INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Europol Seizes First VPN Used by Ransomware Gangs

| 2026-05-22 11:03 HIGH HIGH
Executive Summary AI-generated
Europol desmantela First VPN, un servicio de red privada virtual utilizado por grupos de ransomware para ocultar sus ciberataques. La operación, coordinada por fuerzas del orden de Francia y Países Bajos con apoyo de Europol, Eurojust y otras agencias internacionales, ha sido el resultado de una inteligencia recopilada que expuso a miles de usuarios vinculados al ecosistema criminal. El servicio fue desmantelado en 33 servidores críticos, incluidos dominios onion asociados, y su administrador fue detenido en Ucrania.
Technical Mitigations AI-generated
* Use of secure protocols: Ensure that all communication and data transfer between the user's device and First VPN use secure, encrypted protocols such as HTTPS or TLS. * Regular security audits and penetration testing: Regularly perform security audits and penetration testing on the service to identify vulnerabilities and weaknesses, and ensure that any identified issues are addressed promptly. * Implementing least privilege access control: Implement a least privilege access control model for users accessing First VPN, where each user has only the necessary permissions to perform their specific tasks, reducing the risk of unauthorized access or data breaches. * Monitoring and logging: Continuously monitor and log all activity on the service, including login attempts, data transfers, and system calls, to detect any suspicious behavior or potential security incidents. * Regular software updates and patches: Regularly update and patch the service's underlying infrastructure and applications to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation PowerOFFOperation PowerOFFOperation SaffronOperation Saffron AvaddonAvaddon
Target & Sectors
NORTH_AMERICA NORTH_AMERICA BENELUX BENELUX DACH DACH legallegal
Incident Timeline
‎between 19 and 20 May 2026
Threat actors used Europol's services to target and dismantle the infrastructure of a ransomware VPN.
‎December 2021
Europol-led operation targeted First VPN, seizing notice displayed on its official dark web onion site.
attribution First VPN’s
attribution Data of Thousands of First VPN Users
attribution Europol’s European Cybercrime Centre
‎January 2026
Threat actors used a First VPN to target Spain.
target_region Spain
organisation the Black Axe
data_breach 34 suspected members
‎March 2026
Europol seized LeakBase, a cybercrime forum used to trade stolen data and leaked credentials.
organisation LeakBase
‎April 2026
Threat actors used DDoS services to target ransomware groups using Europol's Operation PowerOFF.
tactic Ddos
organisation Operation PowerOFF
‎2026/05/22
Europol desmantela First VPN, un servicio de red privada virtual utilizado por grupos de ransomware para ocultar sus ciberataques.
organisation Europol
organisation First VPN
organisation el servicio
organisation grupos de ransomware
organisation un
organisation nuevo
organisation el desmantelamiento de First
organisation un servicio de red privada
organisation los operadores
organisation campañas de ransomware
organisation La inteligencia recopilada expuso
organisation Europol Seizes
organisation Ransomware Gangs
organisation First VPN’s
organisation La operación
organisation bautizada como
organisation coordinada
organisation de Europol
organisation Eurojust
organisation el apagado de la infraestructura
organisation apagaron
organisation críticos
organisation incautaron de varios
organisation del servicio fue detenido
organisation el marco de una actuación
organisation como un proveedor de anonimato diseñado
organisation problemas de jurisdicción
organisation maliciosos que
organisation el ecosistema
organisation El uso de este
organisation resulta especialmente útil
organisation el origen
organisation La operación demuestra lo contrario.
organisation los equipos
organisation Según Europol
organisation campañas activas
infrastructure 33 servers
organisation Good News
organisation the Fight Against Cybercrime Cybercriminals
data_breach 140,000 members
infrastructure 53 domains
victims 75,000 users
Tactical Metrics
Metrics
infrastructure
33
Servers
Metrics
data_breach
34
Suspected Members
Metrics
data_breach
140,000
Members
Metrics
infrastructure
53
Domains
Metrics
victims
75,000
Users