Three Russian nationals, Alexander Alexandrovich Volosovik, Yulia Vladimirovna Pankova, and Kirill Andreevich Zatolokin, have been indicted for allegedly running bulletproof hosting providers that supported a series of cybercrime attacks on critical infrastructure in 21 states and several countries. The indictment, unsealed in federal court, alleges that the attacks resulted in losses surpassing $62 million.
Charges and Sanctions
The three accused Russians, along with their companies Media Land and ML.Cloud, have been charged with conspiracy to commit and aid computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. The State Department has offered a reward of up to $10 million for information on government-linked associates of the alleged cybercriminals and malicious use of Media Land or ML.Cloud.
In November 2025, the Treasury Department and officials from the United Kingdom and Australia imposed sanctions on Volosovik, Zatolokin, Pankova, Media Land, and ML.Cloud. The sanctions are aimed at disrupting the financial networks of the alleged cybercriminals and limiting their ability to operate.
Impact of the Attacks
The attacks, which were facilitated by the bulletproof hosting providers, resulted in significant losses for victims across 21 states, including nine cities in the Northern District of Ohio. Additional victims were located in Australia, the European Union, the United Arab Emirates, Canada, and the United Kingdom.
The attacks also put the American public at risk, according to A. Tysen Duva, assistant attorney general of the Justice Department's Criminal Division. "From their overseas safe haven, these defendants ran the criminal infrastructure that powered attacks on critical institutions across our nation," Duva said. "Their actions put the American public at risk. We will continue to dismantle these networks and protect our critical infrastructure from cybercriminals at home and abroad."
Bulletproof Hosting Providers
Bulletproof hosting providers, like Media Land and ML.Cloud, are increasingly used by cybercriminals to obfuscate their activities, deliver malware, phishing, and host content and services that support ransomware, data extortion, and denial-of-service attacks. These providers offer a range of services, including infrastructure and technical support, to cybercriminals looking to infect systems with malware and ransomware for extortion.
"With today's actions, the FBI and our partners are striking at the core services that cybercriminals rely on to attack U.S. critical infrastructure," said Brett Leatherman, assistant director of the FBI Cyber Division. "This is another step in our broader campaign to shrink the space in which these actors can operate, forcing them to work harder, take greater risks, and lose the anonymity they depend on."
Investigation and Next Steps
The investigation into the activities of Volosovik, Pankova, Zatolokin, Media Land, and ML.Cloud has been ongoing since 2019. The indictment and sanctions are the latest steps in the effort to disrupt and dismantle the networks of cybercriminals who use bulletproof hosting providers to facilitate their activities.
The FBI and its partners will continue to work to identify and disrupt the networks of cybercriminals who use bulletproof hosting providers to facilitate their activities. The public is urged to report any suspicious activity to the authorities and to take steps to protect themselves from cybercrime.
Source: CyberScoop