The U.S. Department of Justice unsealed an indictment on July 14, 2026 charging three Russian nationals and two Russia-based hosting companies with running the infrastructure behind ransomware attacks on U.S. hospitals, banks, schools, and government agencies, treating a hosting provider, not just the criminals who rented its servers, as the target of a federal prosecution.

The indictment: Media Land and the infrastructure layer

According to the Department of Justice, the indictment, returned by a grand jury in the Northern District of Ohio in December 2024 and unsealed this week, charges Alexander Alexandrovich Volosovik, 43; Kirill Andreevich Zatolokin, 34; and Yulia Vladimirovna Pankova, 29, all of St. Petersburg, Russia, along with the companies Medialand LLC and ML.Cloud LLC, with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.

U.S. Attorney David M. Toepfer for the Northern District of Ohio said the case’s victims are “not only in Ohio, but also in 20 other states across the country, touching every aspect of Americans’ lives,” naming banks, schools, government entities, hospitals, and media companies among those affected. FBI Cyber Division Assistant Director Brett Leatherman said Media Land “enabled malicious activity causing tens of millions in losses and impacting victims across 21 states and multiple countries.” The Department of Justice put total victim losses at more than $62 million.

Advertisement

CyberTech Your brand belongs here. Reach the decision-makers who read CyberTech every day. Premium placements across the site and newsletter. Advertise with us

How bulletproof hosting sustains ransomware operations

Bulletproof hosts lease servers, IP space, and domain infrastructure to paying customers while ignoring abuse complaints and law enforcement takedown requests. That business model gives ransomware crews, phishing operations, and malware distributors a base of operations that is far harder to disrupt than a single compromised server, because the provider itself is built to absorb and deflect the pressure that would normally take infrastructure offline. For a ransomware group, renting from a bulletproof host is closer to renting office space than committing a break-in: the infrastructure is purpose-built to keep operating through complaints, court orders, and ordinary hosting-abuse workflows.

Who Yalishanda is, and why the case extends beyond the U.S.

Volosovik, who operates under aliases including Yalishanda, Downlow, and Stas_vl, has run Media Land’s hosting operation since at least 2010, according to the UK’s National Crime Agency (NCA). The NCA said Media Land and its subsidiary ML.Cloud “collaborated with notorious criminal organizations including Evil Corp, LockBit, and Black Basta,” among the most prolific ransomware brands of the past decade.

A sanctions case becomes a criminal one

This week’s indictment did not arrive in isolation. On November 19, 2025, the UK, working in coordination with the U.S. Treasury’s Office of Foreign Assets Control and Australia’s Department of Foreign Affairs and Trade, sanctioned Volosovik, Pankova, Zatolokin, and associated entities through the UK’s Foreign, Commonwealth and Development Office and National Crime Agency. UK Foreign Secretary Yvette Cooper said at the time that “cyber criminals think they can act in the shadows, targeting hard working British people and ruining livelihoods with impunity. But they are mistaken.” The Department of Justice’s unsealed indictment, and the U.S. State Department’s accompanying $10 million Rewards for Justice offer for information on the defendants’ foreign-government-linked associates, extends that financial sanctions case into a criminal prosecution eight months later.

What it means for the security leader

Most ransomware defense budgets are built around detecting and blocking the intrusion itself: phishing, exploited edge devices, stolen credentials. The Media Land case is a reminder that a meaningful share of that activity depends on a comparatively small number of hosting and infrastructure providers willing to serve customers regardless of what they do with the servers. When one of those providers is sanctioned or indicted, its customers do not disappear, but they do lose infrastructure and scatter to other providers, generating the kind of migration activity that shows up in a defender’s own threat intelligence feeds as a burst of new IP ranges and autonomous system reassignments tied to previously tracked ransomware and phishing infrastructure.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

For threat intelligence and SecOps teams, that means this indictment is not just a policy headline. It is a prompt to re-check indicator lists and firewall or DNS blocklists tied to Media Land, ML.Cloud, and their known IP ranges, since infrastructure formerly hosted there is likely to move, and any internal detections still pointed at the old ranges will go quiet without the underlying threat having actually stopped.

What defenders should do

Security teams should treat this indictment the same way they would treat a major vendor advisory: as an input to threat intelligence, not just industry news. Review existing indicator feeds and threat intelligence platforms for entries tagged to Media Land or ML.Cloud infrastructure and flag them for refresh, since sanctioned or indicted infrastructure typically gets reassigned or abandoned within weeks. Incident response and threat hunting teams investigating intrusions tied to LockBit, Evil Corp, or Black Basta affiliates should expect infrastructure churn in the coming months as former Media Land customers relocate to other bulletproof hosts, and should treat sudden changes in command-and-control infrastructure for tracked ransomware families as expected fallout from this action rather than a sign that detections have failed.

The case also points to a broader pattern worth tracking: prosecutors and sanctions authorities are increasingly targeting the infrastructure-as-a-service layer that ransomware operators rent, rather than only the operators themselves. CyberTech has covered a related dynamic in ransomware access brokers, another infrastructure layer that sits between initial compromise and ransomware deployment. Security leaders should expect more actions like this one, and should build “infrastructure provider sanctioned or indicted” into their own threat intelligence refresh triggers alongside CVE disclosures and malware family reports.

Source: U.S. Department of Justice