The U.S. Treasury Department’s Office of Foreign Assets Control sanctioned a virtual private network provider for the first time over its role enabling ransomware attacks, alongside a separate seller of malware “cryptor” services, in designations announced July 13. The action names First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, who Treasury says used aliases to buy infrastructure while hiding the service’s purpose from providers. It also names Yegeniy Vladimirovich Silayev, a Belarusian national who Treasury says sold cryptors, tools that repackage ransomware and other malware so security software cannot detect or disable it, to operators that have targeted U.S. businesses, hospitals, financial institutions, and municipal governments.

The designations block any U.S.-based property tied to the parties and bar U.S. persons from transacting with them, with civil or criminal penalties for violations. Treasury issued the action under Executive Order 13694 as amended and the newer Executive Order 14390, signed March 6, 2026 to combat cybercrime and fraud against Americans. “We will continue targeting the actors who enable ransomware attacks against Americans and our critical infrastructure,” said Gene Lange, performing the duties of Under Secretary for Terrorism and Financial Intelligence.

The choice of target matters as much as the action itself. A single VPN provider or cryptor seller can service dozens of unrelated ransomware affiliates at once, so sanctioning the infrastructure layer aims at more of the ecosystem per designation than naming individual ransomware crews one at a time. It is also the latest in a run of enabler-focused actions this year: Treasury’s move follows the State Department’s $10 million bounty offer for hackers behind the Signal and WhatsApp compromise campaign, and a coordinated EU, UK, and U.S. sanctions package against Russia-linked FSB units that this publication covered last week. Taken together, the pattern points to Western governments converging on a strategy of sanctioning the shared infrastructure and services layer beneath both espionage and ransomware operations, not just the operators running individual campaigns.

Source: U.S. Department of the Treasury