Europol and FBI Shut Down First VPN, Used by 25 Ransomware Gangs

An international coalition of law enforcement agencies dismantled First VPN, a virtual private network service used by cybercriminals, and arrested its administrator, authorities announced Thursday, May 21, 2026.

The FBI said in an alert that “at least” 25 ransomware gangs relied on First VPN to conceal their malicious activity. Beyond ransomware, cybercriminals used the service to scan the internet, operate botnets, launch distributed denial-of-service attacks, and run scams. First VPN maintained servers across 27 countries.

Europol said the service offered more than just anonymous connections — it also provided cybercriminals with anonymous payments, hidden infrastructure, and other services explicitly marketed to criminal hackers. The agency noted that First VPN “had become deeply embedded in the cybercrime ecosystem, appearing in almost every major cybercrime investigation supported by Europol in recent years.” The service advertised on known cybercrime forums, including at least two Russian-speaking marketplaces.

Despite First VPN’s claims that it stored no logs that could link users to their activity, Europol said investigators obtained the service’s user database and identified VPN connections, “exposing thousands of users linked to the cybercrime ecosystem.” Those users were notified of the shutdown and informed that they had been identified.

In addition to the administrator’s arrest, authorities said dozens of servers were dismantled and the service’s infrastructure was disrupted. The investigation that led to the takedown was launched in December 2021.

The operation suggests that VPN services marketed specifically to criminal users may not provide the protection they promise, and this could have a chilling effect on cybercriminals who relied on similar anonymous infrastructure to conduct attacks.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top