Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Home/CyberSecurity News/Law Enforcement Dismantles VPNLab.net, a VPN Service Used by Ransomware Gangs
CyberSecurity News

Law Enforcement Dismantles VPNLab.net, a VPN Service Used by Ransomware Gangs

Key Takeaways An extensive international law enforcement operation, “Operation Saffron,” has successfully dismantled First VPN, a Virtual Private Network service explicitly designed and...

David kimber
David kimber
May 21, 2026 4 Min Read
73 0

Key Takeaways

  • An extensive international law enforcement operation, “Operation Saffron,” has successfully dismantled First VPN, a Virtual Private Network service explicitly designed and marketed for cybercriminals.
  • The coordinated action on May 19-20, 2026, resulted in the seizure of 33 servers across 27 countries, the shutdown of key domains, and the identification of thousands of users.
  • Investigators gained covert access to First VPN’s infrastructure, intercepting live traffic from criminals who believed their activities were anonymous.
  • The takedown significantly disrupts global cybercrime operations, including ransomware, hacking, and fraud, by removing a critical anonymity layer.

A multi-national law enforcement initiative spanning seven countries has effectively shut down First VPN, a virtual private network service widely exploited by cybercriminals across the globe. This decisive action, executed between May 19 and 20, 2026, marks a significant blow to the infrastructure supporting illicit online activities.

Table Of Content

  • Key Takeaways
  • “First VPN” Taken Down
  • Operation Saffron Outcomes
  • What You Should Do

Dubbed “Operation Saffron,” the collaborative effort was spearheaded by French and Dutch authorities, receiving crucial backing from Europol and Eurojust. The operation culminated in the confiscation of 33 servers, the decommissioning of numerous associated domains, and the successful identification of thousands of individuals utilizing the service for criminal purposes.

First VPN, predominantly operating through domains such as 1vpns.com, 1vpns.net, and 1vpns.org, alongside their corresponding onion sites, distinguished itself from conventional VPN providers. Unlike services catering to general privacy concerns, First VPN specifically targeted the cybercriminal underworld, actively promoting its services on prominent underground and Russian-speaking cybercrime forums.

The platform brazenly assured its clientele complete non-cooperation with judicial bodies, a strict no-logging policy for user data, and immunity from any jurisdictional claims. These promises, however, were later definitively disproven by investigators.

“First VPN” Taken Down

According to Europol, First VPN emerged as a recurring element in nearly every major cybercrime investigation supported by the agency. It played a pivotal role in facilitating ransomware attacks, enabling system compromises, orchestrating fraud schemes, and compromising accounts on an international scale.

The service offered anonymous payment options and a hidden infrastructure, meticulously designed to support criminal endeavors. This made it a highly trusted resource for threat actors seeking to evade detection by law enforcement agencies.

The investigation originated in May 2022 when Eurojust formally opened a file at the request of French authorities, following the identification of First VPN on known criminal forums. By November 2023, a Joint Investigation Team (JIT) was formally established, allowing French and Dutch investigators to consolidate evidence, share intelligence, and align on a unified prosecutorial approach.

As the scope of the investigation broadened, additional countries joined the effort. This led to the execution of multiple European Investigation Orders (EIOs) and Mutual Legal Assistance (MLA) requests, all meticulously coordinated through Eurojust.

A critical breakthrough in the operation involved investigators gaining covert access to First VPN’s infrastructure before its eventual shutdown. This enabled the interception of live criminal traffic from users operating under the false premise that their activities were fully encrypted and anonymous.

An Operational Taskforce (OTF) was subsequently established at Europol, bringing together investigators from 16 nations to analyze the vast amounts of seized data. This task force generated 83 intelligence packages, which were then disseminated to ongoing international investigations. Furthermore, 506 specific users were identified, and their data was shared with partner agencies globally.

Operation Saffron Outcomes

The coordinated action on May 19-20 yielded several critical outcomes:

  • Thirty-three servers located across 27 countries were seized and rendered inoperable.
  • The primary domains 1vpns.com, 1vpns.net, 1vpns.org, and their associated onion sites were permanently shut down.
  • The alleged administrator of First VPN was questioned in Ukraine at the behest of French authorities.
  • Sixty-five IP addresses linked to the service were publicly identified and disclosed.
  • All identified users were formally notified of the service’s shutdown and informed that their activities had been flagged by law enforcement.

Participating jurisdictions in the operation included France, the Netherlands, Luxembourg, Romania, Switzerland, Ukraine, and the United Kingdom, with supplementary support from Spain, Sweden, Canada, Germany, and the United States.

This takedown sends a unequivocal message to providers of criminal infrastructure. As Europol stated, “Taking it offline removes a critical layer of protection that criminals depended on to operate, communicate, and evade law enforcement.”

What You Should Do

  • Organizations should review their network traffic for any connections to the now-identified IP addresses or domains associated with First VPN.
  • Security teams should enhance monitoring for unusual activity that might indicate threat actors adapting to the loss of this criminal infrastructure.
  • Law enforcement agencies and intelligence partners should continue to leverage the intelligence packages and user data derived from this operation to pursue further investigations and arrests.
  • Individuals and organizations should prioritize legitimate, reputable VPN services that adhere to stringent privacy standards and legal compliance, rather than those advertising anonymity for illicit purposes.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackransomwareThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical antv npm Vulnerability Steals CI/CD Credentials

Next Post

Critical Chrome RCE Flaws Patched

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Windows WalletService Bug (CVE-2024-XXXX) Lets Attackers Escalate Privileges
August 10, 2026
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us