The U.S. Treasury Department has sanctioned First VPN Service, a VPN provider favored by ransomware groups, and its administrator, Dmytro Rashevskyi, for enabling ransomware attacks against American targets. These sanctions reflect ongoing efforts to curb cybercrime affecting critical infrastructure.
Additionally, Yegeniy Silayev, a Belarusian national, has been sanctioned for selling cryptors, which conceal malicious software from security systems. The sanctions prohibit U.S. entities from conducting transactions with any of the designated individuals or entities.
First VPN Service (1VPNS) has been operational since 2014, promoting a service that didn't log user activities or cooperate with law enforcement. This lack of cooperation ostensibly appealed to and supported cybercriminal activities, including ransomware, data theft, and other malicious activities.
The administrator, Rashevskyi, utilized fake identities to purchase necessary infrastructure, bypassing companies' refusal due to complaints of illegal activities originating from 1VPNS servers.
The law enforcement operation, known as "Operation Saffron," dismantled the VPN's infrastructure in May 2026 in a concerted effort by European and North American authorities, including the FBI and intelligence agencies from France and the Netherlands.
The operation resulted in the seizure of 33 servers and the collection of the VPN's user database, revealing extensive utilization by ransomware groups.
The sanctions aim to weaken ransomware networks by disrupting the services they rely upon for anonymous operations. This action highlights the increasing priority given by law enforcement globally to hinder cybercriminals’ methods and support networks.
By targeting both service providers and individuals involved in directly supporting ransomware groups, the sanctions intend to mitigate the growing threat to critical infrastructures posed by these cybercriminal enterprises.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The U.S. Treasury sanctioned VPN provider First VPN Service and its administrator for enabling ransomware attacks. The action follows a large-scale operation that took down their infrastructure and revealed numerous cybercriminal activities, impacting U.S. businesses and critical infrastructure.
The U.S. Treasury sanctioned VPN provider First VPN Service and two individuals for facilitating ransomware attacks. This action highlights the government's response to the growing threat of cybercrime that affects critical U.S. infrastructure.
The U.S. sanctioned VPN provider First VPN Service (1VPNS) and its administrator for enabling ransomware attacks on U.S. infrastructure. The sanctions aim to disrupt operations of ransomware gangs by targeting service providers and suppliers used in their attacks.