On the morning of May 19, 2026, something unusual happened to thousands of cybercriminals across the world. The VPN service they had been relying on to hide their identities, their servers and their operations from law enforcement went dark. A few hours later, Europol confirmed what those users were already beginning to fear: investigators had not just shut the service down. They had taken everything. The logs, the account records, the metadata that the service had promised its users it was not keeping. All of it was now in the hands of authorities across seven countries.
The service was called First VPN. It had been operating since approximately 2014 and had built a reputation in Russian speaking cybercrime forums as the go to anonymization layer for serious criminal operations. Europol confirmed it appeared in almost every major cybercrime investigation the agency had supported in recent years. Ransomware groups used it to obscure command and control servers. Fraud networks ran exfiltration pipelines through it. Individual threat actors used it to scan networks, operate botnets and launch phishing campaigns. For a decade, it was the infrastructure beneath the infrastructure.
The coordinated action, codenamed Operation Saffron, was executed over two days by authorities from France, the Netherlands, Germany and four other countries. Investigators seized 33 servers distributed across 27 countries, shut down the service’s primary domains and arrested a Ukrainian administrator. More critically, they obtained the complete user database.
Europol confirmed that 506 users have been identified across multiple jurisdictions and that 83 intelligence packages have been distributed to law enforcement agencies in countries where those users are based. Those packages are now seeding 21 additional investigations globally.
The “no-logs” promise that services like First VPN sell to their customers rests on a specific assumption: that law enforcement will never obtain the infrastructure directly. Once investigators are inside the servers, there are no promises left to keep. The logs that the service may not have written deliberately are only one data source. Network metadata, connection timing, billing records and payment addresses all survive on infrastructure that a seizure puts directly into investigators’ hands.
This follows a pattern that has defined law enforcement’s cybercrime strategy through 2026. Rather than pursuing individual criminals who can be replaced within days, agencies are targeting the shared services that make criminal operations viable at scale. The January 2026 Black Axe network arrests, the March 2026 LeakBase forum seizure involving 142,000 registered users across 14 countries and now Operation Saffron form a sequence that is systematically dismantling the commercial infrastructure of cybercrime.
The LeakBase takedown in March is worth noting in this context. That forum had more than 215,000 private messages between its 142,000 users at the time of seizure. Those messages are now part of the investigative record across every participating jurisdiction. Users who communicated privately on a forum they assumed was beyond reach found that the forum itself became the evidence.
Europol’s Director of Operations called the operation “a significant blow to the trust model that makes criminal operations possible.” That is an accurate description. Ransomware operations and fraud networks depend on a working market of anonymization services, hosting providers, cryptocurrency mixers and initial access brokers. Each time a major provider in that market is seized rather than simply shut down, every other provider’s users have to ask the same question: how long have investigators been watching before they acted?
For First VPN, the answer was years. French and Dutch authorities started investigating in November 2023. The service ran for another two and a half years before the seizure. During that entire period, every transaction, every connection and every user in the system was potentially visible to investigators who were not yet ready to act.

Leave a Reply