US Treasury Issues First Sanctions Against VPN Operators Supporting Ransomware Gangs

Treasury sanctions VPN operator and cybercriminal suppliers for enabling 25+ ransomware groups targeting U.S. hospitals, governments, and financial firms.

On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarus national Yegeniy Vladimirovich Silayev for providing infrastructure that ransomware operators used to attack American hospitals, governments, and financial firms. This marks the first time the U.S.

government has directly targeted a VPN provider under sanctions, escalating enforcement against the criminal supply chain that enables ransomware extortion campaigns. 1VPNS operated since 2014 as a no-logs VPN deliberately marketed to cybercriminals on dark forums, refusing law enforcement requests and actively concealing the operations of at least 25 ransomware groups. The sanctions follow a May 2026 international law enforcement operation that seized 33 servers across 27 countries and exposed thousands of criminal accounts, demonstrating the vulnerability of infrastructure even criminal actors rely on.

Table of Contents

What First VPN Service Was and Why Criminals Used It

First VPN Service built its business model explicitly around criminals. The platform positioned itself as untraceable—no user logs, no cooperation with law enforcement, and anonymized billing designed to resist subpoenas. Rashevskyi, the administrator, used false identities like "Maksim Sorin" and "Roman Chabanenko" to purchase servers from providers that would otherwise reject accounts flagged for abuse, creating layers of plausible deniability.

ransomware operators needed exactly what 1VPNS offered: a way to hide reconnaissance activity, intrusions, and command-and-control servers from detection. When a criminal group scanned a hospital network or installed malware on a municipal government system, they used 1VPNS to mask the IP addresses that investigators would later trace. The service became infrastructure, like a criminal's mail drop or phone number.

Which Ransomware Groups and Attack Targets Were Involved

At least 25 distinct ransomware groups, including Avaddon, used First vpn's infrastructure to conduct reconnaissance and manage attack operations. The operators leveraged this anonymity to target hospitals, city and county governments, financial institutions, and private businesses across the United States.

These were not theoretical threats—1VPNS concealed the real origins and command infrastructure for ransomware extortion operations that locked critical systems and demanded millions in ransom. Yegeniy Vladimirovich Silayev, sanctioned alongside Rashevskyi, profited further by selling "cryptor" tools that disguised ransomware and other malware distributed through these same networks. This was not a single service but an ecosystem: the VPN provided anonymity, the cryptor tools provided obfuscation, and ransomware operators combined them to increase their odds of success before law enforcement could intervene.

How the International Takedown Exposed the Operation

In May 2026, French and Dutch authorities, supported by the FBI, dismantled 1VPNS infrastructure in what became known as Operation Saffron. The takedown seized 33 servers across 27 countries and exposed the user database containing thousands of criminal accounts. The breach was catastrophic for criminals who believed the service was truly anonymous.

Europol identified 506 specific criminal users from the seized data and generated 83 intelligence packages shared with law enforcement partners across seven countries. The operation demonstrated that even services marketed as bulletproof eventually fail—operators slip, infrastructure gets misconfigured, and databases get seized. For ransomware groups, the takedown meant exposed accounts and the sudden loss of a trusted anonymity layer.

What the Sanctions Mean and Who Feels the Impact

OFAC sanctions freeze any U.S. assets held by the sanctioned parties and prohibit American individuals and businesses from transacting with them. While Rashevskyi and Silayev are unlikely to be easily caught or extradited, the sanctions send a clear signal: providing infrastructure knowingly used by ransomware operators now triggers the same tools the U.S.

uses against terrorism and foreign adversaries. The sanctions are limited in practical enforcement—they do not instantly dismantle other criminal VPN services, nor do they eliminate ransomware. They do, however, close one major avenue that ransomware operators relied on and increase the legal and financial cost of operating similar services openly. Criminals will migrate to other VPNs and anonymity tools, but each new refuge remains vulnerable to the same takedown tactics Operation Saffron demonstrated.

What This Means for Ransomware Defense

Organizations defending against ransomware should recognize that operators' tools and infrastructure are fragile. Ransomware groups invest heavily in anonymity because they know that loss of cover means loss of capability. The takedown of 1VPNS shows that law enforcement, equipped with international cooperation and technical expertise, can penetrate even criminal infrastructure claimed to be impenetrable.

For security teams, this reinforces that ransomware is not a natural disaster but a criminal operation with identifiable actors, suppliers, and dependencies. Reporting attacks to law enforcement (FBI, CISA, or local authorities) feeds intelligence that agencies use to map these networks and pursue takedowns. The May 2026 operation succeeded partly because victims reported intrusions and shared indicators of compromise with authorities.

Frequently Asked Questions

If 1VPNS is already dismantled, why sanction it in July 2026?

The operation took place in May, but sanctions require separate legal and diplomatic action. OFAC sanctions freeze any remaining assets, deter similar services, and signal sustained U.S. commitment to disrupting the criminal supply chain—not just seizing one server at a time.

Can sanctioned individuals or companies appeal OFAC sanctions?

Yes, OFAC allows appeals, but the threshold is high and typically requires demonstrating factual error or due process violation. Sanctions against active criminal operators are rarely reversed.

Will this stop ransomware attacks?

No. Ransomware operators will migrate to other anonymity services and suppliers. The sanctions target one node in a larger ecosystem. They increase friction and cost for criminals but do not eliminate the threat.

Should I avoid all VPNs because of this?

No. Legitimate VPNs with transparent privacy policies, regular audits, and willingness to cooperate with law enforcement are distinct from services like 1VPNS that were designed solely for crime. The issue is intent and design, not the technology itself.


You Might Also Like