Briefing

Police seize “First VPN” service used in ransomware, data theft attacks

security
by Bill Toulas ·

Ensure VPN usage complies with legal requirements and monitor for compromised VPN traffic.

What to do now

Review VPN logs, verify compliance with local laws, and notify users if necessary.

Summary

A joint international law‑enforcement operation seized the virtual private network service First VPN, used by threat actors in ransomware and data‑theft attacks. Europol seized 33 servers linked to First VPN across 27 countries, seized domains 1vpns.com, 1vpns.net, 1vpns.org, and related onion domains, and disrupted key infrastructure supporting the service. The operation identified and questioned a Ukrainian suspect, notified identified users, and shared data on 506 users and 83 intelligence packages with international partners. The seizure, conducted May 19‑20 2026, also involved the disruption of the service’s infrastructure and the collection of user databases. The operation was coordinated by investigators from 16 countries, and the seized data is being used to aid ongoing or upcoming investigations.

Organizations using VPN services should review their VPN logs, verify compliance with local laws, and notify users if necessary to mitigate potential exposure to compromised VPN traffic.

Key changes

  • Europol seized 33 servers linked to First VPN across 27 countries.
  • Seized domains: 1vpns.com, 1vpns.net, 1vpns.org, and related onion domains.
  • Disrupted key infrastructure supporting the service.
  • Identified and questioned a Ukrainian suspect.
  • Notified identified users; 506 users' data shared internationally.
  • Released 83 intelligence packages aiding investigations.
  • Operation coordinated by investigators from 16 countries.
  • Seizure occurred May 19‑20 2026.

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting