Europol has taken down First VPN, a so called bulletproof VPN service that authorities say was used in ransomware and other cybercrime investigations. The operation, called Operation Saffron, led to the seizure of 33 servers across 27 countries and reportedly helped identify 506 users of the service.
The case involved 18 countries, with France, the Netherlands, Luxembourg, Romania, Switzerland, Ukraine, and the United Kingdom playing major roles. First VPN’s regular website and .onion domain were also seized, and visitors now see a law enforcement banner connected to the operation.
The takedown shows the difference between privacy VPNs and services built for abuse
First VPN reportedly promoted itself as a service that would not cooperate with any judicial authority and would not be bound by any jurisdiction. It also allegedly advertised mainly on Russian language cybercrime forums. That matters because the issue here is not simply that the service offered privacy. Authorities say it was repeatedly connected to criminal activity and appeared in many cybercrime investigations.
| Operation detail | Information |
|---|---|
| Operation name | Operation Saffron |
| Target | First VPN |
| Servers seized | 33 |
| Countries with seized servers | 27 |
| Users reportedly identified | 506 |
| Countries involved | 18 |
| Investigation start | 2021 |
The report describes First VPN as a bulletproof service, a term often used for providers that ignore abuse complaints, resist law enforcement requests, and market themselves to people involved in cybercrime. These services are different from mainstream privacy focused VPNs, which may keep no logs but still operate within legal frameworks and public terms of service.

That distinction is important because VPNs are not automatically suspicious. Many people use them for privacy, safer public Wi Fi, avoiding tracking, or protecting sensitive work. Services such as Mullvad, ProtonVPN, and Windscribe have been mentioned in past legal contexts where their no log designs meant there was little or no customer data to hand over. The difference is that privacy focused VPNs are generally built and marketed for lawful use, while bulletproof services often attract criminal customers by promising resistance to any oversight.
Operation Saffron also shows how international cybercrime investigations work. VPN infrastructure can be spread across many countries, so takedowns usually require cooperation between several national authorities. In this case, the investigation reportedly lasted around five years, beginning in 2021, before the servers and domains were seized.
The legal debate around these actions is more complicated. On one side, law enforcement agencies argue that services used heavily in ransomware and cybercrime need to be disrupted. Ransomware groups rely on infrastructure that hides operators, moves stolen data, and supports attacks. Removing that infrastructure can make criminal operations harder to run.
On the other side, privacy advocates worry about the broader direction of VPN enforcement. Europe strongly protects digital privacy through laws such as GDPR and the EU Charter of Fundamental Rights, but governments are also pushing more surveillance friendly rules. Proposals such as ProtectEU and the controversial Chat Control framework have already raised concerns about private communication scanning and wider data retention.
That tension will not disappear. A service accused of advertising to cybercrime forums and refusing all legal cooperation is easier to justify as a takedown target. But each enforcement action also raises questions about where the line should be drawn between criminal infrastructure and legitimate privacy tools.
For now, First VPN appears to be a clear law enforcement target rather than a normal consumer VPN caught in a gray area. The bigger question is what happens next. Authorities will likely continue targeting bulletproof VPNs, hosting providers, and proxy networks tied to ransomware. At the same time, privacy focused VPN companies will need to keep proving that strong privacy can exist without becoming a shelter for organized cybercrime.



Discussion (0)
Be the first to comment.