Operation Saffron, coordinated by France and the Netherlands with Europol and Eurojust support, seized infrastructure behind the service known as First VPN on 19–20 May 2026. Investigators reported 33 servers seized, thousands of suspected criminal users identified, and the alleged administrator interviewed in Ukraine. The FBI stated that at least 25 ransomware groups used the service.
Shared Infrastructure Is An Operational Security Failure
Twenty-five groups using one anonymity service is a striking concentration for adversaries who otherwise avoid one another. Each is buying a specialist capability rather than building it, and the result is a single point at which their activity converges.
It is the same economic logic that produces business-associate breaches on the defensive side. Specialisation is efficient, concentration follows, and the concentration becomes the target.
Three Years Of Watching
Reporting indicates investigators observed the service for around three years before acting. That interval is the interesting decision, and it is a genuinely hard one.
Infrastructure under observation produces intelligence about every group using it — attribution, timing, and links between operations that would otherwise look separate. Seizing it converts that stream into a single disruption and pushes the users to services nobody is watching.
Every month of observation is also a month in which victims are being extorted through infrastructure the authorities could have taken down. That trade is made on behalf of people who are never told it is being made, and it deserves to be stated plainly rather than buried in the word "investigation".
Compiled from published law-enforcement announcements and reporting, listed below. The three-year observation period is as reported. An interview is not a charge, and we do not name the individual. Corrections: corrections@forensicpost.com.