Summary

  • The registration number carried by the RIPE organisation behind AS210328 resolves, in Russian corporate registers, to AO 'ALMAZ' of Yuzhno-Sakhalinsk — a company whose declared primary activity is marine fish farming, whose charter capital is RUB 10,000 and which reports two employees.
  • The storefront at almazcloud.network sells cloud interconnection priced in US dollars and names a company-director role mailbox whose local part points to a director called 'Maksim'. The registered sole director is Khan Marina Menkhoevna, in post since 6 May 2019.
  • Routing data attributes two of the three prefixes announced by AS210328 to a third party, and the advertised direct peering to Yandex, Sberbank and Rostelecom does not appear in any observed adjacency.
  • The registry objects around this network were freshly edited in 2026 — organisation object on 13 May, a new ROA on 20 August, the aut-num on 21 August — while the commercial surface has not moved since 2022.

A registration number inside a RIPE organisation object looks like a formality: a string entered once and rarely revisited. For ORG-ZA238-RIPE — the organisation recorded behind the autonomous system AS210328, whose as-name is ALMAZ and whose operator brands itself DIAMOND at almazcloud.network — that string is 1196501003357. Following the number out of the registry and into the Russian corporate registers is where the operator's documentary substance stops matching its surface. The RIPE object chain is visible through public mirrors and the RIPE NCC's own statistics service (RIPE Stat, IPIP.NET mirror).

This report does not re-measure the network. Earlier BTW coverage already documented the identity verification gap (BTW Media identity verification) and the identity chain that no evidence closes (BTW Media identity chain). It asks a narrower and more uncomfortable question: who, in the documentary record, stands behind the cloud business being sold, and does any public source connect the seller to the company and the person the registry actually names?

Three layers answer differently, and each is governed by a different kind of evidence.

The registration number the registry carries

The organisation object behind AS210328 records the organisation name as AO ALMAZ in country RU, with registration number 1196501003357, and the aut-num object carries the as-name ALMAZ together with the operator's domain in its remarks field (IPIP.NET mirror, RIPE Stat). That is the end of what the registry itself establishes. RIPE Database personal-data handling means the administrative and technical contact chain attached to the object is not a reliable public pointer to a named human: mirrors disagree on whether the handle is a live role object or the placeholder identity used after redaction, and both versions can be seen in public copies of the same record (IPIP.NET mirror, IPinfo AS210328).

The number, however, is a hard pointer, because Russian corporate registers are keyed on it. Running 1196501003357 through the independent aggregators that mirror the state registers — Audit-IT, Checko, Tochka, SPARK-Interfax and T-Bank — produces the same entity every time, and it is not a cloud company (Audit-IT record, Checko record, Tochka dossier, SPARK-Interfax record, T-Bank counterparty record).

What the Russian corporate register records

Across all five aggregators the same picture holds. AO 'ALMAZ' was registered on 6 May 2019 in Yuzhno-Sakhalinsk, Sakhalin oblast, with INN 6501304360. Its declared primary activity is marine fish farming; Tochka's dossier lists thirty-four further OKVED activity codes and SPARK counts thirty-five, but the first entry is the fish-farming code (Tochka dossier, SPARK-Interfax record). The registered address is a street address in Yuzhno-Sakhalinsk. Charter capital is RUB 10,000, and Tochka classifies the entity as a micro-business (Tochka dossier, T-Bank counterparty record).

The sole registered director is Khan Marina Menkhoevna, recorded in post since 6 May 2019 — that is, since the company's registration — by every aggregator examined (Audit-IT record, Checko record, Tochka dossier, SPARK-Interfax record, T-Bank counterparty record). Headcount is two employees, reported for both 2024 and 2025 (Audit-IT record, Checko record). Checko records an average monthly salary of RUB 86,200 in 2025, RUB 59,200 in 2024 and RUB 73,800 in 2023 (Checko record).

The financial line is short and, for a cloud operator, striking. Audit-IT reports 2024 revenue of RUB 14.6 million with a profit of RUB 8.5 million, and 2025 revenue reported as absent with a loss of RUB 883,000 (Audit-IT record). Checko reports a 2025 net loss of RUB 883,000 with taxes and contributions of RUB 380,300 (Checko record). At a dollar pricing sheet of hundreds of dollars per month per product, a company reporting no 2025 revenue has not booked the cloud business it advertises.

Two further register entries matter for the biography of the entity. The founder of record — Matveeva Yulia Yurievna — appears only as a historical entry, removed from the register on 30 November 2021; no founder is currently recorded through the aggregator views examined (Checko record, Audit-IT record). And the legal predecessor, OOO KROKS, was liquidated on 5 March 2022 (Audit-IT record).

On the enforcement side, SPARK reports no tenders, no arbitration cases and no enforcement proceedings against the entity (SPARK-Interfax record). That absence is worth stating plainly: there is no court finding, no enforcement action and no procurement record here. The divergence this report describes is documentary, not adjudicated. T-Bank's risk summary records zero negative and four positive facts (T-Bank counterparty record).

The storefront sells something else

The commercial surface does not read like the register at all. The site at almazcloud.network brands the operation DIAMOND — the Russian word 'almaz' — and sells a priced catalogue: Cloud Connect at USD 499 per month per 10G port, BGP announcements at USD 99 per month per prefix, a no-BGP GRE tunnel at USD 99 per month per 100 Mbps, a corporate cloud VPN at USD 9 per user, and a cloud reselling product at USD 99 per month (almazcloud.network).

Three features of that catalogue deserve attention. First, the pricing is in US dollars, which is a choice aimed at an international counterparty rather than a domestic one. Second, the headline promise is interconnection quality — a direct physical peering connection to Yandex, Sberbank and Rostelecom — rather than storage, compute or platform services; the product being sold is adjacency, not capacity (almazcloud.network). Third, the management section is implemented as role mailboxes rather than named executives, and one of those local parts names a company director called 'Maksim' (almazcloud.network).

That last point is the crux of the persona gap. The only director the corporate register supports is Khan Marina Menkhoevna, in post since the company was registered. The storefront implies a different person. Neither the site nor the register offers a document that maps the two onto each other, and this report does not assert that they are the same person, that the persona is false, or that any particular individual controls the network. What can be said is narrower and firmer: the register names one director and the marketing names another, and no public record reviewed here reconciles them.

The routing record: 512 addresses and a third-party attribution

The third layer is what the network actually announces. Routing data shows AS210328 originating three IPv4 prefixes with a combined 512 IPv4 addresses (Hurricane Electric BGP view, ping.pe prefix record). Two of the three carry valid RPKI authorisations; the third is shown without a covering ROA (ping.pe prefix record).

Two of the three announced prefixes are attributed in routing data to a third party named in those records as Vlad Cojuhari, not to AO ALMAZ (Hurricane Electric BGP view). That attribution is one of the strongest single observations in this file, because it separates the autonomous system from the address space it announces for two of its three prefixes. A network selling interconnection on the strength of its own address footprint is, on this evidence, partly announcing space that public routing records associate with someone else.

The advertised peering fares no better. Hurricane Electric's view lists the observed adjacencies as AS202425, AS201814 and AS48693 — no Yandex, no Sberbank, no Rostelecom (Hurricane Electric BGP view). PeeringDB's entry for the network is self-reported, not observed: it describes an NSP with a self-declared traffic level in the 10-20 Gbps band, a restrictive peering policy and three Moscow interconnection facilities, last updated in 2022 (PeeringDB entry). Self-reported traffic levels and facility lists are claims made by the operator, not measurements taken by anyone else, and nothing in the observed routing corroborates the peering that the storefront headlines.

IPinfo's view of the AS adds a second layer of context through associated address space (IPinfo AS210328), and the upstream picture inside the registry objects is itself unstable: the freshly edited aut-num points to one upstream, while an earlier-era copy of the same object points to another (IPIP.NET mirror, RIPE Stat). Discrepant snapshots of one object are a normal artefact of mirrors, but here the discrepancy is deliberately kept in the reader's view because it means the registry alone cannot settle which transit relationship is current.

The 2026 edit chain on a 2022 storefront

The most recent activity in this file is administrative. The organisation object ORG-ZA238-RIPE was last modified on 13 May 2026; a ROA covering 185.136.15.0/24 was created on 20 August 2026; and the aut-num object was edited on 21 August 2026 (IPIP.NET mirror, RIPE Stat). Over the same period, the storefront, the PeeringDB record and the observable routing show no comparable movement; the PeeringDB entry has stood since 2022 (PeeringDB entry, almazcloud.network).

Read carefully, these are two different kinds of clock. Registry edits are a ledger activity: they keep authorisation state, contact references and routing policy current, and they are performed by whoever holds the maintainer credentials. Market activity is a commercial claim: catalogue changes, price moves, new customers, new facilities. For an operating cloud provider the two clocks normally tick together. Here the ledger has been tended while the commercial surface has stayed still, which is consistent with an operation being kept administratively alive without being commercially active.

It is not consistent with a provider onboarding enterprise customers at the price points advertised. The edit chain also explains why this network keeps appearing in registry-monitoring work: it produces dated, checkable events without producing dated, checkable commercial ones.

What this evidence can and cannot establish

The honest boundary of this report is as important as its findings. Russian corporate aggregators mirror state registers and carry snapshot lag; their figures are as-of their own snapshots, not live state (Audit-IT record, Checko record, Tochka dossier, SPARK-Interfax record, T-Bank counterparty record). RIPE's personal-data handling makes the contact chain attached to the autonomous system unreadable as a chain of named individuals, so the humans who hold the maintainer credentials cannot be identified from the public record (IPIP.NET mirror).

What the evidence does establish is a set of documentary mismatches, each independently sourced: a registration number that resolves to a marine-fish-farming microenterprise with two employees and no 2025 revenue; a storefront that sells dollar-priced interconnection and implies a director who does not appear in that register; a routing footprint of 512 IPv4 addresses where two of three announced prefixes are attributed in routing data to a third party; and a registry object chain edited in 2026 around a commercial surface unchanged since 2022.

Together these mean that no public record reviewed here connects the marketed cloud operator to the registered legal person, and none connects it to operating cloud capacity.

What the evidence does not establish is intent, control or wrongdoing. It does not show who operates AS210328; registry maintainer credentials are not public. It does not show that the storefront has no customers; it shows that the registered entity reports no revenue for 2025. It does not show that the advertised peering is false in every sense; it shows that no observed adjacency matches it. A reader who needs a legal conclusion will not find one here, and should not read one in. What a reader can do is hold the three layers side by side and notice that they do not describe the same business.

For the directory-level record behind this entity, including the linked identity trail, see the almazcloud.network entry (directory entry). The prior verification work that first surfaced these mismatches remains the starting point for anyone following the case (BTW Media identity verification, BTW Media identity chain).