supply-chaintrade-pressNewsThe Broadside1 min read

DOJ unseals Media Land indictment over $62M critical-infrastructure attacks

The case treats uptime, abuse support and anonymity as the offense, which is the whole bulletproof-hosting business model.


TL;DR

CyberScoop reports that a 2024 indictment unsealed Tuesday charges Alexander Volosovik, Yulia Pankova and Kirill Zatolokin over Media Land and ML.Cloud infrastructure allegedly used in attacks across 21 states and several countries, causing more than $62 million in losses. Critical-infrastructure victims and incident responders inherit the operational problem: the provider layer can matter as much as the malware operator.

CyberScoop reports that federal prosecutors unsealed a 2024 indictment charging three Russian nationals tied to St. Petersburg-based Media Land and ML.Cloud: Alexander Alexandrovich Volosovik, Yulia Vladimirovna Pankova and Kirill Andreevich Zatolokin. The charges include conspiracy to commit and aid computer fraud, conspiracy to commit wire fraud, wire fraud and conspiracy to commit money laundering. Officials said the providers supported attacks on critical infrastructure in 21 states, including nine cities in the Northern District of Ohio, and in Australia, the European Union, the United Arab Emirates, Canada and the United Kingdom.

The important move is the target selection. DOJ is not describing Media Land and ML.Cloud as background internet plumbing that bad customers happened to use. According to the report, officials allege the companies provided infrastructure and technical support for malware and ransomware infections, criminal marketplaces, fraudulent domain registrations, phishing and brute-force attacks. That makes the hosting layer part of the attack chain, not just scenery around it.

The indictment also sits on top of other pressure points. The State Department offered up to $10 million for information on government-linked associates of the alleged cybercriminals and malicious use of Media Land or ML.Cloud, while Treasury and officials in the United Kingdom and Australia sanctioned Volosovik, Zatolokin, Pankova, Media Land and ML.Cloud in November 2025. For critical-infrastructure defenders, this does not create a new compliance obligation. It does make infrastructure indicators, fraudulent domains and provider relationships worth preserving in the incident file. DOJ is treating the service layer as evidence.


Published ·Deep Fathom

DOJ unseals Media Land indictment over $62M critical-infrastructure attacks — The Broadside