The Docket: Treasury Just Named the Ransomware Supply Chain

Treasury's First VPN sanctions show ransomware enforcement is moving upstream to infrastructure, evasion tools, and evidence trails.

The Docket: Treasury Just Named the Ransomware Supply Chain

Ransomware does not arrive only as malware. It arrives through rented infrastructure, masked traffic, criminal marketplaces, and evasion tools that help attackers reach victims without standing in the open.

Treasury's July 13 sanctions against First VPN Service matter because they name that service layer. The legal action is not just about one VPN provider. It is a reminder that ransomware response now has to account for the infrastructure economy around the intrusion.

What Happened

The U.S. Treasury Department announced that OFAC designated two individuals and one entity for enabling ransomware actors and other cybercriminal activity. Treasury identified First VPN Service, also called 1VPNS, as a virtual private network provider that sold services to ransomware groups. It also named Dmytro Rashevskyi as the service's administrator.

Treasury also designated Yegeniy Vladimirovich Silayev, while OFAC's sanctions list uses the spelling Yevgeniy Vladimirovich Silayev. Treasury describes him as a seller of cryptors, tools used to disguise ransomware and other malware as safe programs so security systems do not detect or deactivate them.

That distinction matters. This is not a story about a single payload. It is a story about support services: VPN access, exit nodes, aliases, digital-currency addresses, dark-web advertising, and malware-evasion tooling.

The FBI and IC3 advisory gives defenders the technical shape of the allegation. The advisory says First VPN Service had been active since approximately 2014, provided 32 exit-node servers in 27 countries, and had infrastructure used by at least 25 ransomware groups for network reconnaissance and intrusions. It also says First VPN Service IP addresses appeared in scanning activity, botnets, denial-of-service attacks, scams, and hacking.

That is the point. Enforcement is moving upstream. The question is no longer only which ransomware group touched the environment. It is also which services helped make the attack scalable.

The Operator Lesson

The operator lesson is not "ban VPNs." That would be lazy and wrong. Legitimate VPNs support remote work, privacy, administration, and incident response. The issue is whether security, legal, and compliance teams preserve enough evidence to tell the difference between ordinary encrypted access and infrastructure tied to criminal operations.

When Treasury names an infrastructure provider, the evidence trail becomes more valuable. SOC teams need logs that can answer whether traffic touched known exit nodes. Incident-response teams need preserved firewall, proxy, identity, DNS, VPN, and endpoint telemetry. Counsel needs to understand whether sanctioned-party screening, insurance notice, contractual notice, or regulator communications may come into play.

The cryptor detail makes the lesson sharper. If attackers buy tools that make malware look safe, a control program built only around known malware names will miss the operational pattern. Defenders need to look at how the intrusion moved, where connections originated, which accounts authenticated, what processes executed, and whether indicators match an advisory.

This is where legal and technical work meet. A ransomware investigation is not just a forensics exercise, and it is not just a legal memo. It is a chain of custody problem for infrastructure facts.

What to Do This Week

  1. Pull the IC3 indicators into detection review, then check firewall, proxy, VPN, DNS, EDR, and identity logs for matches.
  2. Preserve logs before retention windows erase them, especially remote-access, proxy, authentication, and endpoint telemetry.
  3. Review sanctions-screening workflows for vendors, crypto-payment exposure, incident-response retainers, and any emergency payment process.
  4. Ask incident-response vendors how they preserve evidence tied to exit nodes, anonymization services, and malware-evasion tooling.
  5. Update ransomware tabletop exercises so the scenario includes infrastructure providers, not just a named ransomware group.

The larger lesson is simple: ransomware has a service layer. If your evidence program cannot see that layer, your response will be late, thin, and harder to defend.

Sources