On 13 July 2026 the U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity for supplying tools and infrastructure to ransomware groups. The targets are the VPN provider First VPN Service (1VPNS), its administrator, and a seller of cryptors that disguise malware. OFAC says the ransomware crews using these services caused billions of dollars in losses to U.S. businesses and critical infrastructure.
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.
Ransomware is not a lone hacker with a laptop. It is a supply chain, and this week the United States went after the suppliers.
On 13 July 2026 the U.S. Treasury’s Office of Foreign Assets Control (OFAC) designated two individuals and one entity for enabling ransomware attacks. The entity is First VPN Service (1VPNS), a virtual private network provider whose principal clients were ransomware actors, used to hide the origin of attacks, deploy malware and manage stolen data. OFAC also designated the 1VPNS administrator, Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors that disguise malware as harmless files. The action was coordinated with the United Kingdom and follows a May 2026 European law enforcement takedown of the 1VPNS infrastructure.
Ransomware runs on services you can buy
OFAC’s action names a VPN provider and a cryptor seller whose paying customers were ransomware crews. One hid the origin of attacks and moved stolen data; the other disguised malware so security tools would not flag it. The tooling that makes ransomware work is a market, and defenders are up against the whole market, not one actor.
What the Treasury announced
The 13 July designations, according to the OFAC and State Department press releases:
- First VPN Service (1VPNS), a VPN provider whose principal clients were ransomware actors and other cybercriminals.
- Dmytro Rashevskyi, the 1VPNS administrator, who used false identities including Maksim Sorin and Roman Chabanenko to buy hosting.
- Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors that disguise malware as harmless files.
- The measure was coordinated with the United Kingdom and follows a May 2026 European takedown of the 1VPNS infrastructure supported by the FBI.
The sanctions in numbers
The figures come from the U.S. Treasury and State Department announcements of 13 July 2026 and from the reporting on the earlier European takedown. OFAC describes the losses as billions of dollars but does not publish a single exact total, so no precise figure is claimed here.
Why disguising malware is a paid service
Ransomware groups utilizing these individuals’ services have caused billions of dollars in losses to U.S. businesses and critical infrastructure providers.
From open forums to a coordinated takedown
The sanctions are the latest step in a case that ran for years. For the wider pattern of how these tools are used, see how a ransomware attack usually unfolds. What follows is the sequence described by the Treasury and the earlier law enforcement reporting.
The takedown in four numbers
The 1VPNS case in four numbers
U.S. Treasury OFAC and Operation Saffron, 2021 to 2026
What the ecosystem means for defenders
The table maps each enabler service to what it gave ransomware crews and to the defensive lesson a security team can take from it.
| Enabler service | What it gave ransomware crews | Defensive takeaway |
|---|---|---|
| Bulletproof VPN (1VPNS) | Hid the origin of attacks, delivered malware and moved stolen data, with no logs kept | Do not trust source IP alone; watch for anonymising infrastructure |
| Cryptors (Silayev) | Disguised ransomware as safe files to evade signature detection | Signature antivirus is not enough; use behaviour based EDR with tamper protection |
| False identities | Let the administrator buy hosting that would otherwise refuse him | Abuse reporting to providers matters; it is how takedowns start |
| Coordinated sanctions | Now freeze assets and cut enablers off from U.S. business | Transacting with a sanctioned actor carries its own legal exposure |
What goes wrong when you ignore the supply chain
Treating ransomware as a single-actor problem misses how it is actually run. These are the failure modes the 1VPNS case exposes.
- â›” Treating ransomware as a lone operator when it runs on a paid supply chain of VPNs, cryptors and hosting.
- â›” Relying on signature antivirus, when cryptors are sold specifically to defeat it.
- â›” Trusting geolocation or source IP, when bulletproof VPNs exist to hide the real origin.
- â›” Assuming a ransom payment is a clean transaction, when the recipient may be a sanctioned party.
- â›” Ignoring the data theft stage, since the same services also move exfiltrated data out of the network.
Paying a sanctioned ransomware actor can be a violation in itself
The designations freeze U.S. assets and bar U.S. persons from transactions with the named parties. If a ransomware crew relies on sanctioned infrastructure, a ransom payment can expose the victim to secondary legal liability. Treat any payment decision as a legal question, not only a technical one, and involve legal counsel and law enforcement before acting.
What to do this week
None of the following requires a new budget line. They close the specific paths this ecosystem sells, from evasion to anonymised exfiltration. For the full checklist, see our guide on preventing a ransomware attack.
- ✅ Move detection from signatures to behaviour: enable EDR with tamper protection so a packed payload is caught at execution.
- ✅ Treat source IP and geolocation as unreliable, and alert on traffic to and from anonymising VPN infrastructure.
- ✅ Keep at least one backup copy immutable or offline, beyond the reach of domain credentials.
- ✅ Write a ransom payment decision into the incident plan that requires legal and law enforcement review first.
- ✅ Report infrastructure abuse to hosting providers, because it is part of how takedowns like this one begin.
- ✅ Rehearse the response on the assumption that exfiltration already happened, not only encryption.
Enforcement is shifting to the enablers
The designations target the supply chain behind ransomware, not just the operators, and follow a May 2026 European takedown. Every enabler removed raises the cost of running a ransomware operation. If you are responding to an active incident, preserve the ransom note and one encrypted sample before reimaging: it is the starting point for recovering encrypted files.
Sources
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.
📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.
📅 Last updated: 20 July 2026



