惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
腾讯CDC
Jina AI
Jina AI
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
GbyAI
GbyAI
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
T
The Blog of Author Tim Ferriss
小众软件
小众软件
M
MIT News - Artificial intelligence
MyScale Blog
MyScale Blog
D
Docker
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
月光博客
月光博客
L
LangChain Blog
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky
C
Check Point Blog
U
Unit 42
人人都是产品经理
人人都是产品经理

Latest from TechRadar

Quordle hints and answers for Monday, April 13 (game #1540) NYT Strands hints and answers for Monday, April 13 (game #771) NYT Connections hints and answers for Monday, April 13 (game #1037) Morbid Metal developer explains why he ditched an origami art direction in favor of gritty sci-fi — 'It worked, but it didn't really feel like me' '71% of US households get routers from ISPs': Why new FCC rules could leave millions stuck with outdated,… 'The CPU is the system’s executive layer': Intel joins SambaNova as both face existential threat from… ‘More bang for your buck’: 7 easy ways to boost your MacBook Neo’s performance for free DJI Romo P vs Roborock Saros 10R — which robot vacuum comes out on top when it comes to dodging obstacles? I put… I spent 6 hours with Genshin Impact on the Galaxy S26 Ultra, and I can't believe how far mobile gaming has come What is the release date for The Testaments episode 4 on Hulu and Disney+? I reviewed the LG G6 for 3 weeks, and it's a fantastic OLED TV that's the new best option for brighter rooms Is your bird feeder camera doing more harm than good? 3 tips for using it safely as RSPB issues urgent disease warning Chelsea vs Man City Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news How to watch Alcaraz vs Sinner for FREE: TV Channels for Monte-Carlo Masters Final Sunderland vs Tottenham Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news Are these the best-designed workout headphones ever? I used them for a month to find out How to watch Snooker 900 John Virgo online (it's free) – stream O'Sullivan vs Higgins anywhere I've only just discovered the Walk With Frodo app on Garmin's Connect IQ store — and as as a huge LOTR nerd, it's going to make the next 1,800 miles fly by 'Just not sustainable': Why your monthly £25 broadband internet bill could soon hit £45 How to watch Paris-Roubaix 2026: Free Streams & TV Info as Tadej Pogacar chases third Monument How to watch Euphoria season 3 online – stream Zendaya & Sydney Sweeney drama from anywhere today '$15K bill destroyed a solo developer’s startup': How hackers are using leaked Google API keys to… There's a sneaky way to watch UFC 327 really cheap... NYT Connections hints and answers for Sunday, April 12 (game #1036) NYT Strands hints and answers for Sunday, April 12 (game #770) Quordle hints and answers for Sunday, April 12 (game #1539) Amazon's Ring cameras are the perfect solution to secure your home on a budget — shop today's best deals… I've tested every iPhone since the iPhone 12, and Ceramic Shield 2 is the first iPhone glass I fully trust UFC 327 live stream: how to watch Procházka vs Ulberg, start time, preview, full card We're officially getting the DJI Pocket 4 on April 16, but here's how Insta360 could beat it
FBI confirms 25 ransomware groups using First VPN’s now s...
Silvia Iacovcich · 2026-05-29 · via Latest from TechRadar

  • The FBI identified 25 hacking groups linked to First VPN's illegal activities
  • Avaddon Ransomware was included on the list
  • The FBI recommends stricter controls

At least 25 ransomware groups were actively using First VPN Service IP for criminal purposes at the time it was dismantled in a coordinated international operation led by European law enforcement forces, the Federal Bureau of Investigation (FBI) has confirmed.

Last week, 33 servers belonging to the free VPN service were taken offline, and its European domain was seized as part of "Operation Saffron," jointly led by European law enforcement agencies Europol and Eurojust.

In a report, the US intelligence agency detailed how First VPN facilitated cybercrime, with hackers using its service to carry out criminal web activity, including scams, botnets, and scanning. Among the 25 names listed is Avaddon Ransomware, a malware group that targeted various business sectors, notably striking the insurance giant AXA in 2021.

Launched in December 2021 and culminating in May, the success of Operation Saffron proved that, thanks to the monumental efforts of law enforcement agencies to tackle illegal activities, we can continue to enjoy the real benefits of the privacy that the best VPNs can offer.

Investigators managed to obtain the platform's user database and have already identified 506 specific users, with the data gathered already proving useful in 21 Europol ongoing cybercrime investigations — and we can only expect more to emerge soon.

How cybercriminals used First VPN

This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, "This service has been seized"

(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)

According to the FBI report, the VPN explicitly targeted cybercriminals by advertising directly in their circles on the dark web, including Russian-language online forums — Exploit[.]in and XSS[.]is — where cybercriminals trade stolen data and hacking tools.

There, the First VPN explicitly offered a secure environment for unlawful acts, offering no-log policies, global jurisdiction circumvention, and a refusal to cooperate with the authorities.

Specifically, users could use cryptocurrencies to purchase subscription services offering varying degrees of digital anonymity for periods ranging from one day to one year. To maximise user anonymity, First VPN provided 32 services spread across 27 countries from which users could select up to four 'nodes'.

The service even had its own technical support for criminals via Telegram and a self-hosted Jabber server.

As the malicious infrastructure was hosted in the cloud or virtualised, the IP addresses used for the ransomware were randomly reassigned to legitimate services, making it harder for investigating authorities to trace the source of the criminal activity.

By using techniques such as ‘password spraying’ and brute force attacks, hackers guessed passwords to access their victims’ environments, such as corporate desktops and apps, from where they were able to scan the networks to identify the devices, servers, and users connected to them.

By routing their attacks through the First VPN’s available exit nodes, their attacks appeared to originate from a legitimate and trustworthy source.

Cybercriminals also exploited the infrastructure to launch denial-of-service (DDoS) attacks, flooding victims’ networks with traffic to overwhelm the victim and render their systems inoperable — a technique often used to prevent the detection of a more serious attack in progress.

How to be safe

The FBI has published detailed recommendations for organisations, calling for the implementation of multi-layered security controls, combined network restrictions, identity-based protections, and behavioural monitoring to prevent ransomware attacks, data breaches, and unauthorised network access.

It recommends blocking and monitoring First VPN’s infrastructure, and continuously monitoring unauthorized VPN connections or IP addresses associated with anonymisation services.

Crucially, multi-factor authentication (MFA) should be implemented for all remote access services and cloud-based applications to limit authentication attempts originating from unknown areas or IP addresses.