the seventy-two hours after a letter arrives is what actually changes outcomes.

What Should You Do the Day the Notice Arrives?

Act on the deadline first and the argument second. Provider notices carry a hard date, and missing it releases your identity by default. Before that date you want three things in place: legal advice appropriate to the track you are on, a preserved snapshot of your own network, and a written timeline. Preservation matters most, because the evidence that exonerates a household is usually the evidence that disappears fastest.

First 72 Hours — Preservation Checklist

1 Diary the deadline before anything else

Read the letter for the exact date your provider will disclose your details. Every other decision fits inside that window. Missing it forfeits the choice entirely.

2 Speak to an attorney in the right specialism

A civil copyright matter and a criminal investigation need different counsel. Many copyright defense practitioners offer a free first consultation. Do this before you reply to anyone.

3 Photograph your network exactly as it stands

Screenshot the router's connected-device list, DHCP table, port-forwarding rules, UPnP state and firmware version. Note every person with the Wi-Fi password. Do not change a setting yet.

4 Capture your address and its reputation today

Record your current public IP address, the network that announces it, and whether reputation feeds already list it as a proxy exit. Dated screenshots are worth far more than a recollection months later.

5 Inventory every device on the line

List smart TVs, streaming boxes, cameras, tablets and anything cheap and always on. Those are the devices proxy SDKs and botnets favour, and their presence is part of your account.

6 Write the timeline while it is fresh

Who lived there, who visited, who had the password, when the router changed, when devices arrived. Then see which services your public address answers on and save that result with the rest.

When I build this file for a household, step three carries the most weight and takes the least time. A router's connected-device list, captured before anyone touches anything, has settled more of these questions in my experience than any argument about the law.

Everything above is about adding to the record. The next section is about the actions that destroy it, and they are more tempting than they sound.

What Should You Never Do After Receiving a Notice?

Do not wipe, reset or discard anything. Deleting files, factory-resetting a router or replacing a hard drive after you know about a legal matter exposes you to spoliation findings — sanctions for destroying evidence — and converts a defensible position into an inference of guilt. The forensic picture that clears an innocent household lives on the same devices that a panicked owner erases first.

Four Moves That Consistently Backfire

  • Ignoring a court summons. A subpoena notice and a summons differ. Ignoring the second risks a default judgment entered against you without argument.
  • Calling the plaintiff's attorney yourself. They represent the other side. Anything you volunteer helps them price the demand, and defense counsel routinely advise routing all contact through a letter of representation.
  • Posting the details publicly. Court filings are public and plaintiff firms read forum threads. Several practitioners note that a motion filed under a real name defeats the anonymity it was meant to protect.
  • Assuming a VPN erases the question. A VPN changes what happens next; it does nothing about a timestamp already logged against your line months ago.

Preserve

Router state, device inventory, dated address records, household timeline, the notice itself, and every envelope and email with its arrival date.

Postpone

Firmware updates, factory resets, device disposal, password changes on the router, and any cleanup — until counsel tells you the preservation duty allows it.

Once your lawyer confirms you may act, hardening the connection is the right long-term answer, and our walkthrough on how to close the openings attackers look for first covers the sequence. The same technical limits that constrain you also constrain the people investigating you, which is worth remembering when the file feels one-sided.

None of this is legal advice, and none of it substitutes for counsel. What it does is stop you from losing the technical evidence before a lawyer can use it.

The Short Version

Someone using your IP address for illegal activity puts your name in a file, not a charge on a docket. An IP address identifies an account, and the Ninth Circuit confirmed in Cobbler Nevada v. Gonzales that subscriber status alone does not make you the infringer. That protection is real in civil court and much weaker at the search-warrant stage, where probable cause is a low bar and the devices in your home become the actual evidence.

Three current facts should shape your response. The Supreme Court's March 2026 decision in Cox v. Sony pushed enforcement pressure from providers onto individual subscribers. Strike 3 Holdings filed 807 federal cases in the first quarter of 2026 alone. And the FBI's March 2026 advisory confirmed that residential proxy networks route strangers' crime through ordinary home connections every day.

So do the boring, decisive things. Diary the deadline, call an attorney in the right specialism, and preserve your network exactly as it stands before touching anything. Then build the technical record: capture what your address resolves to, check whether it already carries a proxy or abuse reputation, and understand how providers hand out and recycle addresses on a lease, because a reassignment can decide the whole question. Evidence gathered this week is worth more than any argument made next year.

Build Your Record Before You Need It

Capture what your address resolves to, which network announces it, and whether it already carries an abuse reputation. Dated evidence beats memory every time. Free, instant, no account.

Frequently Asked Questions

Q Can I get in trouble if someone else used my IP address for illegal activity?

A
Being the account holder is not the same as being the offender. In Cobbler Nevada v. Gonzales the Ninth Circuit held that subscriber status alone does not support a reasonable inference of infringement. You can still be investigated, subpoenaed or sued as a John Doe, so respond to any deadline rather than assuming the law protects you automatically.

Q Is an IP address enough evidence to convict someone?

A
No. An IP address identifies an internet account during a time window, not a person or a device. Prosecutors build cases on what forensic examiners recover from seized computers and phones, not on the address itself. By trial the address usually functions only as the reason investigators looked at that household in the first place.

Q Can police search my house based only on my IP address?

A
In most US jurisdictions courts have generally allowed it. Probable cause means reasonably likely, which is a far lower standard than conviction requires, and judges have accepted that residents are the likeliest users of a connection even when the Wi-Fi was open. The search happens first; questions about who actually did it come later.

Q What should I do if my ISP sends me a copyright subpoena notice?

A
Note the deadline immediately, because missing it releases your identity by default. Contact an attorney who handles copyright defence, many of whom offer a free first consultation. Preserve your router settings, connected-device list and network state exactly as they are, and change nothing until counsel confirms your preservation duty allows it.

Q Does a motion to quash actually stop the subpoena?

A
It can, but defence practitioners consistently report low success rates. Federal courts usually find these subpoenas procedurally adequate and deny the motion, and some judges require the filing to carry your real name, which defeats the anonymity you were protecting. Filing one typically buys four to eight weeks rather than ending the case.

Q How can my home internet be used for crime without me knowing?

A
Residential proxy networks route strangers' traffic through ordinary household connections, so the activity appears to originate from your address. The FBI warned about this in March 2026, noting that streaming boxes, tablets and routers are commonly enrolled without the owner's knowledge. Malware, botnets and app SDKs all supply these networks with home connections.

Q How long do ISPs keep records linking an IP address to me?

A
No federal law sets a required retention period for US providers. Publicly disclosed figures cluster roughly between six and eighteen months for address-assignment logs, and policies differ by carrier. Cases have been dismissed because the records aged out, so gather evidence about your own connection early rather than waiting for a dispute to develop.
Sarah Thompson
Verified Content Expert

Sarah Thompson

Network Intelligence Analyst

Sarah Thompson is a network intelligence analyst based in Seattle, Washington, with over 12 years of experience in IP geolocation systems, WHOIS forensics, domain intelligence, and network data accuracy. At Trust My IP, she focuses on the data integrity layer — investigating geolocation discrepancies, mapping domain ownership through WHOIS forensics, and documenting what network-level data actually reveals about users and organizations. Her work is grounded in the understanding that network data is only useful when you know exactly how reliable it is.

Helpful Insight?

Share with your professional network