OFAC sanctions First VPN over ransomware infrastructure sales
OFAC is drawing a line around anonymity infrastructure: neutrality gets harder to claim after years of cybercrime-forum advertising.
TL;DR
CyberScoop reports that Treasury’s Office of Foreign Assets Control sanctioned First VPN Services, also known as 1VPNS, alleged administrator Dmytro Rashevskyi, and Belarus national Yegeniy Vladimirovich Silayev in coordination with the U.K. OFAC said 1VPNS sold anonymity infrastructure used by ransomware groups against U.S. businesses, financial services firms, hospitals and municipal governments. Silayev allegedly sold cryptors used to disguise ransomware and other malware. For incident-response teams, the practical point is counterparty risk: small infrastructure purchases can still create visible sanctions and attribution trails.
CyberScoop reports that Treasury’s Office of Foreign Assets Control sanctioned First VPN Services, also known as 1VPNS, and alleged administrator Dmytro Rashevskyi, alongside Belarus national Yegeniy Vladimirovich Silayev. The First VPN allegation is not that a virtual private network can be misused, which is true of plenty of legitimate infrastructure. OFAC’s claim is narrower and more damaging: 1VPNS allegedly advertised for more than a decade on cybercrime forums, touted its refusal to cooperate with law enforcement, and sold infrastructure used by ransomware groups to hide attack origins, deploy malware and manage stolen data.
The affected victims, according to OFAC as reported by CyberScoop, included U.S. businesses, financial services companies, hospitals and municipal governments. That makes this more than another name on a blocked-property list. For municipalities and healthcare entities already trying to turn ransomware response into a procurement and compliance problem, OFAC is signaling that anonymity providers and malware-support vendors are part of the same operational chain as the crew that drops the payload.
Silayev’s designation extends the same logic to cryptors, tools OFAC described as designed to make malware look harmless rather than protect data. CyberScoop also notes that Europol said it arrested the administrator of 1VPNS in May, but did not name the person, and Treasury did not immediately say whether Monday’s sanctions targeted that same individual. That caveat matters. The sanctions move is clear; the overlap with the Europol arrest is not.
Published ·Deep Fathom