Another Win
Virtual Private Networks are a common way to encrypt one’s location, either to protect data or gain access to otherwise geographically locked or censored content online. Naturally, they are used to for some nefarious purposes as well as legitimate ones. The US Department of Treasury, in conjunction with EU law enforcement agencies, has placed sanctions on one such – First VPN Service – for providing services to ransomware groups.
Dutch and French authorities, working with an FBI field office out of Boston, had already taken down 1VPNS’s infrastructure and website in May (reported here), seizing over 30 servers in 27 countries, and arresting the administrator of the service, as well as exposing thousands of users associated with ransomware, fraud, and other malicious activity worldwide. The service provider was a well known entity among threat actors, appearing in almost every major cybercrime investigation Eurpol supported in the last few years. It promised not to log user data and ignore law enforcement requests for user information, making it the perfect home for hiding malicious activity. Takedowns and domain seizure are typical for any disruption operation, but they do not necessarily stop the activity, especially on a global scale. These sanctions, therefore, are a way to keep the VPN provider from continuing their services.
The Treasury’s statement on the operation is a wordy treatise attempting to cover all the variables, but in essence comes down to the people responsible, either materially or financially, for supporting cybercrime activity in the US have been blocked from doing so and should be reported to the Office of Foreign Assets Control if engaged with. Violation of the sanctions, which include transactions, sheltering or any other provided assistance, could result in civil or criminal charges for individuals and financial institutions. Victims of 1VPNS’s actions have been notified, as well as users unrelated to any criminal activity (presumably so they can take their business elsewhere). Additionally, a Belarusian national has also been sanctioned by the Treasury for selling cryptors (also known as crypters), which are tools that help ransomware and other malware evade detection by security software.
This disruption is just the latest in a line of counter-operations against cybercriminals in the last couple years. Pursuing these types of cases can be difficult, since so many of the culprits use pseudonyms and, indeed, VPN’s to hide their tracks. European agencies have been investigating 1VPNS since 2021, in fact. And this isn’t the only case in which sanctions have been imposed on alleged threat actors. On Monday, the EU and UK jointly sanctioned dozens of Russian based individuals and entities accused of coordinating hacking groups linked to attacks across Europe. The intent is to target the service providers of cybercriminal activity as well as the actors themselves, breaking down the infrastructure of the networks that sustain them. No doubt someone else will fill the vacuum of 1VPNS, but this is still a notable win.












