The United States Treasury Department has taken direct aim at the infrastructure behind ransomware attacks. On Monday, the Office of Foreign Assets Control announced sanctions against 1VPNS, a virtual private network provider, and its administrator, in connection with ransomware attacks against U.S. organizations. The 1VPNS ransomware sanctions mark a shift toward punishing the suppliers behind attacks, not just the criminals who carry them out.
The action designates First VPN Service, known as 1VPNS, along with Dmytro Rashevskyi, the man who ran it. A third target, Belarusian national Yegeniy Vladimirovich Silayev, was also sanctioned for selling cryptors, which are tools built to help malware slip past security software undetected.
What Made 1VPNS Different From a Regular VPN
Most VPN providers exist to protect ordinary users browsing the internet. 1VPNS operated on a different premise. Since surfacing in 2014, the service marketed itself directly to cybercriminal forums with a simple pitch: no activity logs, no user identification, and no cooperation with police under any circumstances.
That pitch worked. Ransomware groups used 1VPNS to mask their locations and identities while carrying out attacks against hospitals, financial firms, municipal governments, and businesses across the United States. Because the service refused to hand over records, investigators struggled for years to trace attacks back to their source.
Rashevskyi allegedly went further than simply running the service. He used false identities, including the names “Maksim Sorin” and “Roman Chabanenko,” to buy server infrastructure from providers who would have otherwise turned him away over abuse complaints. This let 1VPNS keep expanding even as legitimate hosting companies grew wary of its user base.
How Authorities Took the Network Down
The 1VPNS ransomware sanctions did not come out of nowhere. They follow a law enforcement operation that dismantled the provider in May, led by French and Dutch authorities under the name Operation Saffron. The FBI’s Boston Field Office and Europol supported the takedown.
That investigation had been running since December 2021. Investigators quietly infiltrated the VPN’s infrastructure and pulled its user database before making any arrests, which gave them a detailed map of who relied on the service and why. When the operation moved into its final phase, authorities seized 33 servers spread across 27 countries and arrested the administrator.
Europol later noted that 1VPNS’s name had come up in nearly every major cybercrime case the agency supported, which shows how central the provider had become to ransomware operations worldwide. Thousands of users tied to ransomware, fraud, and other criminal activity were exposed as a result.
The Second Target: A Supplier of Detection-Evasion Tools
Alongside the VPN provider, Treasury sanctioned Silayev for selling cryptors. These tools scramble or repackage malicious code so antivirus software and endpoint detection systems fail to recognize it as a threat. Ransomware groups depend on cryptors to keep their payloads undetected long enough to spread through a network and encrypt files.
Officials estimate that ransomware campaigns using 1VPNS’s infrastructure and Silayev’s cryptors caused billions of dollars in losses to American businesses and critical infrastructure providers. That figure covers ransom payments, but it also includes downtime, recovery costs, and the broader disruption these attacks caused across multiple industries.
State Department spokesperson Thomas Pigott said the sanctions were meant to reach beyond the ransomware operators themselves. He pointed to the suppliers and service providers who make attacks possible in the first place, arguing that cutting off their access to the U.S. financial system disrupts the wider criminal ecosystem rather than just individual attackers.
Why This Matters Beyond One VPN Provider
The sanctions block all property these individuals and the entity hold within U.S. jurisdiction, and they bar American persons and businesses from doing any transactions with them. OFAC coordinated the action with the United Kingdom’s Foreign, Commonwealth & Development Office, adding an international dimension to the enforcement effort.
For everyday VPN users, this case draws a useful line. A legitimate no-logs VPN protects your privacy without inviting criminal activity onto its network. 1VPNS, by contrast, was purpose-built as infrastructure for ransomware groups, and its business model depended on shielding people who were actively harming others. The two should not be confused, even though both use similar marketing language around privacy and anonymity.
This case also signals a shift in how regulators approach ransomware. Rather than only chasing the attackers who deploy the malware, agencies are now targeting the vendors who supply the tools and cover that make those attacks possible. Because ransomware operations rely on a chain of specialized services, from VPNs to cryptors to negotiation support, disrupting any link in that chain can slow down the entire operation.
Final Thoughts
The 1VPNS ransomware sanctions mark one of the clearer examples yet of regulators going after the infrastructure layer of cybercrime instead of just the criminals using it. By targeting a VPN provider built specifically for ransomware groups and a cryptor seller who helped malware avoid detection, Treasury and its international partners are attempting to choke off the support systems that keep ransomware profitable. Whether this approach meaningfully reduces attack volume remains to be seen, but it adds real pressure to a criminal economy that has depended on tools like these for years.