DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // OPERATION-SAFFRON-FIRSTVPNFIRST SEEN: 2014

FIRST VPN CRIMINAL NETWORK (Operation Saffron Takedown)

ALSO KNOWN AS: 1VPN, 1vpns.com
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Ukraine / Russia (administrator interviewed in Ukraine; service promoted on Russian-speaking cybercrime forums)
ATTRIBUTION:ORGANIZED CRIME
STATUS:DORMANT
FIRST OBSERVED:2014
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL37/100
RESOURCES37/100
PERSISTENCE40/100
STEALTH32/100
IMPACT46/100

First VPN — a criminal VPN service operating since 2014 and marketed exclusively on Russian-speaking cybercrime forums — was dismantled May 19–20, 2026 in Operation Saffron, led by French and Dutch authorities with Europol and Eurojust support. The service had over 5,000 accounts, was linked to at least 25 ransomware groups including the Phobos RaaS outfit, and facilitated more than $70M in illicit proceeds laundering. Law enforcement seized 33 servers across 27 countries, shut down domains including 1vpns.com and associated .onion addresses, and generated 83 intelligence packages covering 506 users shared with partner countries. All users were notified their identities are now known to authorities. This represents a significant blow to the anonymization layer of the ransomware supply chain.

Anonymization-as-a-service for ransomware operators, data thieves, and fraud actors; financially motivated infrastructure provider enabling cybercriminal ecosystem anonymity

Anonymization-as-a-service for ransomware C2 and exfiltration routing; tiered connection relay pricing for criminal clients; no-log / no-cooperation policy marketed to criminal buyers; infrastructure spanning 27 countries; T1090 Proxy, T1572 Protocol Tunneling

RANSOMWARE OPERATORS
FRAUD ACTORS
CYBERCRIME ECOSYSTEM INFRASTRUCTURE USERS

33 servers across 27 countries (all seized); domains: 1vpns.com, 1vpns.net, 1vpns.org, and associated .onion domains (all shut down May 19–20, 2026); service operational since 2014; administrator based in Ukraine

FILE DATE: MAY 2026
Operation Saffron — International Takedown
French and Dutch authorities with Europol/Eurojust seized 33 servers, shut down all First VPN domains, and exposed 5,000+ criminal user accounts on May 19–20, 2026; intelligence packages linked to Phobos RaaS and multiple other ransomware investigations.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn