# First VPN dismantled in ransomware actor crackdown

Published: 2026-05-21 · Severity: routine
Canonical: https://vorant.io/reports/75ec3903-7af0-5e66-abaf-a9f660e11664/first-vpn-dismantled-in-ransomware-actor-crackdown

> Law enforcement shut down First VPN, an infrastructure service used by thousands of ransomware actors and cybercriminals to conceal attacks and data theft.

First VPN was a criminal infrastructure service deeply embedded in the ransomware and cybercrime ecosystem for years, promoted on Russian-speaking underground forums as a trusted anonymity tool. The service enabled attackers to conduct ransomware deployments, large-scale fraud, data theft, and other serious offences while evading law enforcement by providing anonymous payments, hidden server infrastructure, and features designed specifically for criminal operations.

French and Dutch authorities, supported by Europol and Eurojust, dismantled the service in a coordinated action on 19-20 May. The operation arrested the service administrator in Ukraine, seized three primary domain names (1vpns.com, 1vpns.net, 1vpns.org), and took offline 33 servers supporting the infrastructure. Investigators obtained the complete user database and identified thousands of accounts linked to cybercrime activity.

Defenders should note that First VPN appeared in almost every major Europol-supported cybercrime investigation in recent years, making it a widespread indicator of compromise. The takedown generates significant defensive value: law enforcement has shared 83 intelligence packages and information on 506 identified users across international partners, and has advanced 21 Europol-supported investigations. Users of the service have been notified they have been identified, disrupting the service's value to criminal operators.

## Mentioned in this report

- Malware: First VPN

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/75ec3903-7af0-5e66-abaf-a9f660e11664/first-vpn-dismantled-in-ransomware-actor-crackdown.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
