US authorities have imposed sanctions on First VPN

✨ Megiddo

✨ President ✨
Staff member
972
261
The US Treasury Department's Office of Foreign Assets Control (OFAC) has imposed sanctions against the VPN service First VPN Service (1VPNS) and its administrator, Ukrainian citizen Dmitry Rashevsky. According to US authorities, the service provided the necessary infrastructure for extortionists and other criminals. Interestingly, the recent outage of the t.me domain was linked to these sanctions.

First VPN's infrastructure was taken down in May 2026 during the international operation Saffron, led by French and Dutch law enforcement with support from the FBI.

The investigation began in December 2021, and over the years, investigators have managed to penetrate the service's internal infrastructure, gain access to the user database, and track the VPN connections used in the attacks.

First VPN had been operating since 2014 and was actively advertised on hacker forums as a service that keeps no logs, accepts anonymous payments, and does not cooperate with authorities. The service promised users "anonymity, stability, and security," and the website claimed that it was impossible to trace an IP address back to a specific client.

According to authorities, extortionists used First VPN to conceal the origins of their attacks, distribute malware, and manage stolen data. For example, the FBI reported that First VPN's infrastructure was used by at least 25 ransomware groups, including Avaddon: the service was used for reconnaissance, initial infiltration, data theft, and other attacks.

During the operation, law enforcement seized 33 servers in 27 countries, detained the service's administrator, and collected information on thousands of users linked to extortion, fraud, and other activities. At the time, Europol representatives noted that the name 1VPNS had appeared in nearly every major cybercrime investigation the agency had participated in.

As OFAC has now reported, American companies, hospitals, financial institutions, and municipal governments were among those affected by attacks that used 1VPNS's infrastructure. The US Treasury Department claims that ransomware attacks related to First VPN have caused billions of dollars in losses to businesses and critical infrastructure operators.

According to the department, Dmitry Rashevsky used several false identities, including Maxim Sorin and Roman Chabanenko. Investigators believe he used these identities to purchase servers from companies that might have refused him access due to numerous complaints about malicious activity originating from 1VPNS addresses.

All assets of Rashevsky and 1VPNS under US jurisdiction have now been frozen, and American citizens and organizations are prohibited from conducting transactions with them.

Interestingly, the temporary blocking of the t.me domain, owned by Telegram, was linked to these sanctions against First VPN. OFAC officials listed the service's Telegram channel as a separate website in First VPN's profile.

t.me.jpg


Subsequently, employees of the Montenegrin company doMEn doo, which manages the .me domain extension under the Domain.ME brand, transferred the t.me domain to serverHold status. As a result, it disappeared from DNS records, and Telegram short links stopped working for users worldwide. As a result, Pavel Durov contacted Domain.ME representatives on the social network X, asking why t.me links had stopped working. A few hours later, the domain was back online, and Domain.ME representatives responded to Durov stating that t.me was blocked "due to OFAC compliance," effectively confirming the incident's connection to US sanctions. During the outage, Telegram links were replaced with telegram.me, and after the domain was restored, Pavel Durov announced on X that he had now purchased the t.you domain. Apparently, just in case. @xakep.ru