First VPN Cybercrime Service Dismantled in Global Takedown

Authorities led by France and the Netherlands dismantled First VPN Service, seizing 33 servers behind a tool used by 25 ransomware groups since 2014.

First VPN Cybercrime Service Dismantled in Global Takedown
International authorities dismantle the First VPN cybercrime service

An international coalition of law enforcement agencies has dismantled First VPN Service, a virtual private network marketed to criminals as a way to hide the origins of ransomware attacks, large-scale fraud, and data theft. The takedown, announced on May 22, 2026, removes a piece of infrastructure that investigators say had quietly underpinned cybercrime for more than a decade.

A VPN built for criminals

Unlike mainstream privacy tools, First VPN was openly promoted on Russian-speaking cybercrime forums such as Exploit and XSS as a service designed to evade law enforcement. According to Europol, it advertised anonymous payments and hidden infrastructure, and assured customers it would not cooperate with judicial authorities, store logs, or fall under any jurisdiction. Subscriptions ranged from roughly $2 for a single day to $483 for a year, paid in Bitcoin and several other electronic currencies.

The FBI said the service had been active since about 2014, operating 32 exit-node servers across 27 countries, with three nodes located in the United States. It offered multiple connection protocols and the ability to disguise its traffic as ordinary encrypted web browsing, making detection harder for defenders.

How Operation Saffron unfolded

Codenamed Operation Saffron, the investigation was led by France and the Netherlands with support from more than a dozen other nations, including the United States, Canada, Germany, the United Kingdom, and Ukraine, in a coordination effort dating back to December 2021. Between May 19 and 20, 2026, authorities took concurrent action: interviewing the service's administrator, conducting a house search in Ukraine, seizing 33 servers, and confiscating the domains used to run the operation, including several hidden services on the Tor network.

Linked to 25 ransomware groups

Investigators say no fewer than 25 ransomware groups, including the Avaddon operation, relied on First VPN to perform reconnaissance and carry out intrusions while masking their true locations. Dismantling that shared layer is intended to raise the cost and risk for the criminal ecosystem that depends on anonymity-as-a-service.

Part of a wider crackdown

The action lands amid a broader push against criminal enablers and the tools that automate attacks. It follows recent disruption efforts such as Microsoft's move against the Fox Tempest malware-signing service, and arrives as policymakers weigh tighter oversight of advanced technology, illustrated by the European Parliament's push for a permanent AI and robotics committee. Security increasingly intersects with autonomous systems as well, a theme visible in defense programs like the Pentagon's counter-drone investments.

For defenders, the message is that the infrastructure behind cybercrime is itself a target, not just the malware it carries.

Reporting based on coverage from The Hacker News, Europol, Eurojust, and the U.S. FBI.

Category: Cyber Security

Tags: Security Cybersecurity European Union

Related Articles