You’ve probably never heard of Medialand LLC or ML.Cloud. They sound like boring B2B tech companies — the kind that sponsor mid-tier podcasts and have LinkedIn pages nobody visits. But according to a federal indictment unsealed this week, these two unremarkable companies based in St. Petersburg, Russia, provided the server infrastructure that fueled cyberattacks responsible for over $62 million in losses worldwide.
The most dangerous cybercriminals don’t wear hoodies in dark rooms. They file tax returns and register LLCs.
Here’s what the indictment actually reveals, and why almost everyone is missing the point. When we read about cybercrime, the story is always the same: a lone hacker, a brilliant exploit, a dramatic takedown. It’s the Hollywood version. It’s also completely wrong.
Cybercrime isn’t a heist movie. It’s a supply chain. And like any supply chain, it depends on infrastructure — servers, IP addresses, bandwidth, hosting services. The hackers get the headlines, but the infrastructure providers are the ones who make the whole operation possible. Without Medialand and ML.Cloud allegedly renting out servers, the attacks don’t happen. The ransomware doesn’t deploy. The phishing campaigns don’t launch.
Three Russian nationals — Aleksandr Grichishkin, Aleksandr Skvortsov, and Lyubov Pankova — were indicted alongside these companies. But the real story isn’t about three individuals. It’s about an entire ecosystem where legitimate businesses operate as the backbone of criminal enterprises, shielded by a regulatory grey zone that Russia has zero interest in closing.
When a country tolerates cybercrime infrastructure the way other countries tolerate potholes, the entire internet becomes a company town — and we’re all working in the mine.
Think about what this means for you. Every time your company pays for cloud hosting, uses a VPN, or relies on a third-party API, you’re plugging into a global infrastructure network. Most of it is clean. But some of it exists in jurisdictions where “clean” and “criminal” are distinctions without a difference. The DOJ’s decision to indict the companies — not just the individuals — signals something rare: an acknowledgment that going after hackers is like mopping the floor while the faucet runs.
The faucet is the infrastructure. Turn it off, and the problem actually shrinks.
But here’s the uncomfortable truth nobody in the cybersecurity industry wants to say out loud: this approach should have been standard practice a decade ago. Instead, we’ve spent years building bigger firewalls, faster threat-detection tools, and fancier zero-trust architectures — all while the pipes feeding the attacks stayed wide open. It’s like upgrading your home security system while leaving a note on the door that says, “Key under the mat.”
You can’t out-innovate an enemy who has a business license and a government that looks the other way. You can only cut off their supply.
The $62 million figure in this indictment sounds large, but it’s a rounding error compared to the global cost of cybercrime, which runs into the trillions. What makes this case different isn’t the dollar amount — it’s the target. If prosecutors can establish that infrastructure providers bear legal liability for the crimes their servers enable, the entire calculus changes. Every bulletproof hosting provider, every lookalike domain registrar, every anonymous proxy service suddenly has to wonder whether the next knock on the door comes with a subpoena.
That’s not just a legal strategy. It’s a deterrence strategy. And it’s about time.
The next time you read about a massive ransomware attack, don’t just ask who pulled the trigger. Ask who sold them the gun, who rented them the safe house, and who cashed the check. Because the hackers are replaceable. The infrastructure isn’t. And until we start treating the enablers as criminals — not just the operators — we’re all just waiting for our turn in the breach report.
FAQ
Q: Won't infrastructure providers just move to jurisdictions beyond US reach?
A: Some will. But indictments create a chilling effect — payment processors, upstream providers, and international partners start cutting ties. You don't need to reach everyone; you need to make complicity expensive enough that the math stops working.
Q: What does this mean for companies buying cloud and hosting services?
A: Due diligence on your supply chain just became legally and practically relevant. If your vendor's vendor is hosting criminal infrastructure, you're downstream of the blast zone. Audit your stack.
Q: Is targeting infrastructure providers actually a new idea, or just good PR?
A: It's not new — it's just rarely used. The DOJ has had this power for years. The fact that they're finally using it against companies, not just individuals, suggests either a strategy shift or mounting pressure to show results. Either way, it sets a precedent.