Operation Saffron Yanks the Plug on First VPN, the Getaway Car of at Least 25 Ransomware Crews

French and Dutch police led the takedown of a bulletproof VPN service that prosecutors say routed traffic for Conti, LockBit affiliates, and roughly two dozen other ransomware brands.

ThreatVectr Newsdesk· 2 min read
Operation Saffron Yanks the Plug on First VPN, the Getaway Car of at Least 25 Ransomware Crews
Share

Every bank robber needs a getaway driver, and for the better part of a decade ransomware crews have been paying a monthly subscription to one.

That driver, a service marketed as First VPN Service (sometimes branded 4VPN), was dismantled this week under Operation Saffron, a coordinated police action led by France and the Netherlands with support from Germany, Sweden, Romania, Canada, and the United States. Investigators say the platform was used by at least 25 distinct ransomware operations to mask infrastructure during intrusions, exfiltration, scanning, and DDoS campaigns. Servers were seized, the clearnet and Tor portals now serve a law-enforcement banner.

This is the bulletproof-hosting playbook, just rented by the hop instead of the rack. First VPN sold itself on the same forums where initial access brokers hawk corporate credentials, advertising no logs, crypto-only payments, and exit nodes in jurisdictions unfriendly to mutual legal assistance requests. The price was reportedly a few hundred dollars a year. The customer base, according to French cyber prosecutors at JUNALCO, included affiliates linked to Conti-lineage groups and operators who pivoted into LockBit and its successors.

And here is the part that matters operationally: police didn't just unplug the boxes, they took the logs.

Europol's statement notes that seized infrastructure is being analysed for subscriber data and connection records, which is exactly the outcome a "no-logs" provider is supposed to make impossible. We have seen this movie before. The 2024 takedown of the bulletproof VPN provider used by LockBit affiliates produced a slow drip of follow-on arrests for months. The 2021 dismantling of Safe-Inet, another criminal VPN, eventually fed indictments well into the following year.

The pattern is consistent, said researchers tracking the cybercrime services economy: take down the plumbing, then work outward to the tenants.

For defenders, the immediate intel value is in the IP ranges. If First VPN exit nodes show up in your historical logs touching VPN appliances, Exchange, or Citrix gateways, that is now a high-confidence indicator of pre-ransomware reconnaissance and worth a retro-hunt. CISA has not yet published associated indicators, but the Europol case page is the cleanest primary source as the operation expands.

The interesting question is not whether the customers scatter. They will.

It is which bulletproof service they scatter to, and whether that operator is already sitting in a European interview room.

© 2026 Threat Vectr