The United States, the United Kingdom and Australia on February 11 sanctioned a Russia-based bulletproof hosting provider and two Russian men accused of running it for the ransomware syndicate LockBit. The action targeted Zservers, a web-hosting service described by U.S. Treasury as designed to ignore or evade law-enforcement requests, along with two Russian nationals named as operators of the service.

The sanctions are important because they aim at the infrastructure that allows ransomware groups to operate at scale. Treasury said Zservers provided LockBit access to specialized servers that were built to resist law-enforcement action. The package was coordinated across three countries, signaling that allied governments wanted to disrupt not just one gang, but the services that help such groups survive.

LockBit has become one of the most persistent names in cybercrime. According to the AP report, attacks linked to the group have extracted more than $120 million from thousands of victims around the world. The group has been active since 2019 and remains one of the most deployed ransomware variants, according to the U.S. Cybersecurity and Infrastructure Security Agency.

The sanctions come against a broader backdrop in which ransomware is still among the costliest and most disruptive forms of cybercrime. Hospitals, schools, local governments, court systems and private companies can all be forced offline when attackers encrypt data and demand payment. Officials have also argued for years that groups based in former Soviet states are harder for Western authorities to reach, which makes infrastructure providers especially valuable targets for sanctions.

Treasury’s Acting Under Secretary for Terrorism and Financial Intelligence, Bradley T. Smith, said the action underscored a collective resolve to disrupt the criminal ecosystem wherever it operates. The State Department also framed the move as part of a wider commitment with international partners to combat cybercrime and weaken the networks that enable it.

The AP report linked LockBit to major incidents including attacks on Boeing, Royal Mail, Britain’s National Health Service and the international law firm Allen and Overy, underscoring why the hosting layer matters. By going after a provider rather than only the malware operators, the three governments are trying to cut off the tools that let ransomware crews set up servers, hide from enforcement and keep returning after takedowns.

The February 11 sanctions do not end LockBit, but they show a different tactic: pressure the service providers that make ransomware infrastructure usable in the first place.