US Treasury Issues First Sanctions Against VPN Operators Supporting Ransomware Gangs

Treasury sanctions VPN operator and cybercriminal suppliers for enabling 25+ ransomware groups targeting U.S. hospitals, governments, and financial firms.
Bank and financial institution data breaches

Treasury sanctions VPN operator and cybercriminal suppliers for enabling 25+ ransomware groups targeting U.S. hospitals, governments, and financial firms.

Large enterprises and U.S. healthcare organizations face accelerating ransomware targeting, with enterprise attacks up 74% and healthcare enduring 2.3 attacks daily in H1 2026.

Learn how OkoBot's fake seed-phrase pages trick hardware wallet users, and the one rule that stops the theft cold.

How a Steam game malware scheme allegedly drained $220K in crypto — and the practical steps gamers can take to stay safe.

Malware-laden fake wallet apps on the Apple App Store stole recovery phrases; similar campaigns target Android, Chrome extensions, and GitHub users with clipboard thieves and trojanized tools.

The US Treasury has sanctioned VPN operators for the first time, targeting services that shielded ransomware groups for over a decade.

The Treasury targets the hidden infrastructure ransomware gangs depend on to launch attacks costing American businesses billions.

Ransomware attacks reached 5,275 incidents in H1 2026, with threat actors now targeting large enterprises alongside traditional SMB victims.

Ransomware groups are targeting enterprises with laser focus, with large companies facing 74 percent more attacks in 2026.

Kaspersky's discovery of OkoBot reveals a 20-payload malware framework actively stealing cryptocurrency wallet credentials across 25 countries.