US Treasury Issues First Sanctions Against VPN Operators Supporting Ransomware Gangs

The US Treasury has sanctioned VPN operators for the first time, targeting services that shielded ransomware groups for over a decade.
Ransomware incidents and attacks

The US Treasury has sanctioned VPN operators for the first time, targeting services that shielded ransomware groups for over a decade.

The Treasury targets the hidden infrastructure ransomware gangs depend on to launch attacks costing American businesses billions.

Ransomware attacks reached 5,275 incidents in H1 2026, with threat actors now targeting large enterprises alongside traditional SMB victims.

Ransomware groups are targeting enterprises with laser focus, with large companies facing 74 percent more attacks in 2026.

Attackers hide credential-stealing malware in fake and compromised open-source packages, targeting developers who trust package managers blindly.

Developers face a hidden risk when installing software packages: counterfeit repositories containing credential-stealing malware designed to capture their most sensitive authentication data.

Windows filesystem redirection tricks let compromised systems hide malware from EDR tools, requiring urgent patching and enhanced path validation.

Windows administrators face a new threat where legitimate system features become invisible smuggling routes for malware, bypassing EDR tools and security scanners.

Attackers are purchasing compromised login credentials as the fastest path to deploying ransomware, bypassing traditional defenses entirely.

Attackers deployed thousands of fake GitHub repositories disguised as popular software, tricking developers into installing malware.