Between July 13 and 14, 2026, the United States, United Kingdom and European Union ran a coordinated strike against the infrastructure layer of ransomware rather than its operators. The US indicted the alleged operators of bulletproof host Media Land, tied to LockBit, BlackSuit and Play, while Treasury sanctioned the 1VPNS VPN service and a Belarusian cryptor seller. The UK and EU imposed their first-ever simultaneous cyber sanctions the same week. The message is structural: hit the enablers who make attacks possible, and every downstream operator gets more expensive to run.
What actually happened this week?
Three actions landed almost on top of each other. The US Department of Justice unsealed an indictment against three Russian nationals and two companies, Media Land LLC and ML.Cloud LLC, for running bulletproof hosting marketed to cybercriminals. The Treasury separately sanctioned First VPN Service (1VPNS), its administrator, and a cryptor seller who helped malware evade detection. And the UK and EU announced coordinated designations against Russian cyber actors, including operators tied to Lumma Stealer. Individually each is routine. Together, in one 48-hour window, they read as a deliberate campaign against the ransomware supply chain.
Why go after infrastructure instead of operators?
Ransomware operators are hard to arrest. Most sit in jurisdictions with no extradition, rebrand when disrupted, and recruit replacements fast. Their infrastructure is stickier. A bulletproof host that has served clients since the mid-2010s, a VPN that “appeared in nearly every major cybercrime investigation,” and a cryptor seller with an established reputation are not trivially replaced. Sanctioning and indicting that layer raises costs for every operator who relied on it, and it makes future business with those services legally radioactive.
The DOJ tied Media Land to more than $62 million in losses across 42 victims in 21 US states. Treasury framed 1VPNS as a service that “explicitly refused law-enforcement cooperation” since 2014. These are the load-bearing walls of the criminal economy, not the tenants.
The enabler layer, in context
This fits a longer arc. Enforcement has already learned that taking down one ransomware brand produces a rebrand within months. The initial access broker economy shows the same modularity: attacks are assembled from bought components. Hit the components, or the services that host and hide them, and you degrade the whole market rather than one node. It is the same logic that made threat-group tracking shift from “who encrypted whom” to “who supplied the access, the hosting, and the obfuscation.”
What this means for defenders and policymakers
For defenders, nothing about detection changes overnight, but the intelligence picture improves: infrastructure designations come with named entities, wallets, and IPs that feed blocklists and attribution. For policymakers, the week is a proof of concept that synchronized, multi-jurisdiction action against enablers is operationally feasible. The open question is durability. Infrastructure crackdowns work only if they are sustained, because the market reconstitutes around whoever is left standing.
Frequently asked questions
What is bulletproof hosting?
Bulletproof hosting is infrastructure sold to criminals with a promise to ignore abuse complaints and law-enforcement requests. It keeps malware command servers, phishing sites, and leak sites online when normal providers would take them down.
Which ransomware groups used Media Land?
US prosecutors linked Media Land’s hosting to LockBit, BlackSuit and Play operations, among others. The indictment cited more than $62 million in losses across 42 victims.
Why sanction a VPN provider?
1VPNS was marketed specifically to cybercriminals and, per authorities, refused to cooperate with law enforcement since 2014. Sanctioning it targets the anonymization layer that helps attackers hide their identity and location.
Will this stop ransomware?
Not on its own. Infrastructure crackdowns raise costs and disrupt operations, but the criminal market reconstitutes around surviving providers unless the pressure is sustained.
What is a cryptor?
A cryptor is a service or tool that obfuscates malware so it evades antivirus and endpoint detection. Sanctioning a cryptor seller targets the evasion layer of the attack chain.
