Authorities in Europe have dismantled a major criminal VPN service, which ransomware operators and cybercriminal groups widely used to conceal their activities.
The coordinated operation, led by French and Dutch authorities with support from Eurojust and Europol, marks a significant disruption to cybercrime infrastructure spanning multiple countries.
The takedown occurred during a joint operation on May 19–20, 2026, resulting in the seizure of more than 33 servers linked to the illegal VPN service spread across 27 countries.
Law enforcement agencies also conducted a search and interview of a suspect in Ukraine, while authorities confirmed that critical infrastructure supporting global cybercriminal operations had been disrupted.
The first VPN was specifically marketed to cybercriminals, offering anonymity-focused services that enabled ransomware attacks, hacking campaigns, and data theft.
The service claimed it would not log user data, would not cooperate with law enforcement, and would not operate under any jurisdiction, making it highly attractive to threat actors seeking to evade detection.
According to Europol, First VPN appeared in nearly every major cybercrime investigation supported by the agency, highlighting its deep entrenchment within the criminal underground ecosystem.
The investigation began gathering momentum in December 2021 after French authorities repeatedly encountered the service in connection with crimes targeting French victims.
Eurojust formally opened a case in May 2022 after French authorities identified the VPN service being advertised on cybercriminal forums.
A Joint Investigation Team (JIT) was formally established in November 2023 through Eurojust, enabling close cooperation between France and the Netherlands.
Over time, the operation expanded to include law enforcement agencies from 16 countries, with authorities leveraging European Investigation Orders (EIOs) and Mutual Legal Assistance (MLA) requests to gather intelligence and access infrastructure before it was taken offline.
Critically, investigators successfully obtained live traffic data from users who believed their activities were fully anonymous, yielding 83 intelligence packages covering 506 identified users.
Eurojust facilitated 16 coordination meetings to align legal strategies and operational planning, while Europol established a dedicated task force to analyze seized data and support intelligence sharing among international partners.
As part of the takedown, authorities seized the domains 1vpns.com, 1vpns.net, 1vpns.org, and associated Tor-based onion domains.
Users of the service have been notified that they have been identified, signaling a wave of follow-up investigations and prosecutions across France, the Netherlands, Luxembourg, Romania, Switzerland, Ukraine, and the United Kingdom.
This operation underscores the critical role that bulletproof VPN services play in enabling ransomware and cybercrime at scale. By dismantling First VPN, authorities have removed a foundational layer of anonymity that major threat actor groups relied on.
For defenders, the case reinforces how international judicial cooperation and proactive intelligence sharing can effectively disrupt even long-established criminal infrastructure.
Organizations should remain vigilant, as threat actors are likely to migrate toward alternative anonymization services in the aftermath of this disruption.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.