Authorities take down First VPN after ransomware actors used it to hide attacks
International authorities have dismantled First VPN, a cybercrime-focused virtual private network that investigators say helped ransomware actors, hackers, fraudsters, and account thieves hide their activity online. The takedown took place during Operation Saffron on May 19 and 20, 2026, in a coordinated action led by French and Dutch authorities, with support from Europol and Eurojust.
The operation removed a service that had become deeply tied to cybercrime investigations across Europe and beyond. Authorities took down First VPN’s main domains, including 1vpns.com, 1vpns.net, and 1vpns.org, along with associated onion domains used to reach the service on the dark web.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
First VPN did not operate like a normal consumer VPN marketed around privacy, streaming, or secure public Wi-Fi use. Investigators say it targeted cybercriminals directly, advertised on underground forums, and promised users that it would not store data, would not cooperate with judicial authorities, and would not fall under any jurisdiction.
What authorities seized during Operation Saffron
The action focused on the infrastructure that allowed First VPN customers to route criminal traffic through hidden systems. Authorities dismantled at least 33 servers linked to the service and searched a location in Ukraine, where a suspect connected to the administration of First VPN was interviewed.
According to Bitdefender, which supported the investigation through Europol, the action exposed data linked to 506 users and helped produce 83 intelligence packages for international law enforcement partners. The company also said 21 Europol-supported investigations advanced because of intelligence obtained from the takedown.
| Operation detail | What happened |
|---|---|
| Operation name | Operation Saffron |
| Action dates | May 19 and 20, 2026 |
| Main target | First VPN, also linked to 1vpns domains |
| Infrastructure action | At least 33 servers dismantled and key domains shut down |
| Lead authorities | French and Dutch investigators |
| Judicial and police support | Eurojust, Europol, and authorities from several participating countries |
Why First VPN mattered to ransomware investigations
First VPN mattered because it gave criminals a ready-made way to hide where attacks came from. A ransomware group can use malware, stolen credentials, and phishing emails, but it also needs infrastructure that makes the attack harder to trace. Services like First VPN fill that gap by masking traffic and making attribution slower.
Authorities said the service appeared in almost every major Europol-supported cybercrime investigations in recent years. That gives the takedown broader importance than the shutdown of a single website, because it disrupts a tool used across many different types of cybercrime.
The case also shows how law enforcement is increasingly targeting criminal infrastructure instead of only chasing individual attackers after an incident. Removing a trusted anonymization layer can force multiple groups to rebuild their setup, make mistakes, or move to less reliable tools.
How investigators reached the service
The investigation began after French authorities found First VPN being promoted on known criminal forums. Eurojust opened a case in May 2022, and a joint investigation team was formed in November 2023 so French and Dutch authorities could share evidence and coordinate their legal strategy.

As more countries joined, investigators used European Investigation Orders and Mutual Legal Assistance requests to expand access and share evidence. Eurojust also hosted 16 coordination meetings before the joint action days.
One of the most important parts of the case was access to First VPN before the service went offline. Authorities said this allowed investigators to gather traffic data from users who believed they were operating in a secure environment.
Countries and agencies involved
The action days involved France, the Netherlands, Luxembourg, Romania, Switzerland, Ukraine, and the United Kingdom. Additional cooperation came from other international partners, while Europol hosted an Operational Taskforce that brought together investigators from 16 countries to analyze the seized data.
- France and the Netherlands led the joint investigation.
- Ukraine conducted a search and interview connected to the suspected administrator.
- Romania, Luxembourg, Switzerland, and the United Kingdom took part in the coordinated action.
- Eurojust coordinated judicial cooperation across participating countries.
- Europol helped analyze data and distribute intelligence to partner agencies.
The takedown also included notification messages to users of the service. Authorities informed identified users that First VPN had been shut down and that they had been flagged by investigators.
What this means for cybercriminal VPN services
The First VPN case sends a clear warning to services that market anonymity specifically for criminal use. VPN technology remains legal and widely used for legitimate privacy and security reasons, but law enforcement is drawing a sharper line around providers that knowingly support ransomware, hacking, fraud, or data theft.
Bitdefender’s Draco Team described the case as its first VPN-category takedown in its law enforcement collaboration program. The company framed the disruption as part of a wider effort to remove the supporting layers that allow cybercrime groups to operate at scale.
More criminal anonymization services will likely appear, but Operation Saffron raises the risk for both operators and users. Customers who trusted First VPN’s claims of no cooperation and no data exposure now face the opposite result, with seized infrastructure, shared intelligence, and follow-up investigations underway.
For businesses and security teams, the case is another reminder that ransomware defense depends on more than endpoint protection. Attackers rely on infrastructure, payment channels, credentials, hosting, and anonymization. When one layer disappears, ongoing investigations can move faster.
FAQ
First VPN was a virtual private network service that authorities say targeted cybercriminals by offering anonymity, hidden infrastructure, and no-cooperation promises.
First VPN was taken down during Operation Saffron on May 19 and 20, 2026.
French and Dutch authorities led the operation, with support from Europol, Eurojust, and law enforcement partners in several countries.
Authorities targeted First VPN because it allegedly helped ransomware actors, hackers, fraudsters, and other cybercriminals hide their identities and infrastructure.
Using a VPN is legal in many countries for privacy and security. The issue in this case was the alleged use and marketing of First VPN for criminal activity.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages