US Prosecutors Indicted Three Russian Nationals
Federal authorities charged three individuals for operating bulletproof hosting services linked to ransomware.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you believe international sanctions effectively deter foreign cybercriminals from targeting US institutions?
On July 20, 2026, US federal prosecutors unsealed an indictment against three Russian nationals for their roles in managing bulletproof hosting providers. The operation reportedly caused over $62 million in damages while supporting major ransomware groups.
Why it matters
The defendants provided critical infrastructure to ransomware gangs including LockBit, BlackSuit, and Play, enabling attacks on US infrastructure. By ignoring law enforcement requests, these services facilitated significant cybercrime across multiple countries.
The hosting services supported ransomware groups by ignoring abuse complaints and law enforcement inquiries. These providers utilized server infrastructure located across Russia, China, Finland, the Netherlands, and the United States.
The players
Aleksandr Volosovik
He is a Russian national accused of owning the Media Land hosting service.
Yulia Pankova
She is a Russian national identified as the owner of the ML.Cloud hosting company.
Kirill Zatolokin
He is a Russian national who served as the individual responsible for collecting customer payments.
LockBit
This is a prominent international ransomware operation that received support from the defendants' hosting infrastructure.
US State Department
This federal agency is offering a reward of up to $10 million for information leading to the defendants.
The details
Aleksandr Volosovik owned Media Land, Yulia Pankova owned ML.Cloud, and Kirill Zatolokin collected customer payments for these operations. Media Land infrastructure specifically facilitated DDoS attacks against US critical infrastructure, leading to a coordinated international sanctioning effort in November 2025.
Timeline
November 2025: The US, UK, and Australia sanctioned the defendants.
July 20, 2026: US federal prosecutors unsealed the indictment against the trio.
The Tech Race
The unsealing of the indictment follows the November 2025 US, UK, and Australia international sanctions. This move marks a departure from purely economic pressure, shifting toward direct criminal prosecution to dismantle the infrastructure used by global ransomware syndicates.
The indictment represents an attempt to mitigate the threat of ransomware attacks that disrupt critical infrastructure and private businesses. Citizens in the 21 affected states may see increased security measures as authorities prioritize the neutralization of bulletproof hosting platforms.
The takeaway
This case highlights the ongoing challenge of policing digital infrastructure that operates across jurisdictions with little cooperation. Authorities continue to use financial incentives and multi-national sanctions to target the individuals enabling global ransomware operations.
Further reading
Learn more about the evolving landscape of global digital threats in our Cybersecurity section.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you believe international sanctions effectively deter foreign cybercriminals from targeting US institutions?







