A criminal anonymization service called First VPN is now offline after an international law enforcement operation dismantled it on May 19 and 20, 2026. Ransomware gangs, fraudsters, and data thieves had used it for years to hide their activity. Codenamed Operation Saffron, the action took down 33 servers, seized three domains, and put the service’s administrator in handcuffs in Ukraine. Europol called First VPN one of the most widely used tools in the cybercrime underground — present in nearly every major investigation the agency has supported in recent years.
How First VPN Operated
First VPN was not a consumer privacy tool. Criminals built it, advertised it on Russian-language cybercrime forums, and marketed it on one core promise: it would never cooperate with law enforcement. The service offered no activity logs, anonymous payment options, and infrastructure designed to keep users invisible to investigators.
That pitch found a ready audience. Ransomware operators, fraud networks, and data thieves all relied on First VPN to hide their real locations and mask their attack infrastructure. VPNs work by encrypting traffic and replacing a user’s real IP address with one from the VPN’s own servers. That makes them valuable for privacy-conscious users. It also makes them useful for criminals running attacks across borders.
First VPN went after that criminal market deliberately. Posts on underground forums claimed the service stored nothing that could tie activity to a specific user. Investigators found a very different reality.
Operation Saffron: How the Takedown Unfolded
The investigation behind Operation Saffron began in late 2021. French authorities spotted First VPN on cybercrime forums in 2022. France and the Netherlands then formed a Joint Investigation Team through Eurojust in November 2023, and the operation grew from there.
Investigators did not simply wait and then shut the service down. They got inside First VPN’s infrastructure while it was still live. Teams executed multiple European Investigation Orders and Mutual Legal Assistance requests to pull traffic data and access backend systems before the takedown date.
That covert access changed everything. Investigators collected live data from users who thought their activity was fully protected. Every criminal who connected through First VPN during that window gave authorities a record of what they were doing — without knowing it.
On May 19 and 20, authorities moved. They arrested the administrator, searched the suspect’s home in Ukraine, pulled down 33 servers, and shut off the domains 1vpns.com, 1vpns.net, 1vpns.org, and several associated onion addresses on the Tor network.
What Investigators Found
The intelligence from Operation Saffron was significant. Authorities put together 83 intelligence packages covering 506 identified users and sent them to partner countries. The material also covered ransomware investigations, including cases tied to the Phobos ransomware-as-a-service outfit.
Phobos runs on a franchise model. Its operators license attack tools to affiliates and collect a cut of every ransom payment. Finding Phobos connections in the First VPN data shows how deeply the service sat inside multiple criminal ecosystems at once.
The operation has already pushed 21 active cybercrime investigations forward. Europol also contacted identified users directly, telling them the service was gone and that investigators had identified them. That move serves a purpose beyond notification. Letting suspects know authorities have their data can disrupt live operations and force criminal networks to react.
Edvardas Šileris, Head of Europol’s European Cybercrime Centre, stated: “For years, cybercriminals saw this VPN service as a gateway to anonymity. They believed it would keep them beyond the reach of law enforcement. This operation proves them wrong.”
A Shift in Law Enforcement Strategy
Operation Saffron fits a deliberate shift in how agencies fight cybercrime. Chasing individual attackers has limits — criminal networks replace people fast. So investigators are going after the shared infrastructure that makes large-scale operations possible in the first place. Bulletproof hosting, cryptocurrency mixers, and criminal anonymization services like First VPN sit underneath many different groups at once. One takedown can expose dozens of operations.
First VPN was a high-value target for exactly that reason. Europol noted it appeared in almost every major investigation the agency ran in recent years. Shutting it down does not end ransomware. But it removes a layer of infrastructure that many groups depended on and hands investigators a user database they can work through across multiple jurisdictions.
Eighteen countries took part in the operation, including France, the Netherlands, Germany, the United Kingdom, the United States, and Ukraine. Eurojust ran 16 coordination meetings to keep legal strategies aligned across all of them.
What This Means for VPN Users
Legitimate VPN users have nothing to fear from Operation Saffron. The operation targeted a service that criminals built specifically to evade law enforcement — not a standard consumer privacy product.
Reputable VPN providers work within legal frameworks, respond to valid court orders, and publish clear policies on data retention. First VPN did the opposite. It promised total invisibility and zero accountability. That promise is exactly what brought investigators to its door.
The broader point is worth stating clearly. Anonymization tools do not make criminal activity invisible. Investigators can infiltrate services before acting. Data that criminals trusted to stay private can become prosecution evidence. First VPN’s users learned that the hard way.
Final Thoughts
The First VPN takedown stands out as one of the more consequential cybercrime infrastructure operations in recent years. Investigators spent more than four years building the case, coordinated across 18 countries, and chose to infiltrate the service before pulling it offline. The intelligence they collected will drive active prosecutions for months to come. Operation Saffron delivers a clear message to anyone still banking on the cybercrime underground’s promises of guaranteed anonymity: those promises do not hold.