# U.S. Sanctions First VPN Service Over Ransomware Support as Global Cyber Enforcement Escalates


The United States has taken unprecedented action against a commercial VPN provider, marking the first time OFAC (Office of Foreign Assets Control) has sanctioned a VPN service for facilitating ransomware and cybercriminal activity. The crackdown reflects a dramatic shift in how governments are targeting the infrastructure that enables some of the world's most damaging cyberattacks.


## The Threat


On July 14, 2026, the U.S. Treasury Department announced sanctions against First VPN Service (1VPNS), a Ukrainian-administered VPN provider, along with two individuals: Dmytro Rashevskyi, the 45-year-old Ukrainian administrator of the service, and Yegeniy Vladimirovich Silayev, a Belarusian national who sold malware cryptors designed to evade detection.


According to OFAC, First VPN provided critical infrastructure for ransomware operations targeting American institutions:


  • U.S. businesses and critical infrastructure providers suffering billions in cumulative losses
  • Financial services companies exposed to ransomware schemes
  • Hospitals and healthcare networks disrupted by attacks
  • Municipal governments forced to pay extortionate ransoms or face service outages

  • The sanctions underscore a sobering reality: ransomware actors do not operate in isolation. They rely on a supply chain of support services—VPNs to mask their origin, cryptors to weaponize malware, hosting providers willing to turn a blind eye, and money laundering channels to convert stolen data into profit.


    ## Background and Context


    First VPN's Rise and Fall


    First VPN Service operated since 2014, explicitly marketing itself as a privacy tool for users seeking anonymity. The service's pitch was straightforward and seductive to criminals: no logs, no user identification, no cooperation with law enforcement. This advertising, ironically, became central evidence in the government's case.


    The service was dismantled in May 2026 following a coordinated law enforcement operation involving European and North American authorities. By that point, the damage was considerable. Multiple ransomware groups—including some of the most prolific actors in the criminal ecosystem—had made First VPN a cornerstone of their operational security strategy.


    Rashevskyi's Infrastructure Obfuscation


    To avoid suspicion from infrastructure providers, Rashevskyi employed a sophisticated identity fraud scheme:


    | Identity Used | Purpose |

    |---|---|

    | Maksim Sorin | Purchasing hosting and infrastructure |

    | Roman Chabanenko | Registering accounts with providers |

    | Dmytro Rashevskyi | Original administrator identity |


    This compartmentalization allowed him to maintain plausible deniability while acquiring the servers, bandwidth, and hosting resources that powered the VPN. Internet service providers repeatedly complained about abuse originating from 1VPNS infrastructure—but by the time complaints accumulated, Rashevskyi had already cycled through identities and providers.


    Yegeniy Silayev's Cryptor Supply Chain


    Silayev's role was equally critical but more specialized. Malware cryptors are tools that obfuscate malicious code, making it appear legitimate to antivirus engines and security tools. His cryptors enabled ransomware operators to:


  • Deploy payloads without triggering endpoint protection alarms
  • Distribute malware to thousands of devices before detection
  • Maximize the effectiveness of initial access brokers
  • Support both ransomware and data theft operations

  • ## Technical Details


    ### How First VPN Enabled Ransomware Operations


    The VPN infrastructure allowed ransomware operators to accomplish several critical tasks:


    1. Attack Origination Masking — Attackers using First VPN appeared to originate from legitimate geographic locations or spoofed IP addresses, complicating law enforcement attribution.


    2. Command and Control (C2) Communication — Ransomware beacons and exfiltration traffic routed through First VPN servers avoided direct traceability to attacker infrastructure.


    3. Data Staging and Management — Exfiltrated data from breaches was aggregated and held on servers leased through First VPN, obscuring ownership and jurisdiction.


    4. Negotiation Infrastructure — Some ransomware groups used First VPN's infrastructure to host victim communication portals, negotiation pages, and payment interfaces.


    ### The Cryptor Supply Chain


    Silayev's cryptors typically worked by:


  • Polymorphic Encoding — Changing the malware's code signature with each deployment to evade signature-based detection.
  • Process Injection — Embedding malicious payloads into legitimate system processes to blend in with normal activity.
  • Anti-Analysis Techniques — Detecting and disabling debuggers, sandbox environments, and virtual machines used by security researchers.

  • ## Implications for Organizations


    ### Direct Victims


    Organizations targeted by ransomware groups using First VPN suffered unprecedented losses:


  • Ransomware Recovery Costs — Estimated at billions of dollars across downtime, remediation, and settlements
  • Data Breach Exposure — Intellectual property, trade secrets, and customer information stolen at scale
  • Operational Disruption — Hospitals unable to access patient records; municipalities unable to process taxes or permits; financial services unable to execute transactions

  • ### Broader Ecosystem Impact


    This sanctions action signals that governments are moving beyond pursuing individual cybercriminals toward targeting the service providers and tool vendors that enable criminal activity at scale. This represents a significant escalation with implications for:


  • VPN Providers — Legitimate services must now demonstrate robust compliance and abuse investigation capabilities
  • Hosting and Infrastructure Companies — Increased regulatory scrutiny of customer verification and abuse reporting
  • Tool Vendors — Software developers face pressure to implement safeguards against weaponized use of their tools

  • ## Concurrent International Action


    The U.S. sanctions coincide with U.K. and E.U. sanctions against Russian cyber networks, targeting 24 individuals and entities behind destructive operations attributed to:


  • Russia's Main Intelligence Directorate (GRU) — Including senior leadership members Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko
  • GRU Unit 29155 — The cyber division that recruited hackers from Russian universities and worked with cybercriminals at scale
  • FSB Centre 16 — Attributed to disruptive sabotage operations against Poland's energy grid
  • Lumma Stealer Operators — A credential-stealing malware family used in espionage operations globally

  • This coordinated enforcement action demonstrates a unified approach to cybercriminal infrastructure, suggesting that the international community is finally organizing against the service providers and nation-state actors that enable the most damaging attacks.


    ## Recommendations for Organizations


    ### Immediate Actions


    1. Audit VPN and Remote Access Tools — Review all external access points and eliminate any reliance on services with known abuse histories

    2. Strengthen Endpoint Protection — Prioritize cryptor detection and implement behavioral analysis alongside signature-based antivirus

    3. Review Breach Notifications — Determine whether your organization was affected by First VPN-enabled attacks through law enforcement notifications or breach databases


    ### Strategic Measures


  • Implement Zero Trust Architecture — Eliminate implicit trust in network location; require continuous verification of all access
  • Enhance Threat Intelligence Sharing — Participate in industry ISACs to receive early warnings of infrastructure compromises
  • Review Incident Response Plans — Ensure ransomware-specific playbooks account for sophisticated attackers using service-provider infrastructure

  • ---


    ## HackWire Analysis


    This sanction marks an inflection point in how democracies combat ransomware: governments have realized that prosecuting individual cybercriminals is ineffective when the underlying infrastructure—VPNs, cryptors, hosting providers, money launderers—remains operational. By targeting First VPN Service directly, OFAC is attacking the *supply chain* rather than individual criminals. This is strategically sound but faces a hard problem: legitimate VPN services serve genuine privacy needs, and the line between privacy advocate and criminal enabler is contentious.


    What's particularly significant is the explicit acknowledgment that a commercial service knowingly facilitated ransomware. First VPN's "no logs, no law enforcement cooperation" policy wasn't a privacy feature—it was a service guarantee to criminals. The use of false identities by Rashevskyi, coupled with his awareness of abuse complaints, demonstrates intent. Expect this precedent to embolden enforcement actions against other privacy-focused services that ignore clear signals of criminal use.


    The concurrent UK/EU sanctions on Russian cyber infrastructure reveal a second emerging pattern: nation-state actors and cybercriminals are no longer operating in separate lanes. Russia's GRU is actively recruiting from the same cybercriminal talent pool and sharing infrastructure. This convergence means future ransomware attacks may carry dual-use objectives—financial gain *and* geopolitical disruption. Organizations should assume that a ransomware incident could be prelim to state-level espionage or sabotage.


    The cryptor component deserves emphasis: Silayev's tools were the technical enabler that made ransomware scalable. A cryptor doesn't just hide malware—it democratizes ransomware deployment, allowing lower-skilled attackers to weaponize sophisticated payloads. Sanctioning the cryptor vendor targets this multiplier effect.


    HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)