# Historic VPN Takedown: How Authorities Dismantled Infrastructure Used by 25 Ransomware Groups


A coordinated international law enforcement operation has successfully shut down First VPN, a criminal-focused virtual private network service that functioned as critical infrastructure for some of the world's most prolific ransomware groups. The operation, led by France and the Netherlands and involving authorities from 15 additional countries, represents a significant milestone in disrupting the tools and services that enable large-scale ransomware campaigns, data theft, and fraud.


The takedown, executed on May 19-20, 2026, resulted in the confiscation of 33 servers and seizure of infrastructure supporting global cybercriminal operations. For the first time, law enforcement has successfully dismantled a VPN service specifically designed to facilitate cybercriminal activity—a crucial piece of the infrastructure that ransomware groups have relied upon to obscure their origins and evade detection.


## The Operation: Scope and Execution


The investigation into First VPN began in December 2021 as a joint effort between France and the Netherlands. What started as a bilateral inquiry expanded into one of the largest coordinated law enforcement actions against cybercriminal infrastructure, involving support from Luxembourg, Romania, Switzerland, Ukraine, the U.K., Canada, Germany, the U.S., Spain, Sweden, Denmark, Estonia, Latvia, Lithuania, Poland, and Portugal.


Key actions taken during the operation:


  • Interviewed the service's administrator
  • Conducted a house search in Ukraine
  • Seized 33 servers distributed across multiple countries
  • Dismantled related onion domains operating on the Tor network
  • Confiscated three primary domains (1vpns.com, 1vpns.net, 1vpns.org)

  • According to Europol and coordinated statements from the U.S. Federal Bureau of Investigation (FBI), the operation targeted a service that had actively operated since approximately 2014, making it one of the longest-running criminal VPN platforms.


    ## What Was First VPN? Design for Criminals


    First VPN was not a conventional commercial VPN service repurposed for criminal use. Rather, it was explicitly engineered from inception as criminal infrastructure, marketed exclusively on Russian-speaking cybercrime forums such as Exploit[.]in and XSS[.]is.


    The service's core marketing promises included:


  • Zero-logging claims: Marketing materials promised that no logs could connect a user's IP address to their activity during a specific time period
  • Jurisdictional immunity: Claims that the service would not cooperate with any judicial authority or operate under any country's laws
  • Anonymity-first design: Built specifically to enable users to hide their identities while conducting illegal activities
  • Payment obfuscation: Accepted cryptocurrency and alternative payment methods (Bitcoin, Perfect Money, Webmoney, EgoPay, InterKass) that further obscured user identity

  • The service maintained a façade of legitimacy by including prohibitions against illegal activity in its terms of service and FAQ—yet deliberately marketed itself to criminal actors on forums where such prohibitions were meaningless.


    ## Technical Infrastructure and Capabilities


    First VPN operated a globally distributed network of 32 exit nodes spanning 27 countries, providing redundancy and geographic diversity that made it particularly attractive to threat actors conducting international operations.


    Geographic distribution of exit nodes included:


    | Region | Countries |

    |--------|-----------|

    | Europe | Austria, Belgium, Cyprus, Finland, France, Germany, Italy, Latvia, Luxembourg, Moldova, Netherlands, Poland, Romania, Russia, Serbia, Spain, Sweden, Switzerland, Turkey, Ukraine, U.K. |

    | Asia-Pacific | Australia, Hong Kong, Singapore |

    | North America | Canada, United States |

    | Central America | Panama |


    Three exit nodes were located within the United States alone (2.223.66.103, 5.181.234.59, 92.38.148.58), creating potential liability for U.S.-based criminal actors and enabling law enforcement visibility.


    Technical protocols and encryption offered:


  • OpenConnect
  • WireGuard
  • Outline
  • VLESS with TCP Reality (specifically designed to disguise VPN traffic as HTTPS traffic)
  • OpenVPN with Elliptic Curve Cryptography (ECC)
  • L2TP/IPSec
  • PPtP

  • The inclusion of VLESS and Reality protocols is particularly significant. These emerging protocols allow VPN traffic to be masked as standard HTTPS connections using common web ports—a capability specifically valuable for threat actors attempting to avoid detection on monitored networks.


    The service provided technical support through a self-hosted Jabber server and Telegram encrypted messaging, creating multiple channels for customer support while maintaining operational security.


    ## Pricing and Accessibility


    First VPN employed a tiered subscription model designed to accommodate both short-term operations and longer-term infrastructure. Subscription pricing ranged from $2 for a single day to $483 for a full year, with intermediate options supporting weekly or monthly engagements.


    This accessibility model democratized ransomware operations—even small criminal groups or individual actors could afford short-term VPN access for reconnaissance activities, while established ransomware-as-a-service (RaaS) platforms could maintain persistent infrastructure with annual subscriptions.


    ## Criminal Use: 25 Ransomware Groups and Beyond


    At minimum, 25 distinct ransomware groups leveraged First VPN infrastructure to conduct network reconnaissance, execute intrusions, perform data theft, and launch denial-of-service attacks. The FBI specifically identified Avaddon Ransomware as a confirmed user, but the actual number of threat actors utilizing the service likely exceeded documented cases.


    The service enabled the full lifecycle of a modern ransomware attack:

  • Reconnaissance: Identifying vulnerabilities and attack surfaces
  • Initial access: Conducting intrusions while obscuring origin
  • Lateral movement: Moving through compromised networks with anonymity
  • Data exfiltration: Stealing sensitive information without exposure
  • Extortion: Negotiating ransom demands while remaining unidentified

  • ## Broader Implications for Cybercriminal Infrastructure


    The successful dismantling of First VPN demonstrates that even mature, distributed criminal infrastructure can be disrupted through sustained international cooperation. However, the operation also reveals structural realities about the cybercriminal ecosystem that law enforcement must contend with:


    Replacement velocity: Threat actors have demonstrated rapid ability to migrate to alternative services. Multiple criminal VPN providers operate on similar models, and First VPN's shutdown will likely accelerate migration to competitors rather than eliminate demand.


    Jurisdictional complexity: The involvement of 17 countries highlights the challenge of coordinating across disparate legal systems, each with different authorities and investigative protocols. Ukraine's participation—where the administrator was located—was particularly crucial.


    Infrastructure resilience: First VPN's distributed exit nodes across 27 countries created multiple layers of investigation and seizure complexity. This geographic distribution will become an increasingly standard design principle for criminal services seeking to evade takedown.


    ## HackWire Analysis


    The dismantling of First VPN represents a watershed moment in law enforcement's ability to disrupt ransomware operations, yet it also underscores a fundamental asymmetry in the cybersecurity landscape.


    For years, defenders have watched as ransomware groups leveraged purpose-built infrastructure—VPN services, bulletproof hosting, encrypted communications platforms, payment processors—that required little technical sophistication but enormous operational coordination to take down. First VPN's longevity (active since 2014) demonstrates that law enforcement investigation moves on geological timescales compared to the operational tempo of modern cybercrime.


    What makes this takedown significant isn't just that authorities removed 33 servers; it's that they *coordinated across 17 countries to do so*. This represents a new maturity in international law enforcement collaboration against cybercriminal infrastructure. The involvement of Eurojust (the European Union's judicial cooperation body) and coordinated statements from the FBI show that critical infrastructure targeting is now treated as a priority worthy of sustained diplomatic and investigative effort.


    However, defenders should remain realistic about impact. First VPN's $2-per-day subscription model meant that the service was tactically replaceable for threat actors. Ransomware groups will migrate to competing services (LimeVPN, SafeVPN, and others operate on similar models). The real value of this operation lies not in the immediate disruption to active campaigns, but in establishing precedent: criminal VPN infrastructure can be identified, traced to operators, and dismantled through patient investigation.


    Organizations should use this window of disruption to reassess their ransomware defenses. Any organization that detected traffic to First VPN's known exit nodes should assume reconnaissance or lateral movement may have occurred. Threat intelligence teams should cross-reference First VPN's exit nodes against network logs to identify potential compromise.


    The lesson for defenders: ransomware infrastructure, while sophisticated, creates investigative breadcrumbs. Distributed exit nodes, cryptocurrency payment trails, and technical support channels all provide surfaces for law enforcement to attack. Organizations that maintain comprehensive network logs, DNS records, and egress traffic inspection have better evidence to both detect intrusions and support law enforcement investigations.


    — HackWire Editorial


    ## Recommendations for Organizations


    Immediate actions:

  • Review network logs for connections to any of First VPN's known exit node IP addresses
  • Query your DNS logs for queries to 1vpns.com, 1vpns.net, 1vpns.org, or associated onion domains
  • Check endpoint security logs for VPN client installations or configuration changes
  • Correlate any detected First VPN usage with intrusion detection alerts

  • Strategic improvements:

  • Implement egress filtering to restrict VPN traffic except through approved corporate services
  • Deploy advanced network monitoring capable of identifying VPN traffic patterns even when disguised as HTTPS
  • Maintain detailed network logs (minimum 90 days, preferably 1+ year) to support law enforcement investigations
  • Establish incident response procedures specifically for detecting reconnaissance activity

  • Intelligence sharing:

  • Report any First VPN infrastructure detected in your networks to law enforcement
  • Share indicators of compromise with industry Information Sharing and Analysis Centers (ISACs)
  • Cross-reference First VPN exit nodes against any ransomware incidents in your organization

  • ## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)