Legal & Compliance

US indicts the hosting layer: bulletproof providers charged over infrastructure behind phishing and fraudulent domains

The US Department of Justice unsealed an indictment on 14 July 2026 in the Northern District of Ohio charging three Russian nationals and two St Petersburg hosting companies, Medialand LLC and ML.Cloud LLC, over “bulletproof hosting” infrastructure that prosecutors say enabled cybercrime causing more than $62 million in losses to US victims. Alongside the unsealing, the State Department’s Rewards for Justice programme offered up to $10 million and possible relocation for information on foreign-government-linked associates of the operators or state-linked use of the infrastructure. For email abuse and deliverability teams, the detail that matters sits in the charging language: among the services the firms allegedly provided were fraudulent domain registration and a platform from which to launch phishing and brute-force attacks.

What the indictment describes

The defendants are Alexander Volosovik, who owned Medialand and advertised its services on criminal forums under the alias Yalishanda, Yulia Pankova, who owned ML.Cloud and handled legal and financial matters, and Kirill Zatolokin, who collected customer payments. The charges span conspiracy to commit and aid computer fraud, wire fraud, and money laundering conspiracy. Medialand’s infrastructure operated from multiple countries including China, Finland, the Netherlands, and the United States, and prosecutors say criminal groups using the two firms’ services targeted 42 victims across 21 US states, including banks, hospitals, schools, and government offices. The Justice Department’s Tysen Duva said the defendants “ran the criminal infrastructure that powered attacks on critical institutions across our nation.”

The indictment, returned in December 2024 after a seven-year FBI investigation, builds on Treasury sanctions imposed in November 2025 against the same individuals and entities, with the UK joining fully and Australia in part.

The upstream pattern

This is the American half of a pattern we reported from the European side when Europol seized the infostealer pipeline feeding email account takeover. Enforcement is moving upstream from messages and landing pages to the service fabric beneath them: the hosting, domain registration, and payment layers that make phishing an industry rather than an incident. A bulletproof host that registers fraudulent domains and rents launch infrastructure is where a lookalike of your brand exists before the first message is ever sent. That has two practical consequences for senders. Vendor due diligence should extend to hosting and infrastructure intelligence, because reputation attaches to neighbourhoods as well as tenants. And brand protection should watch the registration layer, not just the inbox, because by the time a spoofed message arrives the infrastructure behind it has usually existed for days.

Sidebar: watching the registration layer

Practical steps for monitoring lookalike infrastructure before it sends. Monitor Certificate Transparency logs for certificates issued against permutations of your brand and sending domains, since most phishing infrastructure obtains certificates before use. Generate and watch typosquat permutations of your core domains, including homoglyphs and hyphenated variants, against new registration feeds. Register or defensively block the small set of highest-risk variants, and put enforcing DMARC records, null SPF, and no MX on defensive domains that should never send. Establish escalation paths to registrars and hosts in advance, because abuse-desk speed is the variable you control before an incident, not during one. And check periodically what actually sends for your domains: our free Who Sends Email tool is one starting point, alongside DMARC aggregate reporting, for spotting infrastructure claiming your name.

More info: US Department of Justice press release on the indictment.
Additional reference: BleepingComputer on the operators and the Rewards for Justice offer.

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory