ThreatPaper
Darknet & Illicit MarketsRansomwareHigh

Operation Saffron: Europol dismantles First VPN, the bulletproof anonymity layer behind years of ransomware cases

By Sethu Satheesh · 25 Sept 2026 · 10 min read

Threat Actor: First VPN / 1VPN (bulletproof anonymity service; alleged administrator in Ukraine, searched and interviewed, not charged) · Target: The First VPN criminal anonymity service and its clientele (25+ ransomware groups incl. Avaddon and Phobos, plus fraud and credential-theft operators)

Source: www.eurojust.europa.eu


Executive Summary

On May 19–20, 2026, a Europol- and Eurojust-coordinated operation named Operation Saffron dismantled First VPN (also branded "1VPN"), a bulletproof anonymity service that had operated since 2014 and had become, in Eurojust's words, a service that "appeared in almost every major cybercrime investigation supported by" Europol.12 Investigators seized more than 33 servers, took down the service's domains — 1vpns.com, 1vpns.net, 1vpns.org and associated onion addresses — and searched and interviewed the service's alleged administrator in Ukraine.13 France and the Netherlands led the investigation, with a Joint Investigation Team formed in November 2023 and support from Eurojust, Europol, and private-sector partner Bitdefender.14

First VPN was not a privacy tool that criminals happened to use; it was marketed for crime. It advertised that it would not cooperate with any judicial authority and would not be subject to any jurisdiction, and it was promoted on Russian-speaking cybercrime forums as a way to remain "beyond the reach of law enforcement," offering anonymous payments, hidden infrastructure, and features designed specifically for illegal use.2 According to the reporting on Europol's briefing, the service was used by at least 25 ransomware groups — Avaddon and Phobos among them — as well as for fraud campaigns, credential theft and other offenses.32

The most consequential detail is not the seizure but what preceded it: investigators infiltrated First VPN's infrastructure before it went offline and collected traffic data, and the operation reportedly identified roughly 506 users linked to criminal activity.2 For a service whose entire value proposition was that it kept no useful records and answered to no court, being read from the inside is the outcome that matters — the takedown converted an anonymity layer into a source of attribution leads against the criminals who trusted it.

Two figures that appear in the coverage need care, and this paper treats them as claims. First, the widely repeated "27 countries" refers to where the 33 seized servers were physically located, not to the number of countries running the operation — Eurojust cites a 7-country investigating group and a 16-country Europol operational taskforce.12 Second, the Ukrainian suspect was searched and interviewed; the primary sources do not describe a formal arrest or charge, even though some coverage frames it as one.13 The operation is a genuine, significant takedown of long-lived criminal infrastructure; it is also a case where the round numbers and the word "arrest" outran the primary record.

Verification of Claims

  1. Claim: Operation Saffron dismantled First VPN, a bulletproof VPN used by cybercriminals. → Verified → Confirmed by Eurojust's own release: a coordinated investigation shut down the criminal VPN network on May 19–20, 2026, seizing 33+ servers and the service's domains.1 The operation name and criminal-service framing are corroborated across reporting.24

  2. Claim: A suspected administrator was arrested. → False / imprecise → Eurojust and CyberInsider describe the Ukrainian suspect as searched at their residence and interviewed as the alleged administrator; neither the primary release nor the corroborating reporting states a formal arrest or charge.13 Coverage that says "arrest" overstates what the sources describe.

  3. Claim: The operation spanned 27 countries. → Assessed / imprecise → The 27-country figure refers to where the 33 seized servers were hosted, not the countries conducting the operation. Eurojust cites 7 countries in the investigating group and a 16-country Europol operational taskforce.12

  4. Claim: First VPN was used by at least 25 ransomware groups and identified ~506 users. → Reported (law-enforcement-sourced) → Both figures come from reporting on Europol's briefing — 25+ ransomware groups (including Avaddon and Phobos) and roughly 506 users unmasked after investigators infiltrated the infrastructure.2 They are law-enforcement-attributed counts, not independently audited.

Timeline

Date Actor Event Source
2014 First VPN operators Service begins operating, later marketed on Russian-speaking cybercrime forums as bulletproof anonymity 2
2021–2022 French / Dutch authorities Investigation into First VPN begins (sources vary between December 2021 and 2022) 13
November 2023 France, Netherlands, partners Joint Investigation Team established under Eurojust 1
Before takedown Investigators Infrastructure infiltrated and traffic data collected; ~506 users linked to criminal activity identified 2
May 19–20, 2026 Europol / Eurojust / national authorities Operation Saffron: 33+ servers seized, domains taken down, Ukrainian alleged administrator searched and interviewed 13
May 21, 2026 Press Takedown reported publicly 32

Operation Anatomy

The service being taken down

First VPN was a "bulletproof" anonymity service: infrastructure explicitly sold to criminals on the promise of non-cooperation with law enforcement and immunity from jurisdiction, with anonymous payment and hidden infrastructure (T1665, T1090.003).2 Its clientele reportedly included at least 25 ransomware groups (Avaddon, Phobos), plus fraud and credential-theft operators — the reason Eurojust says it turned up in nearly every major Europol cybercrime case.32 The service ran on 33+ servers spread across 27 countries (T1583.003).12

The investigation

French and Dutch authorities opened the investigation in 2021–2022 and, in November 2023, formalized a Joint Investigation Team under Eurojust, which hosted coordination meetings and, with Europol, ran a multi-country operational taskforce; private-sector partner Bitdefender assisted.14 Crucially, investigators infiltrated First VPN's own infrastructure before the takedown and collected traffic data — the step that turned a bulletproof service into an attribution source, reportedly unmasking around 506 users.2

The takedown

On May 19–20, 2026, authorities seized more than 33 servers, took down the primary domains (1vpns.com/.net/.org) and associated onion addresses, and searched the residence of, and interviewed, the alleged administrator in Ukraine.13 The seized user data now feeds downstream investigations against the service's criminal customers.2

Loading diagram...

Threat Actor Profile

This paper documents a law-enforcement operation, so the "actor" is the criminal service that was taken down and its clientele, not a hostile operator being profiled.

  • Service: First VPN / 1VPN — a bulletproof anonymity provider operating since 2014, marketed for criminal use on Russian-speaking forums (non-cooperation with courts, anonymous payment, hidden infrastructure).2
  • Clientele: At least 25 ransomware groups, including Avaddon and Phobos, plus fraud and credential-theft operators.32
  • Alleged administrator: A suspect in Ukraine, searched and interviewed; not described as arrested or charged in the primary sources.13
  • Investigating and coordinating bodies: France and the Netherlands (lead), Eurojust and Europol (coordination), with a Joint Investigation Team (Nov 2023) and support from Bitdefender.14

MITRE ATT&CK techniques (describing how the seized service was used by its criminal customers; verified on attack.mitre.org):

ID Technique
T1665 Hide Infrastructure
T1090.003 Proxy: Multi-hop Proxy
T1583.003 Acquire Infrastructure: Virtual Private Server

Technical Indicators

# This is a law-enforcement takedown of a criminal anonymity service. The
# "indicators" are the seized service's own domains and infrastructure, now
# under law-enforcement control, not defender-actionable malware IOCs.
service_names:
  - "First VPN"
  - "1VPN"
seized_domains:
  - "1vpns[.]com"
  - "1vpns[.]net"
  - "1vpns[.]org"
  - "associated .onion domains"
infrastructure:
  - "33+ servers seized, hosted across 27 countries"
operational_since: 2014
clientele_reported:
  - "25+ ransomware groups (incl. Avaddon, Phobos)"
  - "fraud campaigns, credential theft, other cybercrime"
users_identified: "~506 (per law-enforcement briefing, after infrastructure infiltration)"
network_iocs: "seized service domains listed above; no malware IOCs apply"
file_hashes: none

Operation Saffron is itself the legal-and-regulatory response: a Europol/Eurojust-coordinated, multi-country action taken May 19–20, 2026 under a Joint Investigation Team established in November 2023, led by French and Dutch authorities with a Europol operational taskforce and Bitdefender support.14 Actions taken: seizure of 33+ servers, takedown of the service's clearnet and onion domains, and the search and interview of the alleged administrator in Ukraine.13 No formal arrest or charge is described in the primary release; the significant downstream consequence is that investigators hold user data — reportedly ~506 identified users — to pursue the service's criminal customers.2

Impact Assessment

  • Confirmed: First VPN dismantled; 33+ servers seized; clearnet and onion domains taken down; alleged administrator searched and interviewed in Ukraine.13
  • Reported (law-enforcement-sourced): Service operating since 2014; used by 25+ ransomware groups (Avaddon, Phobos); ~506 users identified after infrastructure infiltration and traffic collection; servers spread across 27 countries.2
  • Assessed / imprecise in coverage: The "27 countries" describes server locations, not operation participants (7 investigating / 16 taskforce per Eurojust); the Ukrainian suspect was searched and interviewed, not (per the primary sources) arrested or charged.132
  • Unknown: Whether charges will follow the Ukrainian suspect; the full breakdown of the ~506 users and which will be prosecuted; and the exact investigation start date (sources vary between December 2021 and 2022).13

Lessons and Defensive Recommendations

For threat intelligence and IR teams:

  • Treat "bulletproof" criminal services as future intelligence sources, not permanent black boxes. Operation Saffron's key move was infiltrating First VPN and collecting traffic before the takedown — meaning the anonymity many ransomware and fraud actors relied on has, retroactively, become attribution. If your investigations touched infrastructure that used First VPN, the seized user data may generate new leads or corroborate existing attribution.
  • Ransomware-group tooling and infrastructure choices are shared and long-lived. A single anonymity provider serving 25+ groups since 2014 means the same operational chokepoint sat behind many unrelated intrusions; mapping which of your incidents traversed First VPN is worth doing now that the data is in law-enforcement hands.

For readers and journalists covering takedowns:

  • Country counts in takedown press coverage frequently conflate three different things: where the servers were hosted (27, here), how many countries investigated (7), and how many joined the operational taskforce (16). Cite which one you mean. Likewise, "arrest" is not the same as "searched and interviewed" — the primary Eurojust and reporting on this case describe the latter, and the distinction is legally and factually real.

For policy and platform teams:

  • The value the operation extracted came from lawful infiltration of the service's own infrastructure, not from any backdoor in encryption. The durable lesson is that criminal-service operators' own operational-security failures — reused infrastructure, retained data, a locatable administrator — remain the most reliable path to dismantling anonymity infrastructure, as they were here.

Sources

Footnotes

  1. Eurojust coordinated investigation shuts down criminal VPN network — Eurojust, May 2026 (primary) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21

  2. Europol's Operation Saffron takes down First VPN service over ransomware attacks — 33 'bulletproof' servers spread across 27 countries seized — Tom's Hardware, May 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21

  3. Europol dismantles 'First VPN' service used by ransomware gangs — CyberInsider, May 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15

  4. Operation Saffron: Bitdefender Joins "First VPN" Takedown — Bitdefender, May 2026 ↩ ↩2 ↩3 ↩4 ↩5

Topics: #operation-saffron#first-vpn#1vpn#europol#eurojust#bulletproof-hosting#ransomware-infrastructure#takedown
Original Incident Report →

Related Research

On 31 August 2026 investigators cut a 23-year-old peer-to-peer botnet off from its operator by poisoning the peer lists of its own bots. The protocol they exploited had been documented publicly since 2011 and could never be patched.

Botnet & DDoSMalware

LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.

RansomwareFinancial FraudBotnet & DDoS

A market that took only Monero ran for five years and €330 million. The playbook that broke Silk Road and AlphaBay did not apply — and the authorities who dismantled it have not said what did.

Darknet & Illicit MarketsCryptocurrency & Web3