All news
cybersecurityregulationlegal

US Charges Russian 'Bulletproof' Hosts in $62M Cybercrime Case

16 Jul 2026

What happened

The U.S. Department of Justice has unsealed an indictment against three Russian nationals — Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova — along with two web hosting companies, Media Land and ML.Cloud, accused of providing so-called "bulletproof" hosting infrastructure to ransomware operators. The defendants reportedly reside in St. Petersburg, Russia.

According to the indictment, this infrastructure allegedly supported ransomware groups including LockBit, BlackSuit, and Play in attacks that spanned more than 20 U.S. states, generating roughly $62 million in criminal proceeds. Notably, the charges themselves date back to 2024, but the indictment was only unsealed publicly this week — a gap that underscores how long federal cybercrime cases can take to surface.

U.S. Assistant Attorney General A. Tysen Duva said the hosting providers' actions "put the American public at risk." The case follows earlier action by the U.S. Treasury, which had previously sanctioned both Media Land and ML.Cloud.

What we still don't know

Several key details remain unclear from available reporting:

  • The specific statutes or charges the defendants face
  • The exact number of businesses affected (described only as "dozens")
  • Whether the defendants have been apprehended or remain at large in Russia
  • The timeframe over which the $62 million in proceeds accumulated
  • Precisely how Media Land and ML.Cloud technically enabled the ransomware operations
  • The exact timing of the Treasury sanctions relative to the criminal charges

Why founders should care

This case is likely relevant to founders in a few concrete ways:

  • Vendor due diligence may matter more. Businesses using third-party or offshore hosting providers could unknowingly rely on infrastructure connected to cybercriminal networks — a risk worth checking against sanctions lists, particularly for companies with international vendor relationships.
  • Enforcement may be accelerating, but slowly. The fact that a 2024 indictment is only being unsealed now suggests legal processes against cyber infrastructure providers can take significant time. Founders assessing regulatory risk timelines should factor in that enforcement visibility often lags actual government action.
  • Threat intelligence and compliance tooling could see rising demand. As scrutiny of hosting providers increases, there's a reasonable chance that enterprises will seek more transparent, compliance-focused hosting and cybersecurity vendors — a potential opening for startups building infrastructure vetting or threat intelligence products.
  • Ransomware groups are resilient. Even with this indictment, groups like LockBit, BlackSuit, and Play may continue operating through similar bulletproof hosting arrangements elsewhere, meaning the underlying risk to businesses is unlikely to disappear overnight.

The bigger picture

The unsealing of this indictment signals that U.S. authorities are willing to pursue not just ransomware operators directly, but the infrastructure providers that enable them. However, with sanctioned entities operating internationally, enforcement and asset recovery could remain complicated — a reminder that legal action alone may not fully neutralize the underlying threat landscape.

Sources