US sanctions First VPN over ransomware support
The Treasury sanctioned First VPN Service and its administrator for facilitating ransomware operations, with hospitals among the cited targets.
The US Treasury sanctioned First VPN Service (1VPNS) and its administrator, Ukrainian Dmytro Rashevskyi, for facilitating activity tied to ransomware groups. The available coverage links the move to attacks against hospitals.
The US Treasury has sanctioned First VPN Service (1VPNS) and its administrator, Ukrainian Dmytro Rashevskyi, for facilitating operations tied to ransomware groups. The available coverage links the move to attacks against hospitals, although the material provided does not identify specific groups or detail particular victims.
Scope of the sanctions
According to the US Treasury notice, OFAC blocks all property and interests in property of the designated persons that are in the United States or under the control of US persons. The measure can also expose financial institutions and third parties to sanctions if they conduct transactions with them.
The action also included Yegeniy Vladimirovich Silayev, whom the Treasury described as a cryptor provider. US authorities say he offered encryption and obfuscation services to ransomware operators targeting entities in the United States and allied countries.
How Washington frames the case
The Treasury tied the designation to ransomware activity affecting people, allies, or partners of the United States. In its definition, that activity is intended to, or involves, extortion through the malicious use of code, encryption, or other techniques that affect the confidentiality, integrity, or availability of data or systems.
In the case of First VPN, the reporting reviewed places the sanction within a broader campaign against services that allegedly helped facilitate ransomware attacks against hospitals. Based on the material available, it is not possible to establish a more precise attribution for the operator network or for the affected health care facilities.
The move puts the focus back on the infrastructure and services that support ransomware campaigns, from tools used to hide activity to encryption and obfuscation services. In this case, the US Treasury chose to sanction both the alleged support infrastructure and the individuals linked to that operation.
Sources
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attackshome.treasury.gov· U.S. Department of the Treasury
- Tesoro de EE.UU. sanciona a First VPN por facilitar ataques ransomware contra hospitalesmoncloa.com· Moncloa



