INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
VPN and Cryptor Seller Sanctioned for Ransomware Losses
| 2026-07-14 19:47 HIGH LOW RANSOMWARE & EXTORTION LAW ENFORCEMENT
Executive Summary
AI-generated
The US Treasury has sanctioned two individuals and one entity for their role in supplying tools and infrastructure to ransomware groups, causing billions of dollars in losses to critical American infrastructure. The targeted entities include VPN provider 1VPNS and cryptor seller Dmytro Rashevskyi, who sold "cryptors" used by these groups to disguise malware as safe programs. This action reflects the US commitment to disrupting global cybercrime ecosystems and has been coordinated with allies like the UK's Foreign, Commonwealth & Development Office.
Technical Mitigations AI-generated
* Implement robust security measures, such as encryption and secure authentication protocols, to prevent unauthorized access to sensitive data.
* Regularly update software and systems to patch vulnerabilities before they can be exploited by ransomware attackers.
* Use secure communication channels, such as end-to-end encrypted messaging apps or email services with built-in security features, to protect against phishing and other social engineering attacks.
* Conduct regular backups of critical data to prevent loss in the event of a ransomware attack.
* Implement network segmentation and isolation techniques to limit the spread of malware and reduce the risk of compromise.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation SaffronOperation Saffron
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
BENELUX
BENELUX
Incident Timeline
December 2021
Law enforcement officers infiltrated the 1VPNS VPN infrastructure and collected its user database before dismantling it.
Click on any entity below to view its context and source!
infrastructure
33 servers
The investigation had started in December 2021, with law enforcement infiltrating 1VPNS infrastructure and collecting its user database before dismantling it — 33 servers across 27 countries, and thousands of users exposed.
general_metric
27 countries
The investigation had started in December 2021, with law enforcement infiltrating 1VPNS infrastructure and collecting its user database before dismantling it — 33 servers across 27 countries, and thousands of users exposed.
organisation
VPN
The 1VPNS investigation began in December 2021, with law enforcement officers infiltrating the VPN's infrastructure and collecting its user database before it was dismantled.
organisation
The State Department
The State Department framed the action explicitly as targeting the supply chain behind ransomware, not just the operators themselves.
organisation
Treasury
Treasury estimates the combined operations involving 1VPNS and Silayev’s cryptors have caused billions in losses.
organisation
Silayev
Treasury estimates the combined operations involving 1VPNS and Silayev’s cryptors have caused billions in losses.
organisation
the U.S. State Department
reads the press release published by the U.S. State Department.
March 6, 2026
Threat actors used a VPN provider and cryptor seller to target the U.S. Treasury, resulting in billions of dollars in ransomware losses under President Trump's Executive Order 14390.
Click on any entity below to view its context and source!
attribution
Trump’s Executive
The action sits under Trump’s Executive Order 14390 of March 6, 2026, directing agencies to harden U.S. financial and digital systems against foreign cybercrime.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, VPN Provider)
May 2026
The United Kingdom's Foreign, Commonwealth & Development Office and the FBI coordinated sanctions against a VPN provider and cryptor seller.
Click on any entity below to view its context and source!
target_region
United Kingdom
Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”
attribution
Commonwealth & Development Office
Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”
attribution
FBI
Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”
The sanctions follow a May 2026 takedown of 1VPNS’s website and servers by European law enforcement, with support from the FBI’s Boston Field Office, as part of Operation Saffron led by French and Dutch authorities.
attribution
Operation Saffron
The sanctions follow a May 2026 takedown of 1VPNS’s website and servers by European law enforcement, with support from the FBI’s Boston Field Office, as part of Operation Saffron led by French and Dutch authorities.
attribution
Boston Field Office
The sanctions follow a May 2026 takedown of 1VPNS’s website and servers by European law enforcement, with support from the FBI’s Boston Field Office, as part of Operation Saffron led by French and Dutch authorities.
target_region
France
The sanctions follow a May 2026 takedown of 1VPNS’s website and servers by European law enforcement, with support from the FBI’s Boston Field Office, as part of Operation Saffron led by French and Dutch authorities.
target_region
Netherlands
The sanctions follow a May 2026 takedown of 1VPNS’s website and servers by European law enforcement, with support from the FBI’s Boston Field Office, as part of Operation Saffron led by French and Dutch authorities.
July 13
The U.S. Treasury's Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions in losses to American businesses and critical infrastructure.
Click on any entity below to view its context and source!
target_region
United States
The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to American businesses and critical infrastructure.
tactic
Ransomware
The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to American businesses and critical infrastructure.
2026/07/14
The U.S. Treasury Sanctions two individuals and one entity behind a ransomware attack on the United States, in coordination with the UK's Foreign, Commonwealth & Development Office and following law enforcement takedowns of infrastructure supporting 1VPNS.
Click on any entity below to view its context and source!
target_region
United Kingdom
Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”
attribution
Commonwealth & Development Office
Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”
attribution
FBI
Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”
tactic
Ransomware
“Today, the Office of Foreign Assets Control (OFAC) is designating two individuals and one entity enabling ransomware actors’ and other cybercriminals’ malign activities, notably ransomware attacks against Americans.
organisation
the Office of Foreign Assets Control (OFAC
“Today, the Office of Foreign Assets Control (OFAC) is designating two individuals and one entity enabling ransomware actors’ and other cybercriminals’ malign activities, notably ransomware attacks against Americans.
2026/07/14
1VPNS and its administrator Dmytro Rashevskyi were sanctioned by the US Treasury Department's Office of Foreign Assets Control for selling VPN services to ransomware groups.
Click on any entity below to view its context and source!
organisation
Foreign, Commonwealth & Development Office
The action was coordinated with the UK’s Foreign, Commonwealth & Development Office, which sanctioned additional cybercriminals the same day.
"
OFAC said the action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office.
organisation
OFAC
"
OFAC said the action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office.
OFAC is also designating Yegeniy Vladimirovich Silayev (Silayev), an individual who sells “cryptors,” which are tools used to disguise ransomware and other malware as safe programs to prevent security systems from detecting or deactivating them.”
organisation
the European Union
On Monday, the European Union and the United Kingdom also
jointly sanctioned dozens of Russian individuals and entities
, accusing Russia of coordinating a network of hacking groups linked to cyberattacks across Europe.
organisation
U.S. Treasury Sanctions VPN Provider
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses.
organisation
Ransomware
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure.
organisation
1VPNS
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure.
Since it surfaced in 2014, 1VPNS has advertised on cybercriminal forums that it keeps no logs of user activity or identities and would not cooperate with law enforcement.
organisation
First VPN Service
These include First VPN Service (1VPNS), a virtual private network (VPN) provider selling services to ransomware groups, and its administrator, Dmytro Rashevskyi (Rashevskyi).
On Monday, OFAC
designated First VPN Service (1VPNS)
, a virtual private network provider that sold services to ransomware groups, and its administrator, Dmytro Rashevskyi.
organisation
The U.S. Treasury Department's
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations.
organisation
Office of Foreign Assets Control (OFAC
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations.
infrastructure
33 servers
Throughout the joint operation, the authorities seized 33 servers linked to 1VPNs across 27 countries, arrested its administrator, and exposed thousands of users associated with ransomware, fraud, and other malicious activity worldwide.
organisation
the Treasury Department
This week, the Treasury Department also sanctioned Belarusian national Yegeniy Vladimirovich Silayev, who sells cryptors (also known as crypters), which are tools that help ransomware and other malware evade detection by security software.
organisation
State Department
"These actors supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers,"
said
State Department spokesperson Thomas Pigott.
organisation
Europol
At the time, Europol also said that the VPN service's name had surfaced in nearly every major cybercrime investigation it supported.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
33
Servers
Click for context!
The investigation had started in December 2021, with law enforcement infiltrating 1VPNS infrastructure and collecting its user database before dismantling it — 33 servers across 27 countries, and thousands of users exposed.
Throughout the joint operation, the authorities seized 33 servers linked to 1VPNs across 27 countries, arrested its administrator, and exposed thousands of users associated with ransomware, fraud, and other malicious activity worldwide.
Intelligence Sources
Security Affairs
2026-07-14
BleepingComputer
2026-07-14
US sanctions VPN, malware providers for enabling ransomware attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-15T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
Foreign, Commonwealth & Development Office
entity
6x
timeline
Temporal Reference
2026/07/14
date
5x
target region
Target Country
United Kingdom
country
5x
attribution
Attributing Entity
Commonwealth & Development Office
authority
2x
general metric
%
54
%
Contextual Telemetry
Context Block
6 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
campaign
Campaign
Operation Saffron
operation
infrastructure
Servers
33
servers
general metric
Countries
27
countries
source region
Origin Country
Russian Federation
country
target region
Target Region
EUROPE
region
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.