Authorities dismantle the “First VPN” virtual private network service used by cybercriminals to obscure activity tied to ransomware and other attacks, according to multiple reports. Europol describes the crackdown as targeting a VPN previously marketed to criminals and used for malicious purposes such as ransomware-related activity, fraud, network reconnaissance, and intrusions. SecurityWeek and TechRadar report that the FBI links “First VPN” to use by dozens of ransomware groups, with TechRadar specifically citing 25 groups. The operation is described as international, involving European and North American law enforcement, with leadership attributed to France and the Netherlands and support from Europol and Eurojust. Help Net Security and The Hacker News report the disruption occurs as part of an operation referred to as “Operation Saffron,” with the service taken offline on May 19 and 20 and investigations ongoing since at least December, according to some accounts. Help Net Security adds that authorities dismantle multiple servers associated with the service and interview the operator in Ukraine, while targeted domain names are seized and shut down through cross-border judicial and law-enforcement coordination. SecurityWeek also reports that the administrator is arrested.