U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
IncidentU.S. Treasury DepartmentGRU Unit 29155Our summary
The U.S. Treasury Department has imposed sanctions on FirstVPN (1VPNS) and two individuals for enabling ransomware attacks against American businesses and critical infrastructure. The service, which operated since 2014, was dismantled in May 2026 after being linked to cybercriminals who used it to mask the origins of their attacks. Alongside FirstVPN’s administrator, Dmytro Rashevskyi, and cryptor seller Yegor Silayev, the move highlights growing efforts to hold bad actors accountable for facilitating large-scale cybercrime. These actions are part of broader international measures targeting Russian state-backed cyber operations and ransomware enablers.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.