One of largest bulletproof web hosting providers Media Land got its internal data leaked

One of largest bulletproof web hosting providers Media Land got its internal data leaked

An unnamed actor has leaked a treasure trove of internal data from Media Land, one of the largest bulletproof web hosting providers. The leaked files contain sensitive details about the company’s past customers, the services they contracted, and the kinds of data hosted on its servers.

Media Land, a Russia-registered company operating for over a decade, has been known for providing secure hosting solutions that have been used by cybercriminals worldwide.

The leaked documents, some as recent as February 2025, provide evidence of the platform's involvement in hosting various illicit operations, including malware command and control servers, ransomware infrastructure, phishing kits, data exfiltration servers, and even systems used for malicious code-signing.

Threat intelligence firm Prodaft believes that the hacker behind the Media Land breach is likely the same group responsible for a previous leak in mid-February, which saw internal communications from the notorious BlackBasta ransomware group exposed.

The data also includes personally identifiable information (PII), financial details and critical Indicators of Compromise (IOCs), which could assist researchers in connecting the dots between various cybercrime operations.

Yalishanda, the public face and suspected main administrator of Media Land, has confirmed the breach on an underground hacking forum, stating that the company is currently addressing a technical issue. However, it remains unclear whether the hacker gained access through the BlackBasta servers or if the breach occurred through another vector entirely.

Back to the list

Latest Posts

Cyber Security Week in Review: April 11, 2025

Cyber Security Week in Review: April 11, 2025

In brief: Microsoft fixes yet another Windows zero-day, Russian hackers continue to target military missions, and more.
11 April 2025
Hackers exploited zero-day flaw in Gladinet CentreStack software since March

Hackers exploited zero-day flaw in Gladinet CentreStack software since March

The issue stems from a hardcoded machineKey in the web application’s configuration file.
10 April 2025
Intelligence agencies warn of Chinese spyware targeting Taiwan, Tibetan rights advocates

Intelligence agencies warn of Chinese spyware targeting Taiwan, Tibetan rights advocates

The advisory focuses on two spyware families, dubbed ‘BadBazaar’ and ‘Moonshine’ masquerading as seemingly legitimate apps.
9 April 2025