US Treasury Issues First Sanctions Against VPN Operators Supporting Ransomware Gangs

The US Treasury has sanctioned VPN operators for the first time, targeting services that shielded ransomware groups for over a decade.

On July 13, 2026, the US Treasury’s Office of Foreign Assets Control (OFAC) crossed a historic threshold by formally sanctioning a VPN service provider for enabling ransomware operations. The designation of 1VPNS and related parties marks the first time the Treasury has taken this enforcement action against a virtual private network operator, signaling a significant escalation in how the government pursues the infrastructure behind some of the costliest cyberattacks on American institutions. The action was authorized under Executive Order 14390, signed in March 2026 to combat cybercrime and predatory schemes targeting American citizens.

The sanctioned parties—1VPNS administrator Dmytro Rashevskyi and cryptor seller Yegeniy Vladimirovich Silayev—provided the operational backbone that allowed ransomware gangs to carry out thousands of attacks against U.S. hospitals, financial services companies, municipal governments, and critical infrastructure providers. A hospital system hit by ransomware using 1VPNS infrastructure may have lost weeks of patient records access and paid millions in recovery costs; the financial sector and government agencies faced similarly devastating intrusions. The billions of dollars in cumulative losses across all sectors underscore why Treasury decided that sanctioning these enablers was necessary alongside traditional law enforcement efforts.

Table of Contents

Who Got Sanctioned and Why the VPN Operator Matters

The two primary targets of this action represent different but complementary roles in the ransomware supply chain. 1VPNS, operated by Rashevskyi, functioned as a turnkey privacy solution for cybercriminals—a service that allowed attackers to mask their true locations, deploy malware without revealing their origin, and manage stolen data exfiltration all while maintaining operational anonymity. Silayev’s role was more specialized: he developed and sold cryptors, tools designed to disguise ransomware and other malware as legitimate software so they could slip past security detection systems. Together, they provided both the cover and the camouflage that made large-scale ransomware campaigns feasible.

What makes this treasury action unusual is that VPN services operate in a legal gray zone. Legitimate companies and individuals use VPNs daily for privacy and security. The distinction with 1VPNS was not its existence as a VPN provider but its deliberate marketing to and active support of criminal groups. According to documents and law enforcement findings, 1VPNS operators knew exactly who their customers were and what activities those customers were conducting. This knowing facilitation moved the service from a neutral tool into accomplice territory, giving Treasury legal grounds to treat it as a sanctionable entity under the financial and asset-freezing authorities granted by the executive order.

The 1VPNS Infrastructure and Years of Criminal Use

The story of 1VPNS extends back well before the July 2026 sanctions. european law enforcement and the FBI had been tracking the service’s criminal infrastructure since at least December 2021, when investigators successfully infiltrated 1VPNS systems and began monitoring the criminal traffic flowing through its servers. Over 4.5 years of covert surveillance, law enforcement documented the service’s deep integration into nearly every major cybercrime investigation supported by Europol. The scale was staggering: ransomware groups ranging from small operators to major syndicates relied on 1VPNS to coordinate attacks and move stolen files.

The critical limitation of traditional law enforcement is that dismantling infrastructure takes time, and even successful takedowns can inspire replacement services. In May 2026, coordinating across seven countries, law enforcement executed a major operation that seized 33 servers distributed across 27 countries and shut down 1VPNS’s primary domains. Despite this success, the servers and domains alone were not enough to prevent future criminal use of VPN infrastructure more broadly. That gap—between temporarily disrupting criminal infrastructure and preventing the emergence of successor services—is why Treasury’s sanctions designation was pursued in parallel. Sanctions create financial consequences that make it riskier for financial institutions, payment processors, and other businesses to work with the designated individuals, adding friction to their ability to launch replacement services.

The May 2026 Law Enforcement Takedown

The law enforcement operation that preceded Treasury’s sanctions was itself a milestone in international cybercrime cooperation. The FBI’s Boston Field Office partnered with Europol and law enforcement agencies across multiple European nations to execute a coordinated takedown of 1VPNS infrastructure in May 2026. The operation seized 33 servers, shut down the service’s primary internet domains, and collected evidence documenting years of criminal activity. For investigators, the breakthrough moment came when they successfully infiltrated the service’s backend systems in late 2021, allowing them to monitor the criminal communications and transactions flowing through 1VPNS infrastructure in real time. That 4.5-year window of covert monitoring gave law enforcement an unusually complete picture of how ransomware gangs operated.

They could see which groups used 1VPNS, which attacks were conducted from which servers, and which stolen data passed through the infrastructure. One limitation of the takedown itself is that it targeted infrastructure but not the operators themselves. Rashevskyi and other 1VPNS administrators were beyond the reach of European or FBI jurisdiction, making traditional criminal prosecution difficult. The Treasury sanctions designation addresses this limitation by freezing any U.S. assets, blocking financial transactions in U.S. dollars, and criminalizing business dealings with the designated individuals—effectively attempting to cut them off from the global financial system even when they cannot be extradited.

Ransomware Groups Dependent on 1VPNS, LockBit in Focus

The financial scale of damage inflicted by ransomware gangs using 1VPNS infrastructure illustrates why this is not a marginal issue. LockBit, one of the most prolific ransomware operations, generated at least $500 million in illicit profits over four years and conducted more than 2,000 confirmed attacks. While not every LockBit attack used 1VPNS, the service’s infrastructure appeared in the attack chain of numerous major ransomware campaigns. A hospital that was hit by LockBit ransomware and forced to shut down patient appointment systems for weeks, transferring critical surgeries to nearby facilities and turning away emergency patients, provides concrete evidence of the human impact beyond the financial figures.

The victim profile across all ransomware attacks leveraging 1VPNS infrastructure reveals the breadth of the targeting: U.S. hospitals dependent on networked medical systems, financial services firms managing customer accounts and deposits, municipal governments running water systems and emergency services, and critical infrastructure providers operating power grids and telecommunications. Each victim category faced disruptions that cascaded beyond the initial encryption event. A city government with encrypted servers lost the ability to process permit applications and bill payments; a financial services company faced regulatory reporting failures and customer notifications; a hospital diverted ambulances. The billions of dollars in cumulative losses across all sectors reflects not just ransom payments but recovery costs, system rebuilds, incident response consulting, regulatory fines, and insurance claims.

How Cryptor Tools Amplified the Attack Pipeline

Yegeniy Vladimirovich Silayev’s role as a cryptor developer deserves specific attention because it reveals how the ransomware supply chain operates in layers. A cryptor is a tool that takes a piece of malware—ransomware, spyware, or trojan—and wraps it in obfuscation techniques that make the code unrecognizable to signature-based antivirus and endpoint detection systems. The malware itself remains functionally identical underneath, but to a security scanner, it looks like an entirely different program, often a benign one. This allows attackers to deploy the same ransomware payload repeatedly across different targets while evading the same detection signatures.

The warning here is that cryptor tools lower the technical barrier to ransomware operations. A ransomware gang does not need to invest in sophisticated malware development teams if they can simply purchase cryptor services from operators like Silayev. This commoditization accelerates the attack velocity—new groups can launch campaigns faster, existing groups can scale their operations more efficiently. By designating Silayev alongside 1VPNS, Treasury is attempting to choke off the supply side of the tool chain, making it riskier for vendors to openly market cryptor services. However, this action assumes that cryptor development cannot easily relocate to jurisdictions with no extradition agreements with the US, a limitation that law enforcement has struggled with for years in the context of ransomware gangs themselves.

International Coordination and UK Involvement

Treasury’s action was explicitly coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office (FCDO), reflecting a broader shift toward multilateral enforcement against ransomware infrastructure. The US and UK sanctioned the same parties on the same day, multiplying the impact by freezing assets across both jurisdictions and raising the reputational and operational cost for any financial institution facilitating transactions involving the designated parties. This alignment also signals to other allied nations—many of which are increasingly targeted by ransomware gangs themselves—that coordinated sanctions against enablers are now a standard enforcement tool.

The multi-country law enforcement operation that preceded the sanctions involved seven nations working in parallel to seize servers and evidence. This kind of coordination does not happen by default; it requires agreements on evidence sharing, operational timing, and legal authority. The coordination also revealed a structural advantage for law enforcement: while ransomware gangs are dispersed and decentralized, the infrastructure they depend on—VPN services, payment processors, hosting providers, cryptor developers—can be harder to replicate than the ransomware code itself. By targeting the infrastructure and the people who operate it, rather than just the dispersed criminal groups, enforcement can raise the cost of ransomware operations across the entire ecosystem.

The Precedent and Implications for Cybercrime Supply Chains

This is the first Treasury sanctions action against a VPN provider for ransomware facilitation, but it is unlikely to be the last. The executive order that authorized it (Executive Order 14390) explicitly mentions cybercrime, fraud, and predatory schemes as enforceable categories. This creates a regulatory precedent that any infrastructure provider—whether a VPN service, a cryptocurrency exchange, a hosting provider, or a malware-as-a-service platform—can now be designated if they knowingly facilitate ransomware or other serious cybercrimes. Providers operating in gray zones must now calculate the risk that facilitating criminal activity, even if technically legal in their jurisdiction, could result in US asset freezes and transactions bans.

The practical implications for cybercriminals are immediate: the cost of operations has increased. Ransomware gangs that relied on 1VPNS must migrate to replacement services, incurring operational disruption and increased scrutiny as they do so. Silayev’s designation makes it harder for him to move money or conduct legitimate business, effectively pushing him out of the global financial system. New VPN providers considering whether to market their services to criminals now have a concrete example of the consequences. However, the limitation remains that this enforcement mechanism works best against individuals and infrastructure with ties to the global financial system; criminal operators based in countries with minimal sanctions compliance or financial integration face less pressure.


You Might Also Like