U.S. Sanctions First VPN and Cryptor Seller for Aiding Ransomware
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has imposed sanctions on two individuals and a VPN service provider for facilitating ransomware operations and other cybercriminal activities targeting American organizations. The action targets First VPN Service (1VPNS) and its 45-year-old Ukrainian administrator Dmytro Rashevskyi, alongside Belarusian national Yegeniy Vladimirovich Silayev, who sold cryptors designed to disguise ransomware and other malware as legitimate software to evade endpoint security tools.
First VPN Service was dismantled in May 2026 following a joint law enforcement operation involving European and North American authorities. Operating since 2014, the service marketed itself on a strict no-logs policy and an explicit refusal to cooperate with law enforcement, making it highly attractive to threat actors. According to OFAC, multiple ransomware groups used 1VPNS infrastructure to launch attacks against U.S. businesses, financial institutions, hospitals, and municipal governments, concealing their origins, deploying malware, and managing exfiltrated data. The Treasury noted that Rashevskyi used aliases including "Maksim Sorin" and "Roman Chabanenko" to acquire infrastructure from providers who had received abuse complaints about illegal activity originating from 1VPNS servers. Security researchers investigating suspicious traffic patterns can use a VPN/proxy detector to identify connections routed through known anonymizing services.
Silayev, meanwhile, sold cryptors that allowed ransomware operators to package their payloads to bypass antivirus detection, directly enabling extortion campaigns. The Treasury Department stated that ransomware groups using services from the designated parties caused billions of dollars in losses to American businesses and critical infrastructure operators, with victims spanning healthcare, finance, and government sectors. Officials also noted that the criminal ecosystem underpinning these attacks relies heavily on bulletproof hosting and anonymization services that deliberately ignore abuse reports.
In a parallel action, the U.K. and E.U. announced sanctions against 24 Russian individuals and entities tied to destructive cyber and hybrid operations across Europe. The measures target senior GRU leadership figures Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for directing cyber and hybrid threat operations, while Centre 16 of the FSB has been attributed to sabotage operations against Poland's energy grid late last year. The coordinated Western response signals escalating pressure on both state-sponsored and state-tolerated cybercriminal ecosystems. Defenders can harden their own environments by running a DNS leak test to verify that legitimate VPN deployments are not inadvertently exposing traffic, and using a WHOIS lookup to vet infrastructure providers before purchasing hosting or anonymization services.