DOJ Indicts Russian Bulletproof Hosting Operators Over $62 Million Cybercrime Losses | #cybercrime | #infosec


The U.S. Department of Justice unsealed an indictment on July 14, 2026, charging three Russian nationals and two affiliated “bulletproof hosting” companies for running criminal infrastructure that enabled cyberattacks causing more than $62 million in losses to U.S. victims.

The indictment, originally returned in December 2024 in the Northern District of Ohio, names Alexander Alexandrovich Volosovik (43), Kirill Andreevich Zatolokin (34), and Yulia Vladimirovna Pankova (29), along with Medialand LLC and ML.Cloud LLC, both headquartered in St. Petersburg, Russia.

The defendants face charges of conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.

Prosecutors allege that Medialand (owned by Volosovik) and ML.Cloud (owned by Pankova at the time of the investigation) provided “bulletproof hosting” services designed specifically to shield cybercriminals from detection by law enforcement.

DOJ Indicts Russian Bulletproof Hosting Operators

Their infrastructure spanned multiple countries, including China, Finland, the Netherlands, and the United States.

According to the DOJ, Volosovik actively marketed these services on criminal forums, emphasizing features attractive to threat actors.

The platforms reportedly supported malware and ransomware deployment, extortion campaigns, fraudulent domain registration, phishing operations, brute-force attacks, and criminal marketplaces.

Investigators identified 42 victims across 21 U.S. states, including banks, schools, government entities, hospitals, and media organizations.

The unsealing coincides with a State Department Rewards for Justice announcement offering up to $10 million for information on foreign government-linked associates of the three defendants or their malicious cyber activity.

This builds on Treasury OFAC sanctions imposed in November 2025 against all named individuals and entities, including Medialand subsidiaries Media Land Technology and Data Center Kirishi, as well as sister company ML Cloud.

The UK’s Foreign Commonwealth and Development Office fully joined the sanctions, while Australia’s Department of Foreign Affairs and Trade joined in part.

Assistant Attorney General A. Tysen Duva stated the defendants “ran the criminal infrastructure that powered attacks on critical institutions across our nation.”

FBI Cyber Division Assistant Director Brett Leatherman emphasized the action targets “core services that cybercriminals rely on,” while U.S. Attorney David M. Toepfer noted the case reflects international cooperation against actors “who hide behind computers anywhere in the world.”

The FBI Cleveland Division led the investigation with support from CISA, OFAC, and international partners including the Netherlands’ National Police, the UK’s National Crime Agency, and Australian federal authorities.

The case falls under Operation Riptide, the FBI’s ongoing campaign against cybercrime infrastructure and financial networks, launched amid a reported $20 billion in U.S. cybercrime losses last year, a 26% year-over-year increase.

Trial Attorney Christen Gallagher (CCIPS) and Assistant U.S. Attorney Duncan T. Brown are prosecuting. Since 2020, CCIPS has secured over 180 cyber and IP crime convictions and recovered more than $350 million for victims.

Give your SOC the intelligence it needs to act with confidence.  
Explore ANY.RUN Threat Intelligence Feeds to reduce noise and improve operational efficiency. 



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW