Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses Pierluigi Paganini
    U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to American businesses and critical infrastructure. “Today, the Office of Foreign Assets Control (OFAC) is designating two individuals a
     

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

14 de Julho de 2026, 16:47

U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure.

The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to American businesses and critical infrastructure.

“Today, the Office of Foreign Assets Control (OFAC) is designating two individuals and one entity enabling ransomware actors’ and other cybercriminals’ malign activities, notably ransomware attacks against Americans.  These include First VPN Service (1VPNS), a virtual private network (VPN) provider selling services to ransomware groups, and its administrator, Dmytro Rashevskyi (Rashevskyi).  OFAC is also designating Yegeniy Vladimirovich Silayev (Silayev), an individual who sells “cryptors,” which are tools used to disguise ransomware and other malware as safe programs to prevent security systems from detecting or deactivating them.” reads the announcement published by the U.S. Treasury’s Office of Foreign Assets Control.”Ransomware groups utilizing these individuals’ services have caused billions of dollars in losses to U.S. businesses and critical infrastructure providers.”

The action was coordinated with the UK’s Foreign, Commonwealth & Development Office, which sanctioned additional cybercriminals the same day.

“1VPNS is a VPN provider whose principal clients include ransomware actors and other cybercriminals. VPNs, which allow users to encrypt their internet traffic and hide their computers’ true location, have legitimate uses for privacy and security, but can support malicious activity if misused.” continues the announcement. “Numerous ransomware groups have purchased infrastructure from 1VPNS, which they have leveraged in attacks on U.S. companies and institutions—including to hide the origins of their attacks, deploy malware, and manage exfiltrated data.”

Victims included hospitals, financial services firms, and municipal governments. Since 2014, the service advertised openly on cybercriminal forums that it kept no logs and refused to cooperate with law enforcement — the kind of guarantee that attracts exactly the clientele you’d expect.

“Rashevskyi has used false identities, including “Maksim Sorin” and “Roman Chabanenko,” to buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers.” states the OFAC.

The sanctions follow a May 2026 takedown of 1VPNS’s website and servers by European law enforcement, with support from the FBI’s Boston Field Office, as part of Operation Saffron led by French and Dutch authorities. The investigation had started in December 2021, with law enforcement infiltrating 1VPNS infrastructure and collecting its user database before dismantling it — 33 servers across 27 countries, and thousands of users exposed.

The second designation targets Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors: tools that disguise malware as harmless files to get past security software.

“Unlike legitimate encryption tools, which are designed to protect data and the privacy of the people that own it, cryptors are built specifically to make malware stealthier and more effective by disguising it as harmless files.” continues the announcement.

Silayev supplied these obfuscation services to ransomware operators targeting U.S. and allied organizations. Treasury estimates the combined operations involving 1VPNS and Silayev’s cryptors have caused billions in losses.

The State Department framed the action explicitly as targeting the supply chain behind ransomware, not just the operators themselves.

“These actors supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers.” reads the press release published by the U.S. State Department.

“This action reflects the United States’ commitment to working with allies and partners to disrupt the global cybercrime ecosystem. Today’s designations are coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, and follow a May 2026 European law enforcement takedown of 1VPNS’s infrastructure, supported by the FBI.”

The designations freeze any U.S.-jurisdiction assets of the named individuals and entities, and bar U.S. persons and businesses from any transactions involving them. The action sits under Trump’s Executive Order 14390 of March 6, 2026, directing agencies to harden U.S. financial and digital systems against foreign cybercrime.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, VPN Provider)

  • ✇Firewall Daily – The Cyber Express
  • US Treasury Sanctions VPN Provider Linked to Ransomware Samiksha Jain
    The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure. The act
     

US Treasury Sanctions VPN Provider Linked to Ransomware

Ransomware sanctions

The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure.

The action, coordinated with the United Kingdom, is part of broader efforts to disrupt the cybercrime ecosystem supporting ransomware operations. The Treasury said the targeted services have contributed to attacks that resulted in billions of dollars in losses across the United States.

OFAC Targets 1VPNS and Its Administrator

At the center of the ransomware sanctions is 1VPNS, a VPN provider that OFAC described as a key infrastructure supplier for ransomware operators and other cybercriminals. The Treasury also designated Dmytro Rashevskyi, the administrator of 1VPNS, for allegedly providing technological support to cyber-enabled criminal activity.

According to OFAC, VPN services have legitimate privacy and security uses but can also be misused to conceal the origin of cyberattacks, deploy malware, and manage stolen data.

The Treasury said ransomware groups used 1VPNS infrastructure during attacks against U.S. companies and institutions, including financial services firms, hospitals, municipal governments, and other organizations.

Authorities also alleged that since 2014, 1VPNS advertised its services on cybercriminal forums while claiming it did not retain user logs or cooperate with law enforcement investigations involving illegal activities conducted through its servers.

OFAC further stated that Rashevskyi used false identities, including "Maksim Sorin" and "Roman Chabanenko," to purchase infrastructure from providers that may have otherwise declined business because of abuse complaints linked to 1VPNS servers.

Malware Provider Also Added to Ransomware Sanctions List

The Treasury also imposed sanctions on Yegeniy Vladimirovich Silayev, a Belarusian national accused of supplying cryptors to ransomware operators.

According to OFAC, cryptors are designed to disguise malware as legitimate files, making malicious software more difficult for security products to detect or remove. Unlike traditional encryption technologies that protect user data, cryptors are intended to improve the effectiveness and stealth of malware used in cyberattacks.

The Treasury alleged that Silayev provided encryption and obfuscation services to ransomware groups targeting organizations in the United States and allied countries.

International Action Against Cybercrime Infrastructure

The sanctions were announced in coordination with the United Kingdom's Foreign, Commonwealth & Development Office, which also imposed sanctions against cybercriminals and individuals accused of enabling cybercrime.

The announcement follows a May 2026 operation by European law enforcement authorities that dismantled 1VPNS's website and supporting infrastructure with assistance from the FBI's Boston Field Office.

The FBI has also released a cybersecurity advisory detailing the tactics, techniques, and procedures associated with 1VPNS to help organizations identify and defend against ransomware attacks.

Treasury Cites Executive Orders

The designations were issued under OFAC authorities pursuant to Executive Order 13694, as amended, along with President Donald Trump's Executive Order 14390, signed in March 2026.

According to the Treasury, the order directs U.S. government agencies to strengthen protections against foreign actors involved in cybercrime, cyber-enabled fraud, extortion, and related criminal schemes targeting Americans.

What the Sanctions Mean

Under the sanctions, all property and interests belonging to the designated individuals and entity that are within the United States or controlled by U.S. persons are blocked and must be reported to OFAC.

The restrictions also extend to entities owned 50% or more by designated persons. Unless authorized by OFAC, U.S. persons are generally prohibited from engaging in transactions involving blocked individuals or organizations.

The Treasury said violations of U.S. sanctions may result in civil or criminal penalties for both U.S. and foreign persons. It also warned that financial institutions and other organizations could face sanctions exposure if they engage in prohibited transactions involving designated entities.

The latest ransomware sanctions reflect continuing efforts by U.S. authorities and international partners to target the infrastructure and services that enable ransomware operators rather than focusing solely on the attackers themselves.

❌
❌