The Hidden Servers Behind a $63 Million Cybercrime Scheme Targeting Americans
The most dangerous part of a cyberattack is not always the hacker tapping at a keyboard. Sometimes, it is the quiet network of servers keeping the entire operation alive.
Federal prosecutors say three Russian nationals operated that kind of digital shelter, allegedly helping cybercriminals launch ransomware, phishing and malware attacks that caused more than $62 million in losses. The Justice Department unsealed the indictment in Ohio on July 14, 2026, revealing a case that stretched across 21 states and reached banks, hospitals, schools, government offices and media companies.
The defendants are Alexander Alexandrovich Volosovik, 43; Kirill Andreevich Zatolokin, 34; and Yulia Vladimirovna Pankova, 29. Prosecutors also charged two St. Petersburg-based companies, Medialand LLC and ML.Cloud LLC. All defendants are presumed innocent unless proven guilty.
A Business Built to Keep Criminals Online

At the center of the case is a service known as “bulletproof hosting.”
Ordinary hosting companies provide servers, storage and internet access to legitimate customers. Bulletproof hosting providers allegedly offer similar tools to criminals, but design their systems to resist shutdowns, ignore abuse complaints and make investigations harder.
The Justice Department alleges that Medialand and ML.Cloud rented infrastructure to cybercriminal clients and helped them remain online while conducting illegal activity. Prosecutors say the companies’ servers operated in several countries, including China, Finland, the Netherlands and the United States.
That global footprint mattered. A ransomware group could attack an American hospital while relying on infrastructure spread across several jurisdictions. Each border could slow investigators and give attackers more time to demand payment.
The Alleged Scheme Reached Deep Into American Life
The indictment describes 42 victims in Ohio and 20 other states.
Federal officials said the affected organizations included schools, hospitals, banks, government entities and media companies. That list shows why the case is larger than a dispute over stolen files.
When a hospital network is disrupted, medical care can be delayed. When a school system is attacked, records and classroom technology may become inaccessible. When banks or government offices are compromised, the damage can spread through payroll systems, public services and personal accounts.
Prosecutors allege that clients using the companies’ infrastructure infected computers with malware and ransomware, then demanded money or cryptocurrency. The systems also allegedly supported phishing campaigns, fraudulent domains, criminal marketplaces and brute-force attacks.
The Servers Were the Weapon Behind the Weapon
The case highlights a less visible layer of the cybercrime economy.
Ransomware headlines often focus on the group sending the demand. Yet these operations also depend on hosting providers, payment channels, stolen credentials, malware developers and technical support. Removing one service can weaken several criminal groups at once.
Treasury officials previously described Media Land as a launching pad for ransomware actors, including LockBit, BlackSuit and Play. The agency also said its infrastructure had been used in distributed denial-of-service attacks against American businesses and critical infrastructure.
That is why authorities are targeting the companies as well as the people accused of running them. The goal is to disrupt the machinery that allows attacks to continue.
Sanctions Came Before the Charges Were Unsealed

In November 2025, the United States, United Kingdom and Australia announced coordinated sanctions against Media Land, related companies and members of its leadership. The U.S. sanctions blocked property under American control and generally prohibited transactions involving those designated.
Sanctions create financial pressure, but they do not produce a criminal conviction. The unsealed indictment adds federal charges including conspiracy to commit and aid computer fraud, conspiracy to commit wire fraud, wire fraud and conspiracy to commit money laundering.
The indictment was returned in December 2024 but remained sealed until July 2026. Authorities have not publicly explained every reason for the delay.
Washington Is Offering Millions for Information
The State Department’s Rewards for Justice program is offering up to $10 million for actionable information tied to foreign government-linked associates of the defendants, their alleged cyber activities or government-linked use of Media Land and ML.Cloud.
The offer includes possible relocation for qualifying sources, underscoring the investigation’s sensitivity.
Because the defendants are in Russia, bringing them before an American court could prove difficult. International cybercrime cases often depend on arrests in cooperating countries, extradition agreements or pressure on associates operating outside Russia.
A $63 Million Case Inside a Much Larger Crisis
The alleged losses are enormous, but they represent only a fraction of America’s cybercrime problem.
The Justice Department said Americans reported more than $20 billion in cybercrime losses last year, a 26 percent increase. The case is part of Operation Riptide, an FBI campaign targeting the people, infrastructure and financial systems supporting cybercrime and fraud.
That strategy aims to dismantle the services that make repeated attacks possible instead of waiting for each attack to happen.
The effort also requires international cooperation. Officials credited partners in the Netherlands, United Kingdom and Australia, along with the FBI, the Cybersecurity and Infrastructure Security Agency and the Treasury Department.
The Case Sends a Warning Beyond Russia
The indictment does not prove the accusations, and the defendants may challenge the government’s evidence. Still, it sends a warning to companies accused of serving cybercriminals from overseas.
Distance does not guarantee invisibility. Servers can be mapped, payments traced, business relationships sanctioned and indictments held until prosecutors are ready to reveal them.
For Americans, the case is a reminder that a cyberattack can begin thousands of miles away but still reach a local hospital, school or bank. The criminals demanding payment may be the visible threat, but the infrastructure keeping them online can be just as important.
The Justice Department’s challenge is turning a sweeping international indictment into arrests, trials and lasting disruption. Until that happens, the alleged operators may remain beyond immediate reach while the digital business they are accused of supporting continues to evolve.
