Threats · 62 days ago
Ransomware crews depend on rented concealment and hosting as much as they depend on their own operators. Treasury is now sanctioning that support layer, which can disrupt how multiple gangs hide their traffic, disguise malware, and buy infrastructure at once.
The designations hit First VPN Service (1VPNS), its Ukrainian administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev, who sold malware "cryptors." Treasury linked the service to attacks on U.S. municipalities, hospitals, schools, and businesses, and said many ransomware groups used it to source internet infrastructure. The action follows the May takedown of First VPN by European law enforcement and the FBI.
For defenders, the shift is that ransomware risk now extends upstream into the providers that make campaigns easier to run and harder to attribute. That matters most for teams that track ransomware ecosystems, not just the groups named in an intrusion report.
4 sources covering this story
Treasury sanctions First VPN Service, others for abetting ransomware gangs
Treasury sanctioned First VPN (1VPNS) and its administrator for selling anonymizing infrastructure to ransomware operators targeting U.S.
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
sanctions First VPN and two operators over ransomware support as the U.K.
US sanctions VPN, malware providers for enabling ransomware attacks
Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S.
The Record from Recorded Future
VPN service favored by ransomware groups is sanctioned by US
Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups.
Part of the PlainSec briefing for 2026-07-15