US sanctions VPN, malware providers for enabling ransomware attacks

The US Treasury Department’s Office of Foreign Assets Control (OFAC) has taken a major step in combating ransomware attacks, sanctioning two individuals and one entity for their role in enabling these devastating cybercrimes. The sanctions target First VPN Service (1VPNS), a virtual private network provider that sold services to ransomware groups, as well as its administrator, Dmytro Rashevskyi.

The investigation into 1VPNS began in December 2021, when law enforcement officers infiltrated the VPN’s infrastructure and collected its user database. This effort was part of a joint operation dubbed “Operation Saffron” led by French and Dutch authorities, which also involved the FBI’s Boston Field Office. The authorities seized 33 servers linked to 1VPNs across 27 countries, arrested its administrator, and exposed thousands of users associated with ransomware, fraud, and other malicious activity worldwide.

The impact of 1VPNS’ activities was staggering. Victims of ransomware attacks involving the VPN service’s infrastructure included US businesses, hospitals, financial services firms, and municipal governments. The Treasury Department estimates that ransomware operations using 1VPNS have caused billions of dollars in losses to critical infrastructure providers across the United States.

But 1VPNS is not the only entity being held accountable for its role in enabling ransomware attacks. Yegeniy Vladimirovich Silayev, a Belarusian national, was also sanctioned by the Treasury Department for selling cryptors (also known as crypters), tools that help ransomware and other malware evade detection by security software. These cryptors were allegedly used to disguise malicious software and hide the identities of ransomware operators.

The sanctions imposed by OFAC are designed to disrupt the networks that sustain cybercriminal activity worldwide. By targeting not just ransomware operators but also service providers and tool suppliers, the United States is taking a proactive approach to combating these threats. The action was coordinated with the UK’s Foreign, Commonwealth & Development Office, and all property of the designated individuals and entities within US jurisdiction is now blocked.

The impact of these sanctions will be felt far beyond the US borders. As part of its efforts to combat cybercrime, the European Union and the United Kingdom have jointly sanctioned dozens of Russian individuals and entities accused of coordinating a network of hacking groups linked to cyberattacks across Europe.

In light of these developments, it’s essential for organizations to take a proactive approach to cybersecurity. This includes regularly testing their defenses against potential threats and ensuring that security software is up-to-date. By doing so, they can reduce the risk of falling victim to ransomware attacks and other forms of cybercrime. As one State Department spokesperson noted, “By targeting not just ransomware operators but the service providers and tool suppliers who make their attacks possible, the United States and its partners are dismantling the broader networks that sustain cybercriminal activity worldwide.”


Source: Bleeping Computer — 2026-07-14