The US Treasury Department’s Office of Foreign Assets Control (OFAC) has taken a significant step in combating ransomware attacks against American organizations, sanctioning two individuals and one entity that enabled such crimes. The move targets First VPN Service (1VPNS), a virtual private network provider with ties to ransomware groups, as well as its administrator, Dmytro Rashevskyi.
Since its emergence in 2014, 1VPNS has openly advertised on cybercrime forums that it maintains no user activity or identity logs and would not cooperate with law enforcement. However, investigators allegedly discovered that Rashevskyi used false identities to acquire infrastructure from companies that otherwise wouldn’t have done business with them due to abuse complaints.
The sanctions come after a joint operation dubbed “Operation Saffron” led by French and Dutch authorities in May, which involved taking down 1VPNS’s website and infrastructure with the support of the FBI’s Boston Field Office. The investigation began in December 2021, when law enforcement officers infiltrated 1VPNS’s infrastructure and collected its user database before dismantling it.
The operation resulted in the seizure of 33 servers linked to 1VPNs across 27 countries, the arrest of Rashevskyi, and exposure of thousands of users associated with ransomware, fraud, and other malicious activity worldwide. Europol noted that the VPN service’s name had surfaced in nearly every major cybercrime investigation it supported.
Victims of ransomware attacks involving 1VPNS’ infrastructure included US businesses, hospitals, financial services firms, and municipal governments. Officials estimate that these operations have caused billions of dollars in losses to American critical infrastructure providers.
The Treasury Department also sanctioned Belarusian national Yegeniy Vladimirovich Silayev, who sells cryptors – tools that help ransomware and other malware evade detection by security software. These actors supplied ransomware groups with the means to hide their identities, disguise malicious software, and evade detection, enabling attacks that have caused significant financial losses.
The US action was coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office. Under these sanctions, all property of the designated individuals and entities within US jurisdiction is blocked, while US persons and businesses are barred from transactions involving them.
This move highlights the importance of targeting not just ransomware operators but also service providers and tool suppliers who facilitate their attacks. By dismantling the broader networks that sustain cybercriminal activity worldwide, the US and its partners aim to disrupt the business model of these groups and reduce the financial losses associated with ransomware attacks.
For businesses and individuals, this development serves as a reminder to prioritize cybersecurity measures. With the average organization experiencing 54 successful attacks each year, it’s essential to regularly test security protocols to ensure they can detect and respond to threats effectively. By doing so, we can prevent these types of attacks from occurring in the first place and minimize their impact when they do happen.
Source: Bleeping Computer — 2026-07-14