Elyria business named as alleged victim in federal ransomware case
An unnamed commercial business in Elyria is identified as an alleged ransomware victim in a federal cybercrime case involving three Russian nationals and two Russia-based companies.
The indictment was filed on December 5, 2024, and unsealed on July 14, 2026. It identifies the Elyria company as “Victim 13” and alleges that a ransomware campaign on or about February 27, 2020, damaged the business’s computer systems.
What the indictment says about Elyria
The federal indictment does not name the business. It also does not disclose the extent of the damage, which systems were affected, whether the company paid a ransom or whether the incident disrupted customers or employees.
The document alleges that services connected to the defendants were used by a criminal group to carry out ransomware campaigns. In the Elyria incident, prosecutors allege that the campaign used domains or internet protocol addresses maintained by Media Land.
The public record does not establish that Elyria residents, the city government, a school, hospital or any other specific local institution was affected. The confirmed local reference is limited to the unnamed commercial business described in the indictment.
Who was charged
The U.S. Attorney’s Office for the Northern District of Ohio charged Alexander Volosovik, Kirill Zatolokin and Yulia Pankova, along with Media Land LLC and ML.Cloud LLC. Prosecutors allege that the companies provided “bulletproof hosting” and related infrastructure that helped criminal groups operate ransomware, malware, phishing, brute-force and other computer-based schemes.
The Justice Department says the alleged operation reached victims in 21 states and several countries. Victims included banks, schools, government entities, hospitals and media companies. Northern District of Ohio locations listed by prosecutors include Elyria, Akron, Brookfield, Canton, Cleveland, Findlay, Medina, Solon and Valley View.
Federal officials say the broader case involved more than $62 million in losses. That figure covers alleged victims across the United States and internationally; it is not a loss estimate for Elyria or Northeast Ohio.
Why the case matters locally
For Elyria businesses, the case is a reminder that ransomware investigations can involve outside infrastructure and criminal groups operating across borders. The indictment describes a system in which hosting services, domains and server resources allegedly helped attackers reach organizations in multiple states.
That broader context is relevant to companies and institutions that depend on computer systems for payroll, customer records, communications, production or public services. It does not, however, provide evidence that additional Elyria organizations were victims in this case.
What happens next
The State Department’s Rewards for Justice program announced a reward of up to $10 million for information about the defendants, their alleged cyber activities or foreign government-linked use of the companies’ infrastructure. The investigation is being led by the FBI Cleveland Division with assistance from federal partners.
The charges remain allegations. An indictment is not a conviction, and the public documents reviewed for this story do not establish arrests, extraditions or trial outcomes. The Elyria business also remains unidentified.
Sources
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.