Global law enforcement operation dismantles criminal VPN service used by 25 ransomware groups
Summary
Hide ▲
Show ▼
A coordinated international law enforcement operation dismantled First VPN Service, a criminal-focused VPN infrastructure leveraged by at least 25 ransomware groups, threat actors, and cybercriminals for anonymizing malicious activities including ransomware attacks, data theft, network reconnaissance, and denial-of-service operations. The takedown spanned May 19–20, 2026 and involved authorities from 21 countries, including France, the Netherlands, Ukraine, the U.S., and the U.K., under operations led by Europol and Eurojust. The service, active since 2014, provided 32 exit nodes across 27 countries and promoted itself on Russian-speaking cybercrime forums such as Exploit[.]in and XSS[.]is as an anonymity tool resistant to law enforcement cooperation. Impact includes the seizure of 33 servers, interviews with the service administrator, and disruption of infrastructure supporting global cybercrime operations. The FBI confirmed the service’s role in enabling multiple ransomware operations, including Avaddon Ransomware.
Timeline
-
22.05.2026 20:35 1 articles · 1h ago
First VPN Service seized in international law enforcement operation
Authorities from 21 countries dismantled First VPN Service, a criminal VPN infrastructure used by at least 25 ransomware groups, during a coordinated operation on May 19–20, 2026. Actions included server seizures across 27 countries, a house search in Ukraine, and interviews with the service administrator. The FBI confirmed the service’s role in enabling ransomware operations since at least 2014.
Show sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
Information Snippets
-
First VPN Service was shut down by law enforcement coordinated across 21 countries between May 19 and 20, 2026.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
The service operated from approximately 2014 and provided 32 exit node servers in 27 countries, including three in the U.S.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
First VPN was promoted on Russian-speaking cybercrime forums and explicitly marketed to criminals to evade law enforcement.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
The operation involved seizing 33 servers, conducting a house search in Ukraine, and interviewing the service administrator.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
The service accepted payments via Bitcoin, Perfect Money, Webmoney, EgoPay, and InterKass, with annual subscriptions priced up to $483.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
First VPN supported multiple VPN protocols including OpenConnect, WireGuard, Outline, and VLess TCP Reality, with encryption options such as OpenVPN ECC, L2TP/IPSec, and PPtP.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
The service offered technical support via a self-hosted Jabber server and Telegram, with 'VLESS' and 'Reality' protocols designed to disguise VPN traffic as HTTPS over common web ports.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35
-
At least 25 ransomware groups, including Avaddon Ransomware, were confirmed to have used First VPN infrastructure for network reconnaissance, intrusions, and other malicious activities.
First reported: 22.05.2026 20:351 source, 1 articleShow sources
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups — thehackernews.com — 22.05.2026 20:35