The U.S. Treasury sanctioned a VPN provider and two individuals it said supplied tools and infrastructure used in ransomware attacks affecting U.S. hospitals, financial firms and local governments. The action is part of a broader federal effort to disrupt the cybercriminal ecosystem.
The U.S. Treasury Department sanctioned a VPN provider and two individuals on July 13, saying they supplied infrastructure and tools used in ransomware attacks that have affected U.S. hospitals, financial services firms and municipal governments.
The Treasury’s Office of Foreign Assets Control designated First VPN Service, also known as 1VPNS, along with its administrator, Dmytro Rashevskyi. The office also designated Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors, which are tools that disguise malware from security systems.
According to the Treasury, ransomware groups using 1VPNS infrastructure count hospitals among their victims. The office said the activity is part of a broader pattern of attacks that have cost U.S. businesses and critical infrastructure providers billions of dollars.
Gene Lange, who is performing the duties of undersecretary for terrorism and financial intelligence, said in a news release that the department is using every available tool to disrupt the cybercriminal ecosystem and protect the American people. The quote was included as part of the Treasury announcement.
The action comes after a May 2026 takedown of 1VPNS’s website and infrastructure by European law enforcement. That effort was supported by the FBI’s Boston Field Office, according to the source material.
The Treasury said the sanctions are also coordinated with the United Kingdom’s Foreign, Commonwealth & Development Office, which is sanctioning related actors the same day. No further details about those related actors were provided in the source.
The designations stem from President Donald Trump’s March 6 executive order on combating cybercrime and cyber-enabled fraud against Americans. The source did not provide additional details about the executive order beyond that description.
As a result of the sanctions, all property and interests of the designated individuals and entity within U.S. jurisdiction are blocked. U.S. persons are also barred from transactions involving them. The source did not describe any exceptions or licenses related to the restrictions.
Treasury’s action adds to a growing federal effort to target the infrastructure providers that help ransomware groups operate. The source said these groups have repeatedly disrupted hospital operations and patient care nationwide.
Hospitals have become a recurring target in these attacks, according to the Treasury. The sanctions announcement said the criminal activity has also hit financial services firms and municipal governments, underscoring the broader impact on critical services and public institutions.
The Treasury did not identify specific hospital systems, financial firms or municipalities that were affected by the ransomware activity described in the announcement. It also did not provide details on the individual attacks linked to 1VPNS infrastructure.
The designation of a VPN provider reflects the government’s focus on the enabling infrastructure behind ransomware operations, not just the groups carrying out the attacks. In this case, the Treasury said the infrastructure and tools supported attacks that reached multiple sectors, including health care.
Silayev was described as selling cryptors that help disguise malware from security tools. The source did not say how long he had been involved in that activity or whether any specific ransomware group was named in connection with him.
Likewise, the Treasury announcement identified Rashevskyi as the administrator of First VPN Service, but no additional biographical details were included in the source. The post did not report comments from either designated individual or from First VPN Service.
The July 13 move marks another step in the federal response to ransomware-related infrastructure. According to the source, the action is part of a broader effort to disrupt the ecosystem supporting attacks on hospitals and other critical entities.
The source also noted that the same day the United Kingdom was sanctioning related actors. No further explanation of those actions was included.
For health care organizations, the announcement highlights how ransomware threats can extend beyond the attackers themselves to the services and tools that support them. The Treasury’s statement focused on those enabling services and said they have been used in attacks involving hospitals among other victims.
The source did not report any changes to hospital guidance, cybersecurity recommendations or operational steps tied to the sanctions announcement. It also did not describe any immediate effect on patient care or hospital security operations.
The Treasury’s action follows the May 2026 takedown of 1VPNS’s website and infrastructure and reflects continued pressure from U.S. and allied authorities on cybercrime networks. Based on the information provided, the sanctions are intended to block property and transactions involving the designated parties within U.S. jurisdiction and to further limit ransomware support infrastructure used against U.S. targets.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.
Personalise this feed
Your specialty. Your sources. Your digest.
All set up in under 2 minutes.