2 min read

Bulletproof No Longer: The Unsealing of the Media Land Indictment- 270

Bulletproof No Longer: The Unsealing of the Media Land Indictment- 270

July 16, 2026

Three years after federal prosecutors first built their case, the US Justice Department this week unsealed an indictment that had sat sealed since December 2024, charging three Russian nationals and the two web-hosting companies they allegedly ran with providing the infrastructure backbone for a sprawling wave of cybercrime against American businesses. The unsealing turns a long-known sanctions target into a formal criminal case, and closes the gap between what security researchers have documented about bulletproof hosting for years and what US law is now willing to prosecute.

The defendants, Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova, all residents of St. Petersburg, are accused of operating Media Land and ML.Cloud, "bulletproof" hosting providers whose entire value proposition to criminal clientele was insulation from law enforcement takedowns. The infrastructure reached well beyond Russia, with operations spanning China, the Netherlands, Finland, and even servers within the United States itself, a footprint that let ransomware operators, DDoS crews, and state-backed hacking groups route their attacks through jurisdictions chosen for their resistance to legal process rather than their technical merit. Prosecutors say the two companies knowingly hosted infrastructure for ransomware gangs including LockBit, BlackSuit, and Play, alongside phishing operations, brute-force attacks, and cybercrime marketplaces, with victims spanning at least 42 entities across 21 US states and losses reaching an estimated $62 million.

The operators feeding into Media Land/ML.Cloud, down through the threat actors it hosted, to the US victims,

What the indictment makes explicit is a business model that has operated in plain sight for years: bulletproof hosts don't commit the intrusions themselves, they sell the plausible deniability that lets everyone else's intrusions succeed. The US Treasury had already sanctioned both companies, and the individuals had been publicly named in a coordinated sanctions action with the UK and Australia in late 2025, meaning this indictment adds criminal exposure to a target set already under financial restriction rather than introducing new information about who is responsible. That layering of sanctions, public naming, and now unsealed federal charges reflects a deliberate strategy: Washington has coupled the indictment's release with a $10 million reward offer and the possibility of relocation for anyone providing actionable information on the operators, an incentive structure aimed squarely at the reality that extradition from Russia remains, in practice, functionally unavailable. As Assistant Attorney General A. Tysen Duva put it, the intent is less about securing an imminent arrest than about signaling that the networks enabling ransomware at scale will continue to be dismantled, piece by piece, even when the people running them are unlikely to ever see a US courtroom.