Skip to content
Malware

US Charges Two “Bulletproof Hosting” Companies for Helping Hackers Steal Tens of Millions of Dollars

The Department of Justice has unsealed an indictment in the Northern District of Ohio charging three Russian nationals and two Russia-based “bulletproof hosting” companies. The entities are accused of enabling widespread cybercrimes that have collectively caused tens of millions of dollars in losses...

· Jul 15, 2026 · 3 min read · 👁 3 views
US Charges Two “Bulletproof Hosting” Companies for Helping Hackers Steal Tens of Millions of Dollars

The Department of Justice has unsealed an indictment in the Northern District of Ohio charging three Russian nationals and two Russia-based “bulletproof hosting” companies.

The entities are accused of enabling widespread cybercrimes that have collectively caused tens of millions of dollars in losses to victims across the United States.

The indictment, originally returned in December 2024, levies multiple heavy charges including conspiracy to commit and aid and abet computer fraud, wire fraud, and money laundering:

  • Alexander Alexandrovich Volosovik (43) of St. Petersburg, Russia.
  • Kirill Andreevich Zatolokin (34) of St. Petersburg, Russia.
  • Yulia Vladimirovna Pankova (29) of St. Petersburg, Russia.
  • Medialand LLC, headquartered in St. Petersburg, Russia.
  • ML.Cloud LLC, headquartered in St. Petersburg, Russia.

US Charges Two “Bulletproof Hosting” Companies

Prosecutors allege that Medialand (owned by Volosovik) and ML.Cloud (owned by Pankova during the investigation period) provided dedicated server infrastructure tailored to block law enforcement interventions. Volosovik actively marketed these services on clandestine criminal forums, offering stable setups across global jurisdictions.

Co-conspirators leveraged these configurations to deploy various forms of malware, extort digital currencies, host illicit marketplaces, and orchestrate automated brute-force scripts. These methods closely resemble infrastructure footprints observed in previous Onyx ransomware operations.

The complete breakdown of criminal infrastructure, operations tracking, and explicit charging documents is hosted directly by the official DOJ release.

U.S. Rewards for Justice poster offering a $10 million reward for the three indicted Russian nationals.
U.S. Rewards for Justice poster offering a $10 million reward for the three indicted Russian nationals. (Image Source: www.justice.gov)

According to court filings, the operational footprint compromised 42 unique organizations across 21 states. The target matrix hit critical public segments including healthcare entities, financial organizations, schools, media agencies, and government systems.

To mitigate automated access threats from rogue nodes, defensive teams must continuously audit inbound traffic fields, closely monitoring systems for indicators that resemble gitpaste-12 malware infrastructure.

Operational Service ComponentImplicated Infrastructure NodeTargeted U.S. Sectors
Medialand LLCRussia, China, Finland, Netherlands, and the U.S.Banks, Schools, Government Entities
ML.Cloud LLCGlobal proxy servers and routing systemsHospitals, Media Companies

Alongside the criminal disclosures, the State Department’s Rewards for Justice program announced an active reward offer of up to $10 million for information linking the defendants or their companies to foreign government entities.

This follows a series of coordinated restrictions enacted in November 2025 by the Treasury Department’s OFAC, which fully sanctioned all three individuals alongside Medialand’s corporate subsidiaries (Media Land Technology and Data Center Kirishi) and sister company ML.Cloud.

The UK’s Foreign Commonwealth and Development Office fully joined the sanctions package, while Australia’s Department of Foreign Affairs and Trade implemented matching partial measures.

The underlying multi-agency investigation was spearheaded by the FBI Cleveland Division with operational assistance from CISA, OFAC, and international law enforcement bodies including the Dutch National Police, UK National Crime Agency, and the Australian Federal Police.

The action falls under Operation Riptide, the FBI’s macro campaign targeting the cybercrime economy, launched in response to a 26% year-over-year surge bringing domestic cyber losses to $20 billion annually.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you