US Treasury Issues First Sanctions Against VPN Operators Supporting Ransomware Gangs

The Treasury targets the hidden infrastructure ransomware gangs depend on to launch attacks costing American businesses billions.

The U.S. Treasury Department has taken unprecedented action by issuing the first-ever sanctions against a Virtual Private Network operator for supporting ransomware activities. On July 22, 2026, the Treasury’s Office of Foreign Assets Control designated 1VPNS and its administrator, Dmytro Rashevskyi, as entities facilitating ransomware operations. This marks a significant escalation in how U.S. authorities are targeting the infrastructure that enables ransomware gangs to operate with relative impunity.

1VPNS operated as a critical enabler for multiple ransomware groups seeking to hide their attack origins, deploy malware, and manage stolen data. Numerous criminal organizations purchased infrastructure from 1VPNS specifically to mask their digital footprints and manage extortion campaigns targeting American businesses and critical infrastructure. The Treasury’s action signals that authorities now view VPN providers enabling ransomware operations as direct participants in these crimes, not merely passive service providers. The sanctions come after European law enforcement dismantled 1VPNS’s infrastructure in May 2026 through Operation Saffron, a joint action led by French and Dutch authorities with support from the FBI Boston Field Office. This coordinated international effort, coupled with the Treasury’s sanctions, demonstrates a new approach to disrupting ransomware networks by attacking the infrastructure that criminal groups depend on to operate.

Table of Contents

Why Does the Treasury Target VPN Services Used by Ransomware Gangs?

ransomware gangs require anonymity to operate successfully. They need hidden servers to communicate with victims, deploy malware, and exfiltrate data without law enforcement easily tracing their activities back to them. VPN services and reseller infrastructure create the network obfuscation that ransomware operators depend on, making these services critical to the ransomware business model. By targeting 1VPNS, the Treasury is attacking the foundation that allows multiple ransomware groups to operate simultaneously. The financial scale of ransomware losses has reached billions of dollars across U.S.

businesses and critical infrastructure providers. A single ransomware attack can cost a healthcare system millions in downtime and recovery expenses, or leave municipalities unable to provide essential services. When the Treasury sanctions a VPN service enabling these attacks, it’s targeting infrastructure that has demonstrably contributed to massive financial harm to the American economy. The targeting of VPN services also reflects a strategic shift. Rather than only pursuing individual ransomware operators—who often operate across multiple countries and use changing identities—the Treasury is dismantling the platforms that serve many ransomware groups simultaneously. 1VPNS sold access to infrastructure to numerous ransomware gangs, making it a single point of leverage for disrupting multiple criminal organizations at once.

How Did 1VPNS Become a Critical Ransomware Infrastructure Provider?

1VPNS operated as a commercial VPN service that went beyond providing anonymous internet access. The platform sold dedicated infrastructure and reseller access to criminal organizations, including ransomware gangs seeking to hide their command-and-control servers and malware distribution infrastructure. This approach—selling infrastructure specifically to criminals—distinguishes 1VPNS from legitimate VPN providers that serve general privacy-conscious users. Dmytro Rashevskyi, designated by OFAC as an administrator of 1VPNS, played a central role in the service’s operations and its support of ransomware activities.

His designation suggests that Treasury investigators traced operational decisions and infrastructure provisioning back to specific individuals within the organization, rather than treating 1VPNS as an abstract entity. This shift toward naming specific administrators increases the personal legal and financial liability for individuals running services that enable ransomware. One significant limitation of the current enforcement approach is that new VPN services and infrastructure providers can replace sanctioned services relatively quickly. Shutting down 1VPNS removes one option, but ransomware gangs have already begun migrating to alternative providers or using other obfuscation techniques. The underlying vulnerability—that VPN services can be provisioned by criminals or compromised insiders—remains difficult to address through sanctions alone.

Operation Saffron and the International Takedown Effort

The takedown of 1VPNS infrastructure occurred through Operation Saffron in May 2026, a coordinated effort that preceded the U.S. Treasury sanctions by two months. French and Dutch law enforcement agencies led the operation with technical support from the FBI Boston Field Office, reflecting the international nature of ransomware enforcement. Operation Saffron targeted the physical servers, domain registrations, and operational infrastructure that 1VPNS relied on to serve its criminal customer base. The European law enforcement action removed 1VPNS from operation, but the subsequent Treasury sanctions create additional enforcement mechanisms. While European authorities dismantled the infrastructure, U.S.

sanctions freeze any assets 1VPNS or its personnel may have within U.S. jurisdiction and prohibit American individuals and entities from doing business with the sanctioned parties. The combination of technical takedown and financial sanctions creates a more comprehensive disruption than either action alone. Operation Saffron’s success demonstrates that international cooperation against ransomware infrastructure is feasible and effective. However, the six-week delay between the infrastructure takedown and the Treasury sanctions highlights that coordinating cross-border law enforcement remains time-consuming. Ransomware gangs exploit this coordination lag by relocating to alternative infrastructure providers during the window when authorities work through formal designation processes.

Cryptor Sellers and the Malware Obfuscation Supply Chain

Beyond 1VPNS, the Treasury also sanctioned Yegeniy Vladimirovich Silayev for selling cryptors—tools that encrypt and disguise ransomware and other malware to evade security detection systems. Cryptors are encryption utilities that take identifiable malware code and transform it into forms that antivirus and endpoint detection systems cannot recognize. A ransomware variant detected once by security vendors becomes undetectable after passing through a cryptor, allowing the same malware to reinfect systems that previously had defenses against it. The cryptor supply chain represents a distinct layer of the ransomware ecosystem. Individual ransomware gangs don’t always develop their own obfuscation tools; instead, they purchase cryptor services from specialists like Silayev.

This specialization allows ransomware operators to focus on targeting and extortion while outsourcing technical evasion to dedicated tool developers. Sanctions against cryptor sellers interrupt this supply chain, but like the broader ransomware ecosystem, new sellers emerge when established providers are disrupted. Comparing cryptors to antivirus evasion techniques, cryptors are particularly effective because they’re automated and relatively commodity services. A ransomware group can submit code to a cryptor provider, receive obfuscated variants, and begin redeploying within hours. More sophisticated evasion techniques require custom development and deep technical expertise, but they affect fewer targets. Cryptor services scale malware evasion across multiple criminal groups, making them high-value targets for law enforcement.

The Ransomware Ecosystem and Billions in Losses

The Treasury’s focus on infrastructure providers reflects the scale of ransomware’s financial impact. Ransomware groups using services and tools provided by 1VPNS and cryptor sellers have caused billions of dollars in losses to U.S. businesses and critical infrastructure providers. This figure encompasses direct ransom payments, recovery and remediation costs, lost productivity, and the cost of incident response across thousands of organizations. Individual attacks illustrate the scale of these losses. Healthcare systems hit by ransomware often face millions in recovery costs plus operational disruption that can delay critical patient care.

Municipal governments have paid tens of millions to recover from ransomware, redirecting resources from services to recovery efforts. Manufacturing facilities have suffered production shutdowns costing millions per day. When Treasury officials cite “billions in losses,” they’re quantifying the cumulative impact of thousands of attacks enabled by infrastructure providers like 1VPNS. A critical warning: the sanctions against 1VPNS represent progress, but they do not indicate that ransomware threats are declining. Ransomware groups have already identified alternative infrastructure providers, and new services continue to emerge in countries with limited law enforcement cooperation. The disruption caused by Operation Saffron and the Treasury sanctions will likely result in ransomware gangs being temporarily inconvenienced rather than stopped entirely.

OFAC Sanctions and Enforcement Mechanisms Against Digital Infrastructure

When the Treasury designates an entity or individual through OFAC sanctions, it triggers specific legal consequences. All property and interests belonging to the designated party that are within U.S. jurisdiction are frozen. American individuals and entities are prohibited from conducting transactions with sanctioned parties. Banks and payment processors must block any attempt to transfer funds to or from sanctioned entities.

For a digital infrastructure provider like 1VPNS, OFAC sanctions create several enforcement challenges. The service itself has already been dismantled by European authorities, so the primary enforcement leverage is against any remaining assets or related business interests. The designation of Dmytro Rashevskyi creates personal liability; he cannot access U.S. financial systems or maintain business relationships with American companies. However, individuals and organizations based in countries with poor U.S. relations can often circumvent these sanctions through alternative financial and banking channels.

Implications for Legitimate VPN Services and Future Enforcement

The Treasury’s sanctions target VPN operators who actively supported ransomware, a distinction that should not be confused with sanctions on legitimate privacy-focused VPN services. Mainstream VPN providers that serve general users and enforce terms of service prohibiting criminal activity are unaffected by these sanctions. However, the precedent has been established: VPN services that knowingly provision infrastructure to criminals or facilitate ransomware operations face designation and asset seizure.

For the broader cybersecurity landscape, the Treasury’s action signals that infrastructure providers enabling major crimes are now on par with the criminals themselves in terms of legal targeting. Law enforcement agencies are increasingly treating VPN resellers, hosting providers, and tool developers as primary targets rather than secondary concerns. This approach may have a deterrent effect on companies considering whether to sell infrastructure to questionable customers, though the financial incentives of the ransomware market will continue attracting new providers willing to take the legal risk.


You Might Also Like