Particle.news

U.S. Sanctions VPN Provider and Two Men for Enabling Ransomware

Freezing their U.S. assets, the action signals a policy shift to disrupt the services and tools attackers use to hide and deliver malware.

Overview

  • U.S. authorities designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and malware tool seller Yegeniy Vladimirovich Silayev for supplying services that helped ransomware groups hit hospitals and other critical infrastructure.
  • The Treasury’s Office of Foreign Assets Control listed the three parties on July 13, 2026, blocked any property in U.S. jurisdiction, and barred U.S. persons from dealing with them.
  • Officials say 1VPNS provided VPN infrastructure that let attackers conceal their origins and manage attacks while Silayev, a Belarusian national, sold “cryptors,” software that hides malicious code from security tools.
  • The action follows a May 2026 European takedown of 1VPNS infrastructure supported by the FBI and was coordinated with the U.K., showing combined law-enforcement and diplomatic pressure across allies.
  • By targeting enablers rather than only operators, the U.S. aims to raise the cost and complexity of ransomware campaigns and reduce disruptions to patient care and local services that have caused billions in losses.