2026 hasn’t been a good year for First VPN, a VPN service that’s been used widely by ransomware actors and other cybercriminals for more than a decade.

On Monday, the Treasury Department announced sanctions on the VPN provider, as well as its administrator (Dmytro Rashevskyi).  The sanctions come after Europol in May announced an international operation led by France and the Netherlands, which targeted First VPN’s infrastructure and dismantled 33 servers linked to the criminal service. That month, the FBI also publicly outlined TTPs linked to threat actors using the service in an effort to help organizations detect ransomware attacks. 

First VPN has been active for more than a decade and is specifically designed for ransomware operators, fraud groups, and other cybercriminals trying to hide malicious activity from law enforcement. It was used in attacks linked back to at least 25 types of ransomware, such as the Avaddon ransomware. Victims of these ransomware groups have included U.S. businesses, financial services companies, hospitals, and municipal governments.

“FirstVPN has advertised on cybercriminal forums like Exploit and XSS since 2014, promising no logs and no cooperation with law enforcement,” according to Ari Redbord, global head of policy and government affairs at TRM Labs, in a recent LinkedIn post. “Ransomware groups paid for that promise and used it to hide the origin of attacks, deploy malware, and manage stolen data.”

The Treasury Department’s announcement shed some light on the activities of First VPN administrator Rashevskyi, who it said used false identities (like “Maksim Sorin” and “Roman Chabanenko”) to acquire infrastructure from companies.  Rashevskyi used these fake aliases because he left behind a trail of abuse complaints from internet service providers about illegal activity on First VPN’s servers.

The U.S. also sanctioned Vladimirovich Silayev, a Belarusian national who government officials said sells “cryptors.” These are tools used to disguise ransomware so they can pass as safe programs, preventing security systems from sniffing them out.

“Unlike legitimate encryption tools, which are designed to protect data and the privacy of the people that own it, cryptors are built specifically to make malware stealthier and more effective by disguising it as harmless files,” according to the Treasury Department. 

The sanctions block all U.S. assets belonging to First VPN, Rashevskyi, and Silayev, and prohibits Americans from doing business with them. It becomes extremely difficult for sanctioned entities to participate in the legitimate global financial system, even if they're located outside the U.S. While this doesn’t mean the end for First VPN, the sanctions coupled with the disruption efforts earlier this year makes it much harder for the service to operate - particularly because in May, authorities also arrested an unnamed administrator linked to the service. 

Beyond First VPN, several other sanctions were announced this week by other countries. The UK on Monday announced sanctions against 24 individuals and entities involved in cybercriminal proxy networks linked to the Russian Intelligence Services (RIS).

“These sanctions strike at the core of the cybercriminal networks propping up the Russian state’s aggression, and the UK and EU are sending a clear message that Russia cannot hide behind its use of these proxy groups,” according to UK Foreign Secretary Yvette Cooper.