INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

VPN and Cryptor Seller Sanctioned for Ransomware Losses

| 2026-07-14 19:47 HIGH LOW RANSOMWARE & EXTORTION LAW ENFORCEMENT
Executive Summary
AI-generated
The US Treasury has sanctioned two individuals and one entity for their role in supplying tools and infrastructure to ransomware groups, causing billions of dollars in losses to critical American infrastructure. The targeted entities include VPN provider 1VPNS and cryptor seller Dmytro Rashevskyi, who sold "cryptors" used by these groups to disguise malware as safe programs. This action reflects the US commitment to disrupting global cybercrime ecosystems and has been coordinated with allies like the UK's Foreign, Commonwealth & Development Office.
Technical Mitigations AI-generated
* Implement robust security measures, such as encryption and secure authentication protocols, to prevent unauthorized access to sensitive data. * Regularly update software and systems to patch vulnerabilities before they can be exploited by ransomware attackers. * Use secure communication channels, such as end-to-end encrypted messaging apps or email services with built-in security features, to protect against phishing and other social engineering attacks. * Conduct regular backups of critical data to prevent loss in the event of a ransomware attack. * Implement network segmentation and isolation techniques to limit the spread of malware and reduce the risk of compromise.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation SaffronOperation Saffron
Target & Sectors
NORTH_AMERICA NORTH_AMERICA BENELUX BENELUX
Incident Timeline
‎December 2021
Law enforcement officers infiltrated the 1VPNS VPN infrastructure and collected its user database before dismantling it.
infrastructure 33 servers
general_metric 27 countries
organisation VPN
organisation The State Department
organisation Treasury
organisation Silayev
organisation the U.S. State Department
‎March 6, 2026
Threat actors used a VPN provider and cryptor seller to target the U.S. Treasury, resulting in billions of dollars in ransomware losses under President Trump's Executive Order 14390.
attribution Trump’s Executive
organisation SecurityAffairs
‎May 2026
The United Kingdom's Foreign, Commonwealth & Development Office and the FBI coordinated sanctions against a VPN provider and cryptor seller.
target_region United Kingdom
attribution Commonwealth & Development Office
attribution FBI
attribution Operation Saffron
attribution Boston Field Office
target_region France
target_region Netherlands
‎July 13
The U.S. Treasury's Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions in losses to American businesses and critical infrastructure.
target_region United States
tactic Ransomware
‎2026/07/14
The U.S. Treasury Sanctions two individuals and one entity behind a ransomware attack on the United States, in coordination with the UK's Foreign, Commonwealth & Development Office and following law enforcement takedowns of infrastructure supporting 1VPNS.
target_region United Kingdom
attribution Commonwealth & Development Office
attribution FBI
tactic Ransomware
organisation the Office of Foreign Assets Control (OFAC
‎2026/07/14
1VPNS and its administrator Dmytro Rashevskyi were sanctioned by the US Treasury Department's Office of Foreign Assets Control for selling VPN services to ransomware groups.
organisation Foreign, Commonwealth & Development Office
organisation OFAC
organisation the European Union
organisation U.S. Treasury Sanctions VPN Provider
organisation Ransomware
organisation 1VPNS
organisation First VPN Service
organisation The U.S. Treasury Department's
organisation Office of Foreign Assets Control (OFAC
infrastructure 33 servers
organisation the Treasury Department
organisation State Department
organisation Europol
organisation EDR
Tactical Metrics
Metrics
infrastructure
33
Servers
Intelligence Sources