Bottom Line: The U.S. Department of the Treasury sanctions a VPN provider for the first time for systematically supporting ransomware groups and other cybercriminals.
The U.S. Department of the Treasury has sanctioned through the Office of Foreign Assets Control (OFAC) two individuals and a VPN provider for supporting ransomware actors and other cybercriminals in attacks against U.S. targets. This is the first time the United States has sanctioned a VPN service in this manner.
The OFAC sanctions action targets VPN service First VPN Service (1VPNS), a 45-year-old Ukrainian operator, and another party involved. According to the U.S. Department of the Treasury, 1VPNS deliberately offered its infrastructure to ransomware groups and other cybercriminals to conceal their activities and orchestrate attacks.
The sanctioning marks an escalation in U.S. enforcement against infrastructure providers that knowingly support cybercriminals. Previous measures primarily targeted individual hackers or groups; action against an established service provider sets a new precedent. For CISOs, this means that third-party providers promising secure channels can come under pressure — and that government agencies are directing their attention to the supply chains of cybercrime infrastructure.
In practical terms, security managers should review their network monitoring capabilities to detect suspicious VPN connections or unusual exit nodes. This includes reviewing DNS queries and threat intelligence feeds that list known malicious VPN providers. Organizations should also update their incident response processes to account for the potential use of anonymization tools by threat actors.
Source: thehackernews.com · Published July 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.