The US Treasury did not sanction a VPN app you have heard of. On July 13, 2026, its Office of Foreign Assets Control (OFAC) hit First VPN Service, also known as 1VPNS, along with its administrator and a separate malware seller, for enabling ransomware attacks that cost American businesses billions. This is a bulletproof hosting operation that marketed itself on cybercriminal forums, not a consumer privacy tool. If you use NordVPN, ProtonVPN, or any other audited provider, nothing here touches your subscription.

But the story is worth understanding anyway, because it draws a clean line between what a real no-logs VPN promises and what a “we don’t cooperate with law enforcement” pitch to criminals actually means.

What OFAC actually did on July 13

OFAC designated two individuals and one entity. The entity is First VPN Service (1VPNS), which has advertised on multiple cybercriminal forums since 2014. Its administrator, Dmytro Rashevskyi, was sanctioned alongside it. Treasury says Rashevskyi bought server infrastructure using false identities, including “Maksim Sorin” and “Roman Chabanenko,” specifically so hosting companies that might have refused to work with him under his real name never got the chance.

A third person, Yevgeniy Vladimirovich Silayev, was designated separately. He sells “cryptors,” tools that disguise ransomware and other malware so it slips past antivirus and endpoint detection. He is not part of First VPN Service, but he was named in the same action because he served the same ransomware ecosystem.

Sanctions work differently from an arrest. OFAC’s action freezes any US-linked assets tied to the sanctioned individuals and entity, and it bars US persons and companies from doing business with them. It does not put anyone in handcuffs. It cuts off financial oxygen: payment processors, hosting providers, and any US-regulated business now have to treat these names as radioactive or risk their own sanctions exposure.

First VPN Service was already dismantled two months earlier

Here is the detail that matters most for reading this story correctly: First VPN Service was already taken down. A joint law enforcement operation involving European and North American authorities dismantled the service in May 2026. That earlier action was a criminal takedown, seizing servers and disrupting the operation itself.

The July 13 OFAC sanctions are a follow-up, not a new bust. They target the money and the people behind the service after the infrastructure was already gone. This is a common one-two pattern in cybercrime enforcement now: law enforcement seizes the servers and databases, then Treasury goes after the assets and the individuals so they cannot simply rebuild under a new name with a clean bank account. Two agencies, two different tools, same underlying investigation.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

What First VPN Service actually was

First VPN Service was not a product built for ordinary people trying to protect their browsing at a coffee shop. It was infrastructure built for criminals, and it advertised itself as such on the same forums where ransomware gangs coordinate and trade access.

Its pitch was explicit: no logs of user identities or activity, and a refusal to cooperate with law enforcement investigations into illegal activity. That is a “bulletproof VPN,” a term security researchers use for services built specifically to shield criminal operations from investigators, as opposed to consumer tools built to protect ordinary privacy.

The distinction is not about the words used in the marketing copy. Plenty of legitimate VPNs also say “we don’t log your activity.” The distinction is about who the service is built for, who it is marketed to, and what happens when law enforcement shows up with a valid legal order.

Real no-logs VPNs and criminal “no-logs” VPNs are not the same claim

This is where the story gets confusing if you only skim the headline, so it is worth being precise.

A legitimate, audited consumer VPN’s no-logs claim means the company has architected its systems so it does not retain data that could identify what you did online, and independent auditors have verified that architecture. If a court in that provider’s jurisdiction serves a valid legal order, the company can respond truthfully: we have nothing to hand over, because we never collected it. That is what a warrant canary and a published transparency report are for.

A bulletproof VPN marketed on darkweb forums makes a similar-sounding promise for the opposite reason. Its value proposition is not “we protect your privacy by design.” It is “we will not cooperate with police, period,” aimed at an audience that specifically needs that. There is no independent audit, no public corporate registration, no transparency report, because none of that serves the business model. The whole point is to operate outside any framework that could compel compliance.

Same three words, “we don’t keep logs,” pointed at completely different customers with completely different accountability.

How to tell a real no-logs VPN from a criminal one

You will not personally encounter a service like First VPN Service, since it never advertised to consumers and only ever operated on forums built for cybercriminals. But the same red flags apply any time a VPN’s marketing sounds a little too aligned with evading accountability rather than protecting privacy.

Legitimate audited VPNBulletproof / criminal VPN
Independent, published no-logs auditNo audit, ever, by anyone
Public corporate entity and named leadershipAnonymous operators, false identities for infrastructure
Clear jurisdiction and published transparency reportsNo public jurisdiction, no reporting of any kind
Responds to valid legal process because it has nothing to hand overMarkets explicit refusal to cooperate with law enforcement
Sold openly, reviewed by mainstream outletsAdvertised only on cybercriminal forums

ProtonVPN is a useful reference point here precisely because it sits on the legitimate side of every row in that table: independently audited, publicly incorporated, transparent about its jurisdiction. NordVPN fits the same pattern. Neither one exists to shield criminal customers from investigators, and neither one would survive the kind of scrutiny that just landed on First VPN Service.

If you want to check any provider yourself before trusting it, our guide on how to verify a VPN’s no-logs claim walks through what an audit actually needs to cover, and our piece on how warrant canaries work explains the legal mechanics behind that “nothing to hand over” promise.

What this means for the legitimate VPN industry

“VPN” is a technical term, not a guarantee of intent. It describes a way of routing traffic, and that description covers everything from a privacy tool millions of people use to watch geo-blocked shows to bulletproof hosting sold to ransomware crews. First VPN Service used the label because it was technically accurate, not because it had anything in common with the consumer products people mean when they say “VPN.”

What has actually changed is the regulatory posture. Treasury used to leave this kind of infrastructure to police, who eventually shut it down and moved on. Now Treasury is willing to freeze the money too. Sanctions choke off the ability to rebuild under US-linked banking or hosting, which is a slower tool than a raid but a broader one. My guess is we will see more of this two-step pattern: police take down the servers, Treasury goes after the operators’ bank accounts a few weeks or months later.

For the legitimate industry, none of this changes much day to day. But it does sharpen a distinction worth keeping in mind: an audited VPN with a real corporate address and a real jurisdiction is a fundamentally different product than one that markets itself with a wink to people who need to hide from investigators. If you are picking a VPN, that difference is what actually matters, not the marketing copy.

Our Verdict

This is not a story about VPNs becoming less trustworthy. It is a story about US Treasury sanctioning a criminal bulletproof-hosting operation that borrowed the word "VPN" for its marketing on darkweb forums. First VPN Service was dismantled by law enforcement in May 2026, and the July 13 OFAC sanctions freeze the operators' assets as a follow-up. Nothing about this affects legitimate, audited providers. If anything, use it as a prompt to check that whatever VPN you actually pay for has a real audit behind its no-logs claim, not just the phrase itself.

For more on this pattern of takedowns, read our coverage of Operation Saffron, the May 2026 law enforcement operation that dismantled First VPN, and see who actually owns your VPN before you trust a “no logs” claim at face value.

Sources: US Department of the Treasury and The Hacker News