Entity record

ZserversOrganization

Source-verifiedReflects UK Sanctions List (UKSL)observed not an issuing authority

Zservers appears on the UK Sanctions List (UKSL) and 1 other official sanctions list, designated by UK HM Treasury (OFSI), UK Foreign, Commonwealth & Development Office (FCDO) under programs Cyber, The Cyber (Sanctions) (EU Exit) Regulations 2020; reflected as observed on 2026-06-03.

Sanctions

Designations

Reason for listing

Per UK Foreign, Commonwealth & Development Office (FCDO) (listed ):

UKSL CYB0064 — Measures: Asset freeze, Director Disqualification Sanction — ZSERVERS has been involved in relevant cyber activity, in that by providing hosting services that support relevant cyber activity it has provided support for the commission, planning or preparation of such activity, has supplied technology and provided technical assistance that could contribute to such activity, and has carried out activities which promoted, enabled or facilitated the commission of relevant cyber activity. ZSERVERS has operated from Barnaul, Russia and has promoted itself as a Bulletproof Hosting (BPH) provider. ZSERVERS has been involved in relevant cyber activity though its role providing infrastructure used in ransomware incidents and reprovisioning infrastructure for customers identified as being involved in malicious cyber activity, including those affiliated with the LockBit ransomware group. ZSERVERS infrastructure was used to host a ransomware-dedicated site connected with the leak of private information stolen from Australian health insurance company Medibank Private Limited. ZSERVERS has been identified as a key enabler of the cybercrime ecosystem. Such activity that ZSERVERS was involved in, directly or indirectly caused, or was intended to cause, economic loss to, or prejudice to the commercial interests of those affected by the activity. (official source)

Per UK HM Treasury (OFSI) (listed ):

CYB0064 — ZSERVERS has been involved in relevant cyber activity, in that by providing hosting services that support relevant cyber activity it has provided support for the commission, planning or preparation of such activity, has supplied technology and provided technical assistance that could contribute to such activity, and has carried out activities which promoted, enabled or facilitated the commission of relevant cyber activity. ZSERVERS has operated from Barnaul, Russia and has promoted itself as a Bulletproof Hosting (BPH) provider. ZSERVERS has been involved in relevant cyber activity though its role providing infrastructure used in ransomware incidents and reprovisioning infrastructure for customers identified as being involved in malicious cyber activity, including those affiliated with the LockBit ransomware group. ZSERVERS infrastructure was used to host a ransomware-dedicated site connected with the leak of private information stolen from Australian health insurance company Medibank Private Limited. ZSERVERS has been identified as a key enabler of the cybercrime ecosystem. Such activity that ZSERVERS was involved in, directly or indirectly caused, or was intended to cause, economic loss to, or prejudice to the commercial interests of those affected by the activity. (official source)

Key properties

Identifiers

OFSI Group ID
16746
UK Sanctions List Unique ID
CYB0064

Addresses

32 Jubileinaia, Barnaul, Altai Kray, 656902, Russia

Source list & list version

Source listList versionManifest SHA-256StatusVerify
UK Sanctions List (UKSL)Sanctions list
UK Foreign, Commonwealth & Development Office (FCDO)
gb_fcdo_uksl@2026-08-046f5e8b8ed92cccf0List version (signing pending)
UK OFSI Consolidated List of Financial Sanctions TargetsSanctions list
UK HM Treasury — Office of Financial Sanctions Implementation (OFSI)
20260610-0014d14d0d8a5584fffList version (signing pending)manifest

About these sources

The UK Sanctions List (UKSL), published by the Foreign, Commonwealth & Development Office — since 28 January 2026 the single, current source for all UK sanctions designations (financial, immigration, trade and transport measures), superseding the older OFSI Consolidated List.

What a match means: A match is a current, binding UK sanctions designation — treat as a direct compliance hit and escalate immediately.

The UK's former OFSI Consolidated List of Financial Sanctions Targets, maintained by HM Treasury. OFSI closed this list on 28 January 2026 — current UK sanctions designations now publish only to the FCDO UK Sanctions List (also in this catalog) — and it is retained here as a historical source.

What a match means: A match reflects a UK financial-sanctions designation recorded before the 28 Jan 2026 cutover; check whether the same party also appears on the current UK Sanctions List, and treat either appearance as a genuine UK sanctions hit, not a stale false positive.

First observed ; last confirmed present in UK Sanctions List (UKSL) list version gb_fcdo_uksl@2026-08-04, observed .

This page reflects the official UK Sanctions List (UKSL), version gb_fcdo_uksl@2026-08-04, as observed on 2026-06-03. ProofAML is not the issuing authority.

Request a correction or dispute (distinguishes a data-handling error on our side from the underlying official designation, which is the issuing authority's record).

How to cite this page

Zservers. ProofAML. This page reflects the official UK Sanctions List (UKSL), version gb_fcdo_uksl@2026-08-04, as observed on 2026-06-03. ProofAML is not the issuing authority. URL: https://proofaml.com/organizations/zservers-nk71fa111d/

Machine-readable export (FTM + lineage): /data/entities/71.json (record key nk71fa111d)