On July 13, 2026, the U.S. Treasury's OFAC sanctioned First VPN Service (1VPNS), a VPN provider used by ransomware gangs.

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What happened when the U.S. Treasury sanctioned a VPN provider for enabling ransomware, and how d. Article summary: Here is the verified, cited account of what happened.. Topic tags: general, government, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned a VPN provider called First VPN Service (1VPNS) for enabling ransomware gangs to attack Americans. Buried in the sanctions listing was a single URL—t.me/FirstVPNService—that inadvertently caused a global outage of Telegram's entire t.me short-link domain for roughly a day. Here is the verified, step-by-step account of what happened and why.
OFAC designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and a Belarusian cryptor provider named Yevgeniy Silayev for providing anonymizing infrastructure to ransomware actors targeting Americans . The Treasury's press release stated that 1VPNS's principal customers were cybercriminals and ransomware distributors
. The sanctions were part of a broader U.S. effort to disrupt the infrastructure used by ransomware gangs to hide their activities.
The OFAC sanctions notice included the full web address of the VPN provider's public Telegram group: t.me/FirstVPNService . This single URL under the
t.me domain was listed as an identifier of the sanctioned entity. While this is standard practice for sanctions listings, it had an unintended consequence.
On July 13, 2026, the .me registry operator (DomainME / Identity Digital) placed the entire t.me domain into serverHold status . This is a registry-level block that removes a domain from the global DNS entirely, causing browsers to return NXDOMAIN errors for every link under that domain
. Telegram founder Pavel Durov confirmed on X that
t.me links had "stopped working" . The separate
telegram.me domain was unaffected because it is a different registered domain .
.me is the country-code TLD for Montenegro, but the technical backend is run by Identity Digital, a U.S. company (which absorbed the former operator Afilias) . GoDaddy is also a partner in the registry venture
. U.S. sanctions law binds U.S. persons and companies, so an OFAC designation could reach the domain through these American operators without requiring Montenegro's direct cooperation
. DomainME CEO Predrag Lešić confirmed the domain had been "on hold due to the OFAC compliance"
.
The registry's only technical lever was to suspend the entire domain—it could not restrict a single path like t.me/FirstVPNService . Since Telegram was not contacted beforehand and could not fix it from its side, the entire domain, used by roughly one billion users for invites, groups, and channel links, went dark
. Identity Digital confirmed the block was requested by OFAC
.
The serverHold was lifted early on July 14, 2026 . DomainME CEO Predrag Lešić confirmed
t.me was back online, and the registry issued a statement saying it "closely cooperates with law enforcement agencies to monitor and address issues in the .ME domain in accordance with applicable law, including sanctions compliance requirements" . The incident highlights how a targeted enforcement action can have unintended global consequences when domain-level infrastructure lacks granular enforcement tools.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On July 13, 2026, the U.S. Treasury's OFAC sanctioned First VPN Service (1VPNS), a VPN provider used by ransomware gangs.
On July 13, 2026, the U.S. Treasury's OFAC sanctioned First VPN Service (1VPNS), a VPN provider used by ransomware gangs. The outage stemmed from a technical limitation: the .me registry could only suspend an entire domain, not a single path like t.me/FirstVPNService.