U.S. and Allies Sanction Cybercriminals and Russian State-Linked Hackers for Ransomware, Espionage, and Infrastructure Attacks
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has sanctioned two individuals and a VPN provider for facilitating ransomware attacks and other cybercriminal activities targeting Americans. First VPN Service (1VPNS), a VPN provider operational since 2014, was dismantled in May 2026 after a joint law enforcement operation by European and North American authorities. The service, along with its Ukrainian administrator Dmytro Rashevskyi (45), was accused of enabling ransomware groups to obscure attack origins, deploy malware, and exfiltrate data all while refusing to log user activity or cooperate with law enforcement.
Rashevskyi allegedly used aliases, including "Maksim Sorin" and "Roman Chabanenko," to acquire infrastructure despite abuse complaints from internet service providers. A Belarusian national, Yegeniy Vladimirovich Silayev, was also sanctioned for selling cryptors that disguised ransomware as legitimate software to evade detection. Victims of attacks linked to 1VPNS included U.S. businesses, financial institutions, hospitals, and municipal governments, with officials estimating billions in losses to American entities.
The sanctions coincide with U.K. and E.U. actions targeting Russian cyber networks for "persistent and reckless" operations aimed at destabilizing Europe. The measures include 24 individuals and entities tied to destructive cyber and hybrid threats, including senior members of Russia’s Main Intelligence Directorate (GRU) Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for directing cyber operations. The FSB’s Centre 16 was also implicated in sabotage attacks on Poland’s energy grid in late 2025.
Additionally, the sanctions address Lumma Stealer, a malware tool used to harvest sensitive data at scale, which Russia has allegedly leveraged for cyber espionage. The E.U. condemned Russia’s misuse of cybercriminals, hacktivists, and private firms to conduct disruptive attacks on critical infrastructure, public services, and financial systems.
Separately, the FBI issued an advisory warning of FSB Centre 16 actors exploiting poorly configured networking devices, particularly routers, to infiltrate critical infrastructure. The group scans for vulnerable devices using SNMP (Simple Network Management Protocol) with default credentials, then exfiltrates configurations to attacker-controlled servers. They also exploit known vulnerabilities in Cisco devices, including CVE-2018-0171 and CVE-2008-4128, the latter added to CISA’s Known Exploited Vulnerabilities (KEV) catalog with a federal patch deadline of July 16, 2026.
The threat actors, tracked under names like Berserk Bear, Dragonfly, and Energetic Bear, have targeted sectors including defense, energy, healthcare, and government facilities. Cisco previously warned of active exploitation of CVE-2018-0171 in August 2025, urging immediate patching. The NSA confirmed the campaign’s ongoing impact across U.S. and international networks.
Source: https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html
U.S. Department of the Treasury cybersecurity rating report: https://www.rankiteo.com/company/us-treasury
Cisco Talos cybersecurity rating report: https://www.rankiteo.com/company/cisco-talos-intelligence-group
"id": "US-CIS1784060682",
"linkid": "us-treasury, cisco-talos-intelligence-group",
"type": "Ransomware",
"date": "5/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'United States',
'name': 'U.S. businesses',
'type': 'Business'},
{'industry': 'Finance',
'location': 'United States',
'name': 'Financial institutions',
'type': 'Financial'},
{'industry': 'Healthcare',
'location': 'United States',
'name': 'Hospitals',
'type': 'Healthcare'},
{'industry': 'Public Sector',
'location': 'United States',
'name': 'Municipal governments',
'type': 'Government'},
{'industry': 'Energy',
'location': 'Poland',
'name': 'Poland’s energy grid',
'type': 'Critical Infrastructure'},
{'industry': 'Defense',
'name': 'Defense sector',
'type': 'Government'},
{'industry': 'Energy',
'name': 'Energy sector',
'type': 'Critical Infrastructure'},
{'industry': 'Healthcare',
'name': 'Healthcare sector',
'type': 'Healthcare'},
{'industry': 'Public Sector',
'name': 'Government facilities',
'type': 'Government'}],
'attack_vector': ['VPN Abuse',
'Exploiting Vulnerable Networking Devices (SNMP, Cisco '
'Vulnerabilities)',
'Malware (Lumma Stealer)',
'Cryptors'],
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Sensitive Data',
'Personally Identifiable '
'Information']},
'date_resolved': '2026-05',
'description': 'The U.S. Treasury Department’s Office of Foreign Assets '
'Control (OFAC) sanctioned two individuals and a VPN provider '
'for facilitating ransomware attacks and other cybercriminal '
'activities. 1VPNS, a VPN provider, was dismantled in May 2026 '
'for enabling ransomware groups to obscure attack origins, '
'deploy malware, and exfiltrate data. The sanctions also '
'targeted Russian cyber networks, including GRU and FSB '
'members, for disruptive cyber operations against critical '
'infrastructure in Europe and the U.S. Additionally, the FBI '
'warned of FSB Centre 16 actors exploiting vulnerable '
'networking devices to infiltrate critical infrastructure.',
'impact': {'data_compromised': True,
'financial_loss': 'Billions (estimated for American entities)',
'identity_theft_risk': True,
'operational_impact': 'Disruption of critical infrastructure and '
'public services',
'systems_affected': ['Critical Infrastructure',
'Financial Institutions',
'Hospitals',
'Municipal Governments',
'Defense',
'Energy',
'Healthcare',
'Government Facilities']},
'initial_access_broker': {'entry_point': ['VPN (1VPNS)',
'Exploiting vulnerable networking '
'devices'],
'high_value_targets': ['Critical Infrastructure',
'Government Facilities',
'Financial Institutions']},
'investigation_status': 'Ongoing',
'motivation': ['Financial Gain',
'Cyber Espionage',
'Destabilization',
'Sabotage'],
'post_incident_analysis': {'corrective_actions': ['Sanctions on threat actors',
'Dismantling of 1VPNS',
'Patching vulnerabilities',
'Enhanced monitoring'],
'root_causes': ['Unpatched vulnerabilities '
'(CVE-2018-0171, CVE-2008-4128)',
'Use of uncooperative VPN '
'providers',
'Exploitation of default SNMP '
'credentials']},
'ransomware': {'data_encryption': True, 'data_exfiltration': True},
'recommendations': ['Immediate patching of known vulnerabilities '
'(CVE-2018-0171, CVE-2008-4128)',
'Enhanced monitoring of networking devices',
'Cooperation with law enforcement',
'Avoiding use of uncooperative VPN providers'],
'references': [{'source': 'U.S. Treasury Department’s Office of Foreign '
'Assets Control (OFAC)'},
{'source': 'FBI Advisory'},
{'source': 'CISA Known Exploited Vulnerabilities (KEV) '
'Catalog'},
{'source': 'Cisco Security Advisory'}],
'regulatory_compliance': {'legal_actions': ['Sanctions'],
'regulatory_notifications': True},
'response': {'communication_strategy': ['FBI advisory',
'Regulatory notifications'],
'containment_measures': ['Dismantling of 1VPNS', 'Sanctions'],
'enhanced_monitoring': True,
'law_enforcement_notified': True,
'remediation_measures': ['Patching vulnerabilities '
'(CVE-2018-0171, CVE-2008-4128)',
'Enhanced monitoring of networking '
'devices'],
'third_party_assistance': True},
'stakeholder_advisories': ['FBI advisory on FSB Centre 16 exploitation of '
'networking devices'],
'threat_actor': ['GRU (Main Intelligence Directorate)',
'FSB Centre 16',
'Dmytro Rashevskyi',
'Yegeniy Vladimirovich Silayev',
'Berserk Bear',
'Dragonfly',
'Energetic Bear'],
'title': 'U.S. and Allies Sanction Cybercriminals and Russian State-Linked '
'Hackers for Ransomware, Espionage, and Infrastructure Attacks',
'type': ['Ransomware',
'Espionage',
'Infrastructure Attack',
'Data Exfiltration',
'Malware'],
'vulnerability_exploited': ['CVE-2018-0171', 'CVE-2008-4128']}