Authorities take down First VPN after ransomware actors used it to hide attacks


International authorities have dismantled First VPN, a cybercrime-focused virtual private network that investigators say helped ransomware actors, hackers, fraudsters, and account thieves hide their activity online. The takedown took place during Operation Saffron on May 19 and 20, 2026, in a coordinated action led by French and Dutch authorities, with support from Europol and Eurojust.

The operation removed a service that had become deeply tied to cybercrime investigations across Europe and beyond. Authorities took down First VPN’s main domains, including 1vpns.com, 1vpns.net, and 1vpns.org, along with associated onion domains used to reach the service on the dark web.

First VPN did not operate like a normal consumer VPN marketed around privacy, streaming, or secure public Wi-Fi use. Investigators say it targeted cybercriminals directly, advertised on underground forums, and promised users that it would not store data, would not cooperate with judicial authorities, and would not fall under any jurisdiction.

What authorities seized during Operation Saffron

The action focused on the infrastructure that allowed First VPN customers to route criminal traffic through hidden systems. Authorities dismantled at least 33 servers linked to the service and searched a location in Ukraine, where a suspect connected to the administration of First VPN was interviewed.

According to Bitdefender, which supported the investigation through Europol, the action exposed data linked to 506 users and helped produce 83 intelligence packages for international law enforcement partners. The company also said 21 Europol-supported investigations advanced because of intelligence obtained from the takedown.

Operation detailWhat happened
Operation nameOperation Saffron
Action datesMay 19 and 20, 2026
Main targetFirst VPN, also linked to 1vpns domains
Infrastructure actionAt least 33 servers dismantled and key domains shut down
Lead authoritiesFrench and Dutch investigators
Judicial and police supportEurojust, Europol, and authorities from several participating countries

Why First VPN mattered to ransomware investigations

First VPN mattered because it gave criminals a ready-made way to hide where attacks came from. A ransomware group can use malware, stolen credentials, and phishing emails, but it also needs infrastructure that makes the attack harder to trace. Services like First VPN fill that gap by masking traffic and making attribution slower.

Authorities said the service appeared in almost every major Europol-supported cybercrime investigations in recent years. That gives the takedown broader importance than the shutdown of a single website, because it disrupts a tool used across many different types of cybercrime.

The case also shows how law enforcement is increasingly targeting criminal infrastructure instead of only chasing individual attackers after an incident. Removing a trusted anonymization layer can force multiple groups to rebuild their setup, make mistakes, or move to less reliable tools.

How investigators reached the service

The investigation began after French authorities found First VPN being promoted on known criminal forums. Eurojust opened a case in May 2022, and a joint investigation team was formed in November 2023 so French and Dutch authorities could share evidence and coordinate their legal strategy.

VPN IP address

As more countries joined, investigators used European Investigation Orders and Mutual Legal Assistance requests to expand access and share evidence. Eurojust also hosted 16 coordination meetings before the joint action days.

One of the most important parts of the case was access to First VPN before the service went offline. Authorities said this allowed investigators to gather traffic data from users who believed they were operating in a secure environment.

Countries and agencies involved

The action days involved France, the Netherlands, Luxembourg, Romania, Switzerland, Ukraine, and the United Kingdom. Additional cooperation came from other international partners, while Europol hosted an Operational Taskforce that brought together investigators from 16 countries to analyze the seized data.

  • France and the Netherlands led the joint investigation.
  • Ukraine conducted a search and interview connected to the suspected administrator.
  • Romania, Luxembourg, Switzerland, and the United Kingdom took part in the coordinated action.
  • Eurojust coordinated judicial cooperation across participating countries.
  • Europol helped analyze data and distribute intelligence to partner agencies.

The takedown also included notification messages to users of the service. Authorities informed identified users that First VPN had been shut down and that they had been flagged by investigators.

What this means for cybercriminal VPN services

The First VPN case sends a clear warning to services that market anonymity specifically for criminal use. VPN technology remains legal and widely used for legitimate privacy and security reasons, but law enforcement is drawing a sharper line around providers that knowingly support ransomware, hacking, fraud, or data theft.

Bitdefender’s Draco Team described the case as its first VPN-category takedown in its law enforcement collaboration program. The company framed the disruption as part of a wider effort to remove the supporting layers that allow cybercrime groups to operate at scale.

More criminal anonymization services will likely appear, but Operation Saffron raises the risk for both operators and users. Customers who trusted First VPN’s claims of no cooperation and no data exposure now face the opposite result, with seized infrastructure, shared intelligence, and follow-up investigations underway.

For businesses and security teams, the case is another reminder that ransomware defense depends on more than endpoint protection. Attackers rely on infrastructure, payment channels, credentials, hosting, and anonymization. When one layer disappears, ongoing investigations can move faster.

FAQ

What was First VPN?

First VPN was a virtual private network service that authorities say targeted cybercriminals by offering anonymity, hidden infrastructure, and no-cooperation promises.

When was First VPN taken down?

First VPN was taken down during Operation Saffron on May 19 and 20, 2026.

Who led Operation Saffron?

French and Dutch authorities led the operation, with support from Europol, Eurojust, and law enforcement partners in several countries.

Why did authorities target First VPN?

Authorities targeted First VPN because it allegedly helped ransomware actors, hackers, fraudsters, and other cybercriminals hide their identities and infrastructure.

Is using a VPN illegal?

Using a VPN is legal in many countries for privacy and security. The issue in this case was the alleged use and marketing of First VPN for criminal activity.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages