Policy & Regulation
Media Land and ML.Cloud owners charged in US cybercrime case
U.S. prosecutors charged three Russian nationals and two web hosts for allegedly running infrastructure that shielded ransomware attacks, netting some $62 million in proceeds.
U.S. prosecutors have unsealed an indictment charging three Russian nationals and two web hosts with hacking, conspiracy, and money laundering over their alleged roles in hosting cyberattacks. The three accused, Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova, reside in St. Petersburg and are accused of owning and running Media Land and ML.Cloud, two web hosts that allegedly provided criminals and state-backed hackers with web hosting and infrastructure support for carrying out cyberattacks.
Operating from St. Petersburg, the accused allegedly ran what prosecutors describe as bulletproof hosting operations — services that deliberately ignore abuse complaints and law enforcement requests so that malicious customers can keep operating. Those services allegedly shielded ransomware gangs including LockBit, BlackSuit, and Play, enabling attacks on dozens of U.S. businesses across more than 20 states that netted some $62 million in proceeds. The two companies had previously been sanctioned by the U.S. Treasury, the agency that also bars Americans and U.S. businesses from transacting with the accused or their companies, for allowing the ransomware gangs to use their infrastructure.
The Russians were first charged in 2024, but the indictment was unsealed this week. According to the U.S. Department of Justice, the federal agency prosecuting the case, the web hosts deliberately aimed to shield their customers from law enforcement demands and takedowns. The suspects are unlikely to be captured, given that they are located in Russia, where extraditions to the U.S. are rare. In a statement, U.S. Assistant Attorney General A. Tysen Duva said the web hosts’ actions put the American public at risk, adding: “We will continue to dismantle these networks and protect our critical infrastructure from cybercriminals at home and abroad.”
Why it matters
The indictment targets the bulletproof hosting infrastructure that acts as the backbone for major ransomware operations, signaling a U.S. strategy to disrupt cybercrime by cutting off its technical foundation rather than chasing individual gangs.