First VPN Service as criminal VPN infrastructure for ransomware and fraud operators
Threat Actor Meta
Summary
Hide ▲
Show ▼
First VPN Service functioned as a criminal VPN layer that let ransomware, fraud, and data theft operators hide their identities, expanding the reach and resilience of underground infrastructure. The service was built for anonymous payments and hidden infrastructure, making it easier for offenders to mask attribution and move traffic through trusted-looking nodes. Its use by at least 25 ransomware groups shows that it was a shared cybercrime enabler rather than a niche access tool.
Related Happenings
1VPNS takedown in Operation Saffron
Law Enforcement
H score26
First: 14.07.2026 12:40
Last: 14.07.2026 12:40
Sources 1
How related:
The sanctions come after European law enforcement took down 1VPNS's website and infrastructure in May with support from the FBI's Boston Field Office, as part of a joint action dubbed "Operation Saffron" led by French and Dutch authorities.
About this happening:
French and Dutch authorities took down 1VPNS, seized 33 servers, and arrested its administrator in Operation Saffron, disrupting a VPN service used by ransomware...
1VPNS takedown in Operation Saffron
Law EnforcementHow related: The sanctions come after European law enforcement took down 1VPNS's website and infrastructure in May with support from the FBI's Boston Field Office, as part of a joint action dubbed "Operation Saffron" led by French and Dutch authorities.
About this happening: French and Dutch authorities took down 1VPNS, seized 33 servers, and arrested its administrator in Operation Saffron, disrupting a VPN service used by ransomware...
OFAC sanctions First VPN Service and two individuals
Regulatory/Legal Action
H score27
First: 14.07.2026 11:02
Last: 14.07.2026 11:02
Sources 1
How related:
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations.
About this happening:
OFAC sanctioned First VPN Service (1VPNS), Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev for enabling ransomware attacks and helping malicious software...
OFAC sanctions First VPN Service and two individuals
Regulatory/Legal ActionHow related: The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations.
About this happening: OFAC sanctioned First VPN Service (1VPNS), Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev for enabling ransomware attacks and helping malicious software...
Joint operation dismantles First VPN Service (1VPNS)
Law Enforcement
H score33
First: 14.07.2026 11:02
Last: 14.07.2026 11:02
Sources 1
How related:
First VPN was dismantled in May 2026 as part of a joint law enforcement operation by European and North American authorities for assisting criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks.
About this happening:
European and North American authorities dismantled First VPN Service (1VPNS) in a ransomware-linked takedown, removing infrastructure used to hide attack origins and o...
Joint operation dismantles First VPN Service (1VPNS)
Law EnforcementHow related: First VPN was dismantled in May 2026 as part of a joint law enforcement operation by European and North American authorities for assisting criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks.
About this happening: European and North American authorities dismantled First VPN Service (1VPNS) in a ransomware-linked takedown, removing infrastructure used to hide attack origins and o...
AudiA6 laundering ecosystem and Dark2Web forum
Threat Actor Meta
H score31
First: 11.06.2026 18:55
Last: 11.06.2026 18:55
Sources 1
About this happening:
AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...
AudiA6 laundering ecosystem and Dark2Web forum
Threat Actor MetaAbout this happening: AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...
Check Point VPN CVE-2026-50751 targeted exploitation wave
Exploitation Wave
H score47
First: 08.06.2026 17:17
Last: 08.06.2026 17:17
Sources 1
About this happening:
CVE-2026-50751 is an active exploitation wave against Check Point Remote Access VPN and Mobile Access deployments that use deprecated IKEv1. The flaw is an a...
Check Point VPN CVE-2026-50751 targeted exploitation wave
Exploitation WaveAbout this happening: CVE-2026-50751 is an active exploitation wave against Check Point Remote Access VPN and Mobile Access deployments that use deprecated IKEv1. The flaw is an a...
Timeline
-
14.07.2026 11:02 2 articles · 1d ago
OFAC sanctions First VPN Service and Dmytro Rashevskyi for ransomware support
Legal Policy Action UpdateThe U.S. Treasury Department’s OFAC sanctioned First VPN Service (1VPNS), Ukrainian administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev for supporting ransomware actors; Treasury said First VPN Service was used to hide attack origins, deploy malware, and manage exfiltrated data, and that victims included U.S. businesses, financial services companies, hospitals, and municipal governments.
Show sources
- U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support — thehackernews.com — 14.07.2026 11:02
- US sanctions VPN, malware providers for enabling ransomware attacks — www.bleepingcomputer.com — 14.07.2026 12:40
-
22.05.2026 20:35 2 articles · 1mo ago
Authorities announce dismantling of First VPN Service
Initial DisclosureAuthorities in Europe and North America announced the dismantling of First VPN Service, a criminal VPN used to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. The France- and Netherlands-led operation involved concurrent actions on May 19-20, including interviewing First VPN Service's administrator, conducting a house search in Ukraine, taking down 33 servers, and seizing infrastructure, while the FBI said the service had been active since about 2014 and had 32 exit node servers in 27 countries.
Show sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
04.03.2026 17:02 1 articles · 4mo ago
Huntress traces 1vpns[.]com to ransomware infrastructure
Technical Analysis UpdateHuntress Tactical Response Team traced a successful brute-force RDP intrusion on an exposed server into a geo-distributed infrastructure cluster centered on specialsseason[.]com and 1vpns[.]com, with TLS-certificate pivots uncovering related domains such as 1jabber[.]com and nologs[.]club. Telemetry and public threat reporting linked the same VPN service and related IP space to Hive ransomware and BlackSuite, reinforcing that the infrastructure supported ransomware operators.
Show sources
- How a Brute Force Attack Unmasked a Ransomware Infrastructure Network — www.bleepingcomputer.com — 04.03.2026 17:02