Law Enforcement Dismantles VPNLab.net, a VPN Service Used by Ransomware Gangs
Key Takeaways An extensive international law enforcement operation, “Operation Saffron,” has successfully dismantled First VPN, a Virtual Private Network service explicitly designed and...
Key Takeaways
- An extensive international law enforcement operation, “Operation Saffron,” has successfully dismantled First VPN, a Virtual Private Network service explicitly designed and marketed for cybercriminals.
- The coordinated action on May 19-20, 2026, resulted in the seizure of 33 servers across 27 countries, the shutdown of key domains, and the identification of thousands of users.
- Investigators gained covert access to First VPN’s infrastructure, intercepting live traffic from criminals who believed their activities were anonymous.
- The takedown significantly disrupts global cybercrime operations, including ransomware, hacking, and fraud, by removing a critical anonymity layer.
A multi-national law enforcement initiative spanning seven countries has effectively shut down First VPN, a virtual private network service widely exploited by cybercriminals across the globe. This decisive action, executed between May 19 and 20, 2026, marks a significant blow to the infrastructure supporting illicit online activities.
Table Of Content
Dubbed “Operation Saffron,” the collaborative effort was spearheaded by French and Dutch authorities, receiving crucial backing from Europol and Eurojust. The operation culminated in the confiscation of 33 servers, the decommissioning of numerous associated domains, and the successful identification of thousands of individuals utilizing the service for criminal purposes.
First VPN, predominantly operating through domains such as 1vpns.com, 1vpns.net, and 1vpns.org, alongside their corresponding onion sites, distinguished itself from conventional VPN providers. Unlike services catering to general privacy concerns, First VPN specifically targeted the cybercriminal underworld, actively promoting its services on prominent underground and Russian-speaking cybercrime forums.
The platform brazenly assured its clientele complete non-cooperation with judicial bodies, a strict no-logging policy for user data, and immunity from any jurisdictional claims. These promises, however, were later definitively disproven by investigators.
“First VPN” Taken Down
According to Europol, First VPN emerged as a recurring element in nearly every major cybercrime investigation supported by the agency. It played a pivotal role in facilitating ransomware attacks, enabling system compromises, orchestrating fraud schemes, and compromising accounts on an international scale.
The service offered anonymous payment options and a hidden infrastructure, meticulously designed to support criminal endeavors. This made it a highly trusted resource for threat actors seeking to evade detection by law enforcement agencies.
The investigation originated in May 2022 when Eurojust formally opened a file at the request of French authorities, following the identification of First VPN on known criminal forums. By November 2023, a Joint Investigation Team (JIT) was formally established, allowing French and Dutch investigators to consolidate evidence, share intelligence, and align on a unified prosecutorial approach.
As the scope of the investigation broadened, additional countries joined the effort. This led to the execution of multiple European Investigation Orders (EIOs) and Mutual Legal Assistance (MLA) requests, all meticulously coordinated through Eurojust.
A critical breakthrough in the operation involved investigators gaining covert access to First VPN’s infrastructure before its eventual shutdown. This enabled the interception of live criminal traffic from users operating under the false premise that their activities were fully encrypted and anonymous.
An Operational Taskforce (OTF) was subsequently established at Europol, bringing together investigators from 16 nations to analyze the vast amounts of seized data. This task force generated 83 intelligence packages, which were then disseminated to ongoing international investigations. Furthermore, 506 specific users were identified, and their data was shared with partner agencies globally.
Operation Saffron Outcomes
The coordinated action on May 19-20 yielded several critical outcomes:
- Thirty-three servers located across 27 countries were seized and rendered inoperable.
- The primary domains 1vpns.com, 1vpns.net, 1vpns.org, and their associated onion sites were permanently shut down.
- The alleged administrator of First VPN was questioned in Ukraine at the behest of French authorities.
- Sixty-five IP addresses linked to the service were publicly identified and disclosed.
- All identified users were formally notified of the service’s shutdown and informed that their activities had been flagged by law enforcement.
Participating jurisdictions in the operation included France, the Netherlands, Luxembourg, Romania, Switzerland, Ukraine, and the United Kingdom, with supplementary support from Spain, Sweden, Canada, Germany, and the United States.
This takedown sends a unequivocal message to providers of criminal infrastructure. As Europol stated, “Taking it offline removes a critical layer of protection that criminals depended on to operate, communicate, and evade law enforcement.”
What You Should Do
- Organizations should review their network traffic for any connections to the now-identified IP addresses or domains associated with First VPN.
- Security teams should enhance monitoring for unusual activity that might indicate threat actors adapting to the loss of this criminal infrastructure.
- Law enforcement agencies and intelligence partners should continue to leverage the intelligence packages and user data derived from this operation to pursue further investigations and arrests.
- Individuals and organizations should prioritize legitimate, reputable VPN services that adhere to stringent privacy standards and legal compliance, rather than those advertising anonymity for illicit purposes.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.