US Prosecutors Indicted Three Russian Nationals

Federal authorities charged operators of bulletproof hosting services linked to over $62 million in ransomware damages.

Updated on Sept. 27, 2026 in Cybersecurity

Bold flat-color editorial illustration of a single geometric server rack monolith, representing illicit digital infrastructure.
US federal prosecutors have indicted three Russian nationals accused of running 'bulletproof' hosting services that facilitated over $62 million in ransomware damages. AI Illustration. Upload story photo >

Live Poll

Do you believe international sanctions effectively deter foreign cybercriminals from targeting US institutions?

On July 20, 2026, US federal prosecutors unsealed an indictment against three Russian nationals accused of running infrastructure that supported ransomware operations. The network, which spanned multiple countries, caused over $62 million in damages across at least 21 US states.

Why it matters

The defendants provided critical infrastructure for ransomware groups including LockBit, BlackSuit, and Play, directly facilitating attacks on US critical infrastructure. Their operations represent a significant vector for cybercriminal activity by allowing operators to bypass law-enforcement requests.

The defendants facilitated criminal operations through bulletproof hosting services, which allow users to rent server infrastructure while ignoring abuse complaints. This infrastructure, which operated across Russia, China, Finland, the Netherlands, and the US, enabled cyberattacks that resulted in $62 million in damages.

The players

Aleksandr Volosovik

Owner of the bulletproof hosting provider Media Land.

Yulia Pankova

Owner of the hosting infrastructure company ML.Cloud.

Kirill Zatolokin

Individual responsible for managing customer payments for the hosting network.

The details

Bulletproof hosting providers offer server environments to clients while explicitly ignoring abuse reports and legal inquiries from authorities. Media Land, one of the implicated entities, reportedly launched distributed denial-of-service (DDoS) attacks—a method where multiple systems overwhelm a target server with traffic—against US critical infrastructure. The infrastructure supported major ransomware syndicates, including LockBit, BlackSuit, and Play, which encrypt victim data to extort payments.

Timeline

  1. November 2025: The US, UK, and Australia sanctioned the defendants and associated companies.

  2. July 20, 2026: US federal prosecutors unsealed the formal indictment.

The Tech Race

The indictment represents an escalation in the ongoing effort by international law enforcement to dismantle bulletproof hosting networks. This move follows the November 2025 international sanctions and highlights the continued effort to degrade the infrastructure supporting major ransomware syndicates.

This development marks a significant legal shift in the fight against ransomware, which has impacted victims in at least 21 US states. While the case against these specific defendants is ongoing, the US State Department has now offered a reward of up to $10 million for information leading to other associates.

The takeaway

This case highlights the fragility of bulletproof hosting infrastructure when confronted with synchronized international legal and financial sanctions. Observers should track the effectiveness of the $10 million reward program in securing the apprehension of these or associated cybercriminals.

Further reading

For more on how international authorities are targeting infrastructure, visit Cybersecurity.

Source note: This article includes information reported by Computer Crime Research Center.

Live Poll

Do you believe international sanctions effectively deter foreign cybercriminals from targeting US institutions?

US Prosecutors Indicted Three Russian Nationals