First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
https://thehackernews.com/2026/05/first-vpn-dismantled-in-global-takedown.html
Publish Date: 2026-05-22 13:35:00
Source Domain: thehackernews.com
Summary:
Authorities in Europe and North America have successfully dismantled First VPN Service through Operation Saffron, a coordinated effort led by France and the Netherlands that aimed to disrupt a criminal VPN provider extensively used by ransomware actors and fraudsters to evade law enforcement. The operation, supported by multiple countries, resulted in the seizure of 33 servers and domains, including several using the onion network on Tor. First VPN advertised itself as an impenetrable shield for cybercriminal operations, allowing users to carry out attacks and large-scale fraud anonymously. The disruption has made cybercriminal users aware that anonymity on such services is increasingly compromised, although demand remains for such anonymizing tools, now with raised entry barriers. The operation targeted 32 exit node servers across 27 countries, including the U.S., providing critical infrastructure for numerous ransomware groups. The shutdown has potentially impeded cybercriminal activities, raising the cost and risk for future anonymization services.
Key Points:
- Operation Saffron led by France and Netherlands successfully dismantled First VPN used by cybercriminals.
- The operation involved multiple countries and led to the seizure of 33 VPN servers and domains.
- First VPN allowed cybercriminals to hide their identities while executing ransomware, data theft, and fraud.
- Takedown of the service potentially raises the challenges for future anonymization services, although demand remains.
- Disruption affected servers in multiple countries including the U.S., impacting a wide array of ransomware groups.