
The United States, the United Kingdom, and Australia have imposed sanctions on Zservers, a Russia-based bulletproof hosting (BPH) provider accused of supplying critical infrastructure to the LockBit ransomware gang. Authorities in the three nations allege that Zservers facilitated cybercriminal activities by offering services that obscured the identities and locations of perpetrators, enabling them to carry out ransomware attacks against critical infrastructure worldwide.
In addition to sanctioning Zservers, the U.S. Treasury’s Office of Foreign Assets Control (OFAC) designated two Russian nationals, Alexander Igorevich Mishin and Aleksandr Sergeyevich Bolshakov, for their roles in managing LockBit’s virtual currency transactions and supporting the gang’s operations. The U.K. government also sanctioned XHOST Internet Solutions LP, a U.K.-based front company for Zservers, along with four of its employees: Ilya Sidorov, Dmitriy Bolshakov, Igor Odintsov, and Vladimir Ananev.
The coordinated international action follows a 2022 raid by Canadian authorities, during which law enforcement discovered a laptop running a virtual machine linked to a Zservers subleased IP address. The device was found to be operating a LockBit malware control panel, providing further evidence of Zservers’ direct involvement in cybercriminal activities. Investigators also revealed that in 2022, a Russian hacker acquired IP addresses from Zservers, likely to support LockBit chat servers used to coordinate ransomware operations. Furthermore, in 2023, Zservers provided a Russian IP address to a LockBit affiliate, underscoring its continued role in supporting the ransomware syndicate.
Acting Under Secretary of the Treasury for Terrorism and Financial Intelligence Bradley T. Smith emphasized the significance of targeting third-party network service providers that enable cybercriminal enterprises. “Ransomware actors and other cybercriminals rely on third-party network service providers like Zservers to enable their attacks on U.S. and international critical infrastructure,” Smith stated. The U.K. government echoed these concerns, describing bulletproof hosting providers like Zservers as enablers of cybercrime, offering tools that allow criminals to mask their activities and evade law enforcement.
As a result of the sanctions, individuals and organizations within the U.S., U.K., and Australia are prohibited from engaging in transactions with the designated entities and individuals. Additionally, any assets linked to the sanctioned parties within these jurisdictions will be frozen. Financial institutions and foreign entities that continue to facilitate transactions with them may also face penalties, further tightening restrictions on their operations.
This move follows a broader international crackdown on LockBit ransomware operators. The U.S. State Department recently announced a reward of up to $10 million for information leading to the arrest or conviction of LockBit administrator Dmitry Khoroshev. An additional reward of up to $15 million has been offered for information on LockBit’s owners, operators, administrators, and affiliates.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543