United States via Greenland, UK, Denmark.
It's also not the only attack model; it serves only as an example of the sort of power Five Eyes has within the five nations they wouldn't necessarily have in Iceland.
Another example: https://en.wikipedia.org/wiki/Room_641A
Colocating in Russia comes with its own issues.
Enemy of my enemy...
If you are afraid of a bogey men called Five Eyes and NSL, then colocating in Russia makes perfect sense.
If you are a publisher of KavkazCenter, you should probably host it somewhere in the US.
I.e. if it became illegal to say certain things about the US government, could I (an American citizen) hypothetically host my protest blog on a Russian provider and avoid prosecution?
Yes, you could probably safely criticize the US on a Russian-hosted blog, but in the scenario of a repeal of the First Amendment, I can't imagine the hosting location would save you from any theoretical prosecution.
My guess is most data, even at privacy focussed companies, ends up accidentally transmitted over a cable unencrypted at least once. It doesn't take much to forget to turn on strict HTTPS enforcement on cloudflare for example. Or to forget to encrypt your backups in transit. Or to have an employee download a database dump for testing over HTTP.
It only has to happen once for security services to keep it if it contains any data of interest to their filters.