Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    US charges Google security engineer with Polymarket insider trading

    May 30, 2026

    CVE-2026-10152 | THREATINT

    May 30, 2026

    SSA-645131 V1.0: Multiple WRL File Parsing Vulnerabilities in Teamcenter Visualization

    May 30, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Police seize “First VPN” service used in ransomware, data theft attacks
    News

    Police seize “First VPN” service used in ransomware, data theft attacks

    adminBy adminMay 23, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Police seize “First VPN” service used in ransomware, data theft attacks

    A virtual private network service called ‘First VPN,’ used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation.

    Authorities have seized dozens of First VPN servers located in 27 countries, arrested the administrator, and conducted a house search in Ukraine.

    The VPN service was advertised on various cybercrime forums as a privacy-focused VPN that does not log user data and ignores law enforcement requests for user information.

    VPN tools encrypt users’ traffic and hide their real IP addresses. While they are used legitimately to protect privacy on public WiFi, bypass censorship, reduce tracking, and enable secure remote work, threat actors also rely on them to hide their location and infrastructure.

    Depending on the region they operate in, VPN providers may be legally required to comply with law enforcement requests and hand over any data they retain for criminal investigations.

    According to Europol, the name of the service came up in almost every major cybercrime investigation the agency supported. Europol says that First VPN names have been shut down.

    Seizure notice published on one of First VPN's website
    Seizure notice published on a First VPN website
    Source: BleepingComputer

    The investigation into the service started in December 2021 and was led by the French and Dutch authorities, who formed a joint investigation team in November 2023.

    At some point, the investigators infiltrated the VPN infrastructure before it went offline and collected the user database and identified the VPN connections cybercriminals used in attacks.

    In an official communication video in the form of a cartoon, Europol highlights that even if threat actors promise to remove the data, oftentimes the information is still present on the servers.

     

    “An Operational Taskforce was set up at Europol, which brought together investigators from 16 countries to analyze the seized data and coordinate intelligence sharing with international partners,” explains Eurojust.

    A coordinated international operation conducted between May 19 and 20 targeted the “First VPN” service and resulted in the following actions:

    • Seizure of 33 servers linked to “First VPN”
    • Seizure of the 1vpns.com, 1vpns.net, 1vpns.org, and related onion domains
    • Disruption of key infrastructure supporting the service
    • Identification and questioning of a Ukrainian suspect
    • Notifications issued to identified users of the platform

    The press release from the Dutch police confirms that all users of First VPN have been identified and directly notified, though no specific numbers were mentioned, and it’s unclear whether there are plans for subsequent legal action against them.

    Europol’s announcement mentions that information about 506 users was shared internationally, as well as 83 “intelligence packages” that will aid ongoing or upcoming investigations.

    “The gathered intelligence exposed thousands of users linked to the cybercrime ecosystem and generated operational leads connected to ransomware attacks, fraud schemes, and other serious offences worldwide,” Europol states.


    article image

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSSA-306654 V1.9 (Last Update: 2025-04-08): Insyde BIOS Vulnerabilities in Siemens Industrial Products
    Next Article Debian krb5 Important Denial of Service Flaw DSA-6293-1
    admin
    • Website

    Related Posts

    News

    US charges Google security engineer with Polymarket insider trading

    May 30, 2026
    News

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026
    News

    New CIFSwitch Linux flaw gives root on multiple distributions

    May 30, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    US charges Google security engineer with Polymarket insider trading

    May 30, 2026

    CVE-2026-10152 | THREATINT

    May 30, 2026

    SSA-645131 V1.0: Multiple WRL File Parsing Vulnerabilities in Teamcenter Visualization

    May 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.