US Treasury sanctions the ransomware supply chain

AI Overview

On 13 July 2026 the U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity for supplying tools and infrastructure to ransomware groups. The targets are the VPN provider First VPN Service (1VPNS), its administrator, and a seller of cryptors that disguise malware. OFAC says the ransomware crews using these services caused billions of dollars in losses to U.S. businesses and critical infrastructure.

Juan Ricardo Palacio, Co-Founder of HelpRansomware

Juan Ricardo Palacio

Co-Founder and CEO for the Americas, HelpRansomware

Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.

Ransomware is not a lone hacker with a laptop. It is a supply chain, and this week the United States went after the suppliers.

On 13 July 2026 the U.S. Treasury’s Office of Foreign Assets Control (OFAC) designated two individuals and one entity for enabling ransomware attacks. The entity is First VPN Service (1VPNS), a virtual private network provider whose principal clients were ransomware actors, used to hide the origin of attacks, deploy malware and manage stolen data. OFAC also designated the 1VPNS administrator, Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors that disguise malware as harmless files. The action was coordinated with the United Kingdom and follows a May 2026 European law enforcement takedown of the 1VPNS infrastructure.

Ransomware runs on services you can buy

OFAC’s action names a VPN provider and a cryptor seller whose paying customers were ransomware crews. One hid the origin of attacks and moved stolen data; the other disguised malware so security tools would not flag it. The tooling that makes ransomware work is a market, and defenders are up against the whole market, not one actor.

What the Treasury announced

The 13 July designations, according to the OFAC and State Department press releases:

  • First VPN Service (1VPNS), a VPN provider whose principal clients were ransomware actors and other cybercriminals.
  • Dmytro Rashevskyi, the 1VPNS administrator, who used false identities including Maksim Sorin and Roman Chabanenko to buy hosting.
  • Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors that disguise malware as harmless files.
  • The measure was coordinated with the United Kingdom and follows a May 2026 European takedown of the 1VPNS infrastructure supported by the FBI.

The sanctions in numbers

3
individuals and entities designated by OFAC on 13 July
33
servers seized in the May 2026 European takedown
27
countries where the 1VPNS servers were hosted
2014
year 1VPNS began advertising on criminal forums

The figures come from the U.S. Treasury and State Department announcements of 13 July 2026 and from the reporting on the earlier European takedown. OFAC describes the losses as billions of dollars but does not publish a single exact total, so no precise figure is claimed here.

Why disguising malware is a paid service

Ransomware groups utilizing these individuals’ services have caused billions of dollars in losses to U.S. businesses and critical infrastructure providers.

U.S. Treasury, Office of Foreign Assets Control

From open forums to a coordinated takedown

The sanctions are the latest step in a case that ran for years. For the wider pattern of how these tools are used, see how a ransomware attack usually unfolds. What follows is the sequence described by the Treasury and the earlier law enforcement reporting.

2014
First VPN Service begins advertising on cybercriminal forums, promising to keep no logs and to refuse cooperation with law enforcement.
Dec 2021
French and Dutch investigators start infiltrating the 1VPNS infrastructure and quietly collect its user database.
May 2026
European law enforcement dismantles 1VPNS in Operation Saffron with FBI Boston support, seizing 33 servers across 27 countries.
13 Jul 2026
OFAC designates 1VPNS, administrator Dmytro Rashevskyi and cryptor seller Yegeniy Silayev; the United Kingdom sanctions further actors the same day.
After designation
U.S. jurisdiction assets of the named parties are frozen and U.S. persons are barred from any transactions with them.

The takedown in four numbers

The 1VPNS case in four numbers

U.S. Treasury OFAC and Operation Saffron, 2021 to 2026

Bar chart showing 33 servers seized, 27 countries, 12 years of operation since 2014 and 3 OFAC designations in the 1VPNS case.

📊 Read it this way: the numbers describe one enforcement action against ransomware infrastructure, not the attacks themselves. The scale sits in the supply chain, not in a single breach.

What the ecosystem means for defenders

The table maps each enabler service to what it gave ransomware crews and to the defensive lesson a security team can take from it.

Enabler service What it gave ransomware crews Defensive takeaway
Bulletproof VPN (1VPNS) Hid the origin of attacks, delivered malware and moved stolen data, with no logs kept Do not trust source IP alone; watch for anonymising infrastructure
Cryptors (Silayev) Disguised ransomware as safe files to evade signature detection Signature antivirus is not enough; use behaviour based EDR with tamper protection
False identities Let the administrator buy hosting that would otherwise refuse him Abuse reporting to providers matters; it is how takedowns start
Coordinated sanctions Now freeze assets and cut enablers off from U.S. business Transacting with a sanctioned actor carries its own legal exposure

What goes wrong when you ignore the supply chain

Treating ransomware as a single-actor problem misses how it is actually run. These are the failure modes the 1VPNS case exposes.

  • â›” Treating ransomware as a lone operator when it runs on a paid supply chain of VPNs, cryptors and hosting.
  • â›” Relying on signature antivirus, when cryptors are sold specifically to defeat it.
  • â›” Trusting geolocation or source IP, when bulletproof VPNs exist to hide the real origin.
  • â›” Assuming a ransom payment is a clean transaction, when the recipient may be a sanctioned party.
  • â›” Ignoring the data theft stage, since the same services also move exfiltrated data out of the network.

Paying a sanctioned ransomware actor can be a violation in itself

The designations freeze U.S. assets and bar U.S. persons from transactions with the named parties. If a ransomware crew relies on sanctioned infrastructure, a ransom payment can expose the victim to secondary legal liability. Treat any payment decision as a legal question, not only a technical one, and involve legal counsel and law enforcement before acting.

What to do this week

None of the following requires a new budget line. They close the specific paths this ecosystem sells, from evasion to anonymised exfiltration. For the full checklist, see our guide on preventing a ransomware attack.

  • ✅ Move detection from signatures to behaviour: enable EDR with tamper protection so a packed payload is caught at execution.
  • ✅ Treat source IP and geolocation as unreliable, and alert on traffic to and from anonymising VPN infrastructure.
  • ✅ Keep at least one backup copy immutable or offline, beyond the reach of domain credentials.
  • ✅ Write a ransom payment decision into the incident plan that requires legal and law enforcement review first.
  • ✅ Report infrastructure abuse to hosting providers, because it is part of how takedowns like this one begin.
  • ✅ Rehearse the response on the assumption that exfiltration already happened, not only encryption.

Enforcement is shifting to the enablers

The designations target the supply chain behind ransomware, not just the operators, and follow a May 2026 European takedown. Every enabler removed raises the cost of running a ransomware operation. If you are responding to an active incident, preserve the ransom note and one encrypted sample before reimaging: it is the starting point for recovering encrypted files.


Sources

Juan Ricardo Palacio, Co-Founder of HelpRansomware

Juan Ricardo Palacio

Co-Founder and CEO for the Americas, HelpRansomware

Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.

📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.

📅 Last updated: 20 July 2026

Leave a Comment

Your email address will not be published. Required fields are marked *