First VPN dismantled in ransomware actor crackdown
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Law enforcement shut down First VPN, an infrastructure service used by thousands of ransomware actors and cybercriminals to conceal attacks and data theft.
First VPN was a criminal infrastructure service deeply embedded in the ransomware and cybercrime ecosystem for years, promoted on Russian-speaking underground forums as a trusted anonymity tool. The service enabled attackers to conduct ransomware deployments, large-scale fraud, data theft, and other serious offences while evading law enforcement by providing anonymous payments, hidden server infrastructure, and features designed specifically for criminal operations.
French and Dutch authorities, supported by Europol and Eurojust, dismantled the service in a coordinated action on 19-20 May. The operation arrested the service administrator in Ukraine, seized three primary domain names (1vpns.com, 1vpns.net, 1vpns.org), and took offline 33 servers supporting the infrastructure. Investigators obtained the complete user database and identified thousands of accounts linked to cybercrime activity.
Defenders should note that First VPN appeared in almost every major Europol-supported cybercrime investigation in recent years, making it a widespread indicator of compromise. The takedown generates significant defensive value: law enforcement has shared 83 intelligence packages and information on 506 identified users across international partners, and has advanced 21 Europol-supported investigations. Users of the service have been notified they have been identified, disrupting the service's value to criminal operators.
Mentioned in this report
Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,768 reports from 152 sources, 472 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs