An international law enforcement operation has taken down First VPN, a virtual private network service authorities say was widely used by cybercriminal groups, including ransomware gangs.
The FBI said in an alert that at least 25 ransomware groups used First VPN to conceal malicious activity. Authorities also accused users of relying on the service to scan the internet, run botnets, carry out distributed denial-of-service attacks, and support scams. The bureau said First VPN operated servers in 27 countries, a detail that has not been independently verified.
Europol said the service was not just a privacy tool misused by criminals, but a platform marketed around features useful to cybercrime. According to the agency, First VPN offered anonymous connections, anonymous payments, hidden infrastructure, and other services aimed at criminal hackers.
Why Authorities Targeted First VPN
The takedown centers on the role First VPN allegedly played inside the cybercrime economy. Europol said the service had appeared in major cybercrime investigations supported by the agency in recent years, with criminals using it to hide identities and infrastructure during ransomware attacks, fraud campaigns, data theft, and other offenses.
Authorities said First VPN advertised on cybercrime forums, including Russian-language marketplaces, and promoted itself as a way for users to avoid being identified. In one forum post reviewed by TechCrunch, the service claimed that it did not keep logs that would allow an IP address from a specific period to be linked to a customer. The post said First VPN stored only an email address and username, while claiming online activity could not be tied back to a specific user.
That claim now appears to be a central part of the case. Europol said First VPN users were notified after the shutdown and told they had been identified. Investigators said they obtained the service’s user database and identified VPN connections, exposing thousands of users tied to the cybercrime ecosystem.
What Investigators Say They Seized
Europol said First VPN’s administrator was arrested, dozens of servers were dismantled, and the service’s infrastructure was disrupted. The agency said the investigation began in December 2021, making the shutdown the result of a multi-year inquiry rather than a sudden enforcement action.
The operation fits a broader law enforcement pattern: targeting not only ransomware groups themselves, but also the infrastructure providers that help those groups operate. VPNs can be legitimate privacy tools, especially for people securing traffic on public networks or protecting sensitive work. Authorities in this case framed First VPN differently, saying it was embedded in criminal activity and promoted to users who wanted to hide attacks and fraud.
The distinction matters because VPN technology itself is not the allegation. The issue is how First VPN was allegedly positioned, sold, and used. Investigators described a service designed to support anonymity for cybercriminal operations, with payments and infrastructure meant to make attribution harder.
Why the Shutdown Matters
For ransomware crews, services that obscure location and identity can be as important as malware. They help attackers stage infrastructure, probe targets, manage stolen data, and communicate without exposing the systems or accounts behind an operation. Removing one widely used provider can disrupt active campaigns and give investigators new leads from seized records.
The most striking part of the announcement is Europol’s claim that users were identified after the shutdown. First VPN had reportedly promised that it could not connect user activity to specific customers. Investigators say they were able to do exactly that by obtaining the user database and analyzing VPN connections.
That does not mean every person who used the service will face charges. Law enforcement notices can be used to warn, gather intelligence, or pressure criminal networks. But the message from authorities is clear: infrastructure marketed as anonymous can still become evidence if investigators gain access to servers, databases, payment trails, or operational records.
The shutdown also signals continued pressure on the support services around ransomware. Even when the people launching attacks are difficult to reach, police can still pursue administrators, hosting providers, forums, payment systems, and anonymity services that make those attacks easier to run.
