Vulnerabilities

Ransomware Enablers Sanctioned by US Treasury

July 15, 2026 00:26 · 10 min read
Ransomware Enablers Sanctioned by US Treasury

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has taken action against individuals and entities that enable ransomware attacks. On Monday, OFAC designated First VPN Service (1VPNS), a virtual private network provider, and its administrator, Dmytro Rashevskyi, for selling services to ransomware groups.

Enabling Ransomware Attacks

1VPNS has been advertising on cybercriminal forums since 2014, claiming to keep no logs of user activity or identities and refusing to cooperate with law enforcement. Rashevskyi allegedly used false identities to acquire infrastructure from companies that would otherwise have refused service due to complaints of abuse.

The sanctions come after European law enforcement took down 1VPNS's website and infrastructure in May, with support from the FBI's Boston Field Office, as part of a joint action dubbed "Operation Saffron" led by French and Dutch authorities. The investigation began in December 2021, with law enforcement officers infiltrating the VPN's infrastructure and collecting its user database before it was dismantled.

Seized Servers and Exposed Users

Throughout the joint operation, the authorities seized 33 servers linked to 1VPNs across 27 countries, arrested its administrator, and exposed thousands of users associated with ransomware, fraud, and other malicious activity worldwide. Victims of ransomware attacks involving 1VPNS' infrastructure included U.S. businesses, hospitals, financial services firms, and municipal governments.

This week, the Treasury Department also sanctioned Belarusian national Yegeniy Vladimirovich Silayev, who sells cryptors (also known as crypters), which are tools that help ransomware and other malware evade detection by security software. Officials estimate that ransomware operations using 1VPNS and Silayev cryptors have caused billions of dollars in losses to businesses and critical infrastructure providers across the United States.

"These actors supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers," said State Department spokesperson Thomas Pigott.

By targeting not just ransomware operators but the service providers and tool suppliers who make their attacks possible, the United States and its partners are dismantling the broader networks that sustain cybercriminal activity worldwide. OFAC said the action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office.

Sanctions and Consequences

Under these sanctions, all property of the designated individuals and entities within U.S. jurisdiction is blocked, while U.S. persons and businesses are barred from transactions involving them. On Monday, the European Union and the United Kingdom also jointly sanctioned dozens of Russian individuals and entities, accusing Russia of coordinating a network of hacking groups linked to cyberattacks across Europe.

The US Treasury Department's actions demonstrate the government's commitment to disrupting and dismantling the networks that enable ransomware attacks. By targeting the individuals and entities that provide services and tools to ransomware groups, the US is taking a crucial step towards reducing the threat of ransomware attacks and protecting critical infrastructure.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about how to protect your organization from ransomware attacks.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free