Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

The week the West went after ransomware’s plumbing

Ransomnews Research TeamBy Ransomnews Research TeamJuly 15, 2026Updated:July 18, 2026No Comments4 Mins Read70 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
The week the West went after ransomware's plumbing, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Between July 13 and 14, 2026, the United States, United Kingdom and European Union ran a coordinated strike against the infrastructure layer of ransomware rather than its operators. The US indicted the alleged operators of bulletproof host Media Land, tied to LockBit, BlackSuit and Play, while Treasury sanctioned the 1VPNS VPN service and a Belarusian cryptor seller. The UK and EU imposed their first-ever simultaneous cyber sanctions the same week. The message is structural: hit the enablers who make attacks possible, and every downstream operator gets more expensive to run.

What actually happened this week?

Three actions landed almost on top of each other. The US Department of Justice unsealed an indictment against three Russian nationals and two companies, Media Land LLC and ML.Cloud LLC, for running bulletproof hosting marketed to cybercriminals. The Treasury separately sanctioned First VPN Service (1VPNS), its administrator, and a cryptor seller who helped malware evade detection. And the UK and EU announced coordinated designations against Russian cyber actors, including operators tied to Lumma Stealer. Individually each is routine. Together, in one 48-hour window, they read as a deliberate campaign against the ransomware supply chain.

RANSOMWARE SUPPLY CHAIN // WHERE THE HAMMER FELL BULLETPROOF HOST Media Land (indicted) ANONYMIZERS 1VPNS (sanctioned) CRYPTORS Silayev (sanctioned) SHARED INFRASTRUCTURE used by many operators LockBit BlackSuit Play Coordinated US / UK / EU action, July 13-14, 2026

Why go after infrastructure instead of operators?

Ransomware operators are hard to arrest. Most sit in jurisdictions with no extradition, rebrand when disrupted, and recruit replacements fast. Their infrastructure is stickier. A bulletproof host that has served clients since the mid-2010s, a VPN that “appeared in nearly every major cybercrime investigation,” and a cryptor seller with an established reputation are not trivially replaced. Sanctioning and indicting that layer raises costs for every operator who relied on it, and it makes future business with those services legally radioactive.

The DOJ tied Media Land to more than $62 million in losses across 42 victims in 21 US states. Treasury framed 1VPNS as a service that “explicitly refused law-enforcement cooperation” since 2014. These are the load-bearing walls of the criminal economy, not the tenants.

The enabler layer, in context

This fits a longer arc. Enforcement has already learned that taking down one ransomware brand produces a rebrand within months. The initial access broker economy shows the same modularity: attacks are assembled from bought components. Hit the components, or the services that host and hide them, and you degrade the whole market rather than one node. It is the same logic that made threat-group tracking shift from “who encrypted whom” to “who supplied the access, the hosting, and the obfuscation.”

What this means for defenders and policymakers

For defenders, nothing about detection changes overnight, but the intelligence picture improves: infrastructure designations come with named entities, wallets, and IPs that feed blocklists and attribution. For policymakers, the week is a proof of concept that synchronized, multi-jurisdiction action against enablers is operationally feasible. The open question is durability. Infrastructure crackdowns work only if they are sustained, because the market reconstitutes around whoever is left standing.

Frequently asked questions

What is bulletproof hosting?

Bulletproof hosting is infrastructure sold to criminals with a promise to ignore abuse complaints and law-enforcement requests. It keeps malware command servers, phishing sites, and leak sites online when normal providers would take them down.

Which ransomware groups used Media Land?

US prosecutors linked Media Land’s hosting to LockBit, BlackSuit and Play operations, among others. The indictment cited more than $62 million in losses across 42 victims.

Why sanction a VPN provider?

1VPNS was marketed specifically to cybercriminals and, per authorities, refused to cooperate with law enforcement since 2014. Sanctioning it targets the anonymization layer that helps attackers hide their identity and location.

Will this stop ransomware?

Not on its own. Infrastructure crackdowns raise costs and disrupt operations, but the criminal market reconstitutes around surviving providers unless the pressure is sustained.

What is a cryptor?

A cryptor is a service or tool that obfuscates malware so it evades antivirus and endpoint detection. Sanctioning a cryptor seller targets the evasion layer of the attack chain.

Sources and further reading

  • US DOJ: Three Russian nationals and two companies indicted (July 14, 2026)
  • US Treasury: Sanctions on ransomware enablers (July 13, 2026)
  • BleepingComputer: US charges alleged bulletproof hosting operators (July 15, 2026)
  • The Record: 1VPNS administrator sanctioned (July 2026)
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleThe Gentlemen weaponised a Kontron driver to kill EDR
Next Article Qilin: the RaaS that ran H1 2026 ransomware
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.