Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

treasury+1webhosting+1techcrunch+1The U.S. Treasury Department on July 13 designated a virtual private network provider, its Ukrainian administrator, and a Belarusian malware tool seller for enabling ransomware attacks against American hospitals, schools, businesses, and local governments — marking the first time OFAC has formally sanctioned a VPN service for facilitating cybercrime. The action inadvertently triggered a global outage of Telegram's widely used t.me short-link domain.
The Treasury's Office of Foreign Assets Control designated First VPN Service (1VPNS), its 45-year-old administrator Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev under Executive Order 13694, as amended, for materially assisting cyber-enabled activities directed at U.S. persons. The State Department said the designated actors "supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers".treasury+1
Treasury alleged that Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold cryptors — tools that disguise ransomware as legitimate software to bypass security systems. Blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, according to TRM Labs. The action was coordinated with the United Kingdom.trmlabs+3
The sanctions follow Operation Saffron, a joint law enforcement effort led by France and the Netherlands with Europol, Eurojust, and FBI support that dismantled 1VPNS between May 19 and 20, arresting a suspected administrator and seizing 33 servers.cybernews+2
Hours after the sanctions were published, Telegram's t.me domain stopped resolving worldwide after the .me registry — a Montenegrin country-code domain administered by American companies — placed it under a "serverHold" status, removing it from global DNS. The hold cut access to every invite, group, channel, and bot link shared via t.me, affecting Telegram's roughly one billion users, though the messaging app itself continued to function.hackread+1
The .me registry operator confirmed it had suspended the domain "due to OFAC compliance requirements". TechCrunch reported on July 14 that the domain was restored after approximately one day offline. The connection between an anti-ransomware sanctions action and Telegram's short-link domain remains unclear, though some observers noted that sanctioned entities may have used t.me links in their operations.webhosting+3
The designation represents an escalation in the U.S. government's strategy of targeting ransomware enablers rather than solely the criminal groups themselves. By sanctioning infrastructure providers, Treasury aims to disrupt the ecosystem that allows ransomware operators to anonymize their activities and evade law enforcement. All property and interests of the designated parties within the United States or in the possession of U.S. persons are now blocked.trmlabs+1