Europol has shut down a VPN service that provided anonymity to approximately two dozen ransomware groups. The agency notified identified users they have been exposed.
European law enforcement authorities have successfully dismantled a VPN service that functioned as a critical infrastructure for ransomware operations across multiple criminal organizations.
The unnamed VPN marketed itself to hackers with promises of complete anonymity for conducting cyberattacks. Despite these assurances, Europol penetrated the service's operations and gathered intelligence on its user base.
According to the enforcement action, around two dozen ransomware gangs relied on the platform to mask their identities and coordinate attacks. The service represented a significant chokepoint in the ransomware ecosystem, suggesting its removal could disrupt multiple criminal networks simultaneously.
In a notable development, Europol notified the identified users—including operators from active ransomware gangs—that their identities have been compromised. This notification serves both as a tactical move to pressure offenders and as a message that anonymizing services cannot guarantee protection against determined law enforcement.
The operation highlights an ongoing strategy by European authorities to target the infrastructure supporting ransomware operations rather than pursuing individual attacks. By dismantling shared tools and services, law enforcement aims to increase operational costs and friction for criminal groups.
Ransomware has become one of the most damaging forms of cybercrime, generating billions in ransom payments annually while affecting hospitals, government agencies, and businesses worldwide. Recent enforcement actions have focused on disrupting payment channels, cryptocurrency exchanges, and now the anonymization services that enable these operations.
The VPN shutdown follows other recent successes including the takedown of major darknet marketplaces and the disruption of ransomware payment infrastructure. However, security experts note that determined cybercriminals typically adapt by migrating to alternative anonymization methods or developing new tools.
Berlin's city administration has confirmed that the Rhysida ransomware gang stole data and is attempting extortion after listing the city on their data leak site.
A security researcher discovered nine vulnerabilities in ATM encryption and authentication software. The findings highlight systemic weaknesses affecting critical infrastructure beyond banking.
Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.
Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.