:

US INDICTS RUSSIAN 'BULLETPROOF' WEB HOSTS FOR $62M CYBERCRIME SCHEME

SECURITY DESK2 MIN READ
WED, JUL 15, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Federal prosecutors have unsealed a 2024 indictment charging three Russian nationals and two web hosting services with facilitating cyberattacks and money laundering that victimized cybercrime targets of $62 million.

The indictment, filed in US federal court, alleges that the defendants operated "bulletproof" hosting services designed to evade law enforcement detection. These platforms provided infrastructure specifically marketed to cybercriminals seeking anonymity for their operations. The three Russian nationals are accused of knowingly supporting threat actors conducting ransomware attacks, data theft schemes, and other cybercrimes. The web hosting services allegedly maintained servers in multiple jurisdictions to complicate investigation efforts. Bulletproof hosting remains a persistent challenge for cybersecurity authorities. These services typically operate with minimal terms of service enforcement, encrypted customer communications, and rapid takedown resistance. They deliberately cater to criminal clientele and profit directly from cybercriminal activity. The $62 million figure represents confirmed losses traced directly to attacks facilitated through these hosting services. Investigators identified connections between the defendants and multiple ransomware gangs and cybercriminal groups operating across Eastern Europe and beyond. The case reflects broader US efforts to disrupt the infrastructure supporting transnational cybercrime. Federal agencies have intensified prosecutions targeting not just the hackers themselves, but the service providers enabling their operations. Despite the indictment, the defendants remain at large. Extradition from Russia remains unlikely given the country's limited cooperation with US law enforcement on cybercrime matters. The charges carry substantial federal penalties including conspiracy, computer fraud, and money laundering counts. This enforcement action underscores the complex challenge of disrupting cybercriminal ecosystems. While shuttering individual hosting platforms proves possible, defendants frequently relocate services or rebrand operations to continue serving criminal markets. Sustained pressure on infrastructure providers aims to increase operational costs and friction for threat actors.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Visa is enabling expired payment cards to continue processing contactless transactions through a new feature. The move allows cardholders to keep using their old cards for tap-to-pay purchases even after expiration.

YESTERDAYIndustry Desk

A Texas-based student discovered and reported an unauthorized AI system being used for cyberattacks. The disclosure prompted immediate investigation and security responses from affected organizations.

YESTERDAYAI Desk

A supply-chain attack is exploiting legitimate device-update apps to infect Android-based car head units with malware. The compromised devices are being enlisted into proxy botnets or used for ad fraud schemes.

YESTERDAYSecurity Desk

Apollo Global Management disclosed a data breach in July resulting from a social engineering attack that exposed personal information. The incident joins a recent wave of cyberattacks targeting major hedge funds.

YESTERDAYSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.