VPN service favored by ransomware groups is sanctioned by US

The U.S. government on Monday sanctioned a VPN provider and its Ukrainian administrator for abetting ransomware gangs behind attacks on American municipalities, hospitals, schools and businesses.
First VPN Service (1VPNS) provided ransomware groups with tools to “hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers,” according to a Treasury Department press release.
The administrator, Dmytro Rashevskyi, used fake identities “to buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers,” the Treasury said.
A second man, Belarusian national Yegeniy Vladimirovich Silayev, was designated for allegedly selling “cryptors,” or methods used to make malware harder to detect and more effective by cloaking it as harmless files.
Silayev is not affiliated with First VPN.
Under the sanctions, no one in the U.S. can complete transactions with the designees. Sanctions are also considered a reputational blow that often leads to a downturn in business revenues.
In May, European law enforcement agencies and the FBI took down First VPN, saying the service has historically been used by cybercriminals to hide fraud, ransomware attacks and other illegal activity. The service has long been promoted on Russian cybercrime forums.
Rashevskyi marketed First VPN as low-risk because “it does not keep logs of users’ identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers,” according to the Treasury.
VPNs, which encrypt internet traffic, are used by many people for privacy and security reasons, but also can be exploited for malicious activity.
By targeting not just ransomware operators but the service providers and tool suppliers who make their attacks possible, the U.S. and its partners are disrupting operations for a large number of gangs at once, according to the Treasury.
The press release did not specify which ransomware groups used First VPN, but said many bought internet infrastructure from the service.
First VPN has operated since 2014 and is also marketed on dark web forums for its ability to support botnets and scammers of all stripes, all while promising customers anonymity.
References in this story
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans home.treasury.gov WASHINGTON — Today, the Office of Foreign Assets Control (OFAC) is designating two individuals and one entity enabling ransomware actors’ and other cybercriminals’ malign activities, notably ransomware attacks against…
- Europe dismantles VPN service used by cybercriminals to hide ransomware attacks therecord.media The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way for criminals to evade law enforcement.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- Suzanne Smalley (@suzannesmalley.bsky.social) bsky.app Reporter covering digital privacy and cybersecurity policy for The Record. Mom. Pub trivia queen. Crossword enthusiast. Literary fiction connoisseur. Idiosyncratic. Signal: Suzanne.236 Email…



