U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support 22%

By Ravie Lakshmanan12%

7/14/2026, 8:02:00 AM

BS Summary: This article contains 21 faulty reasoning types, including Appeal to Authority, Ambiguity (Equivocation), and Hasty Generalization, with Unattributed Quote as the most egregious example at 26.9% saturation with 217 hits. Analysis detected 1,487 faulty-reasoning hits from 806 analyzed words, generating a BS Score of 35.8% and a BS Rank of 22% (16,525 of 21,164 articles). This article is better (less manipulative) than 78.10% of the article peer group.

The U.S. 
Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. 
The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian administrator, Dmytro Rashevskyi. 
The department has also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national, for selling cryptors to help conceal ransomware and other malware as safe programs to avoid being detected by security tools. 
First VPN was dismantled in May 2026 as part of a joint law enforcement operation by European and North American authorities for assisting criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. 
The service had been operational since 2014, advertising that it neither keeps a log of users' identities or activities nor cooperates with law enforcement to tackle illegal activity originating from servers it rents to customers. 
Per the Treasury, several ransomware groups are said to have purchased First VPN to carry out attacks on U.S. companies and institutions and hide their true origins, deploy malware, and manage exfiltrated data. 
Victims of ransomware attacks that involved the VPN infrastructure included U.S. businesses, financial services companies, hospitals, and municipal governments. 
Ransomware groups using services supplied by the designated parties allegedly caused billions of dollars in losses to American businesses and critical infrastructure providers, U.S. officials said. 
"Rashevskyi has used false identities, including 'Maksim Sorin' and 'Roman Chabanenko,' to buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers," the department said. 
U.K. and E.U. 
Impose Sanctions on Russian Individuals and Entities 
The disclosure coincides with the U.K. and E.U. sanctioning Russian cyber networks for their "persistent and increasingly reckless attempts to sow chaos and division across Europe." 
The sanctions target 24 individuals and entities behind destructive cyber and hybrid operations, including operators involved in proxy networks linked to the Russian Intelligence Services (RIS). 
This includes Russia's Main Intelligence Directorate (GRU) senior leadership members Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for their role in directing GRU cyber and hybrid threat operations. 
In tandem, Centre 16 of the Federal Security Service (FSB) has been attributed to disruptive sabotage operations against Poland's energy grid late last year. 
"GRU Unit 29155 cyber division worked with cybercriminals, including the company IMPULS, to recruit hackers and cyber specialists from universities and academies across Russia," the U.K. government said. 
The sanctions are also aimed at individuals behind Lumma Stealer for enabling cybercriminals to collect sensitive information from compromised devices at scale. 
Russia is said to have used the stealer's stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin's objectives. 
"Cybercriminals, self-proclaimed hacktivists and private companies linked to Russia, including actors operating under its instructions, direction or control, have also carried out, enabled and facilitated a wide range of malicious activities," the E.U. said. 
"We strongly condemn Russia's behaviour and misuse of this cyber ecosystem, targeting public services and critical infrastructure, causing disruptions and financial losses. 
By calling out Russia's malicious behaviour and imposing costs on those responsible for such activities, the EU underscores its determination to uphold accountability in cyberspace." 
Russian State-Sponsored Targeting Goes After Routers 
The sanctions also arrive against the backdrop of a new advisory issued by the U.S. 
Federal Bureau of Investigation (FBI) about FSB Center 16 cyber actors' exploitation of poorly configured and vulnerable networking devices across the world to opportunistically hack into multiple critical infrastructure sector networks. 
"The Russian FSB Center 16 cyber actors primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation," the agency said. 
"The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication." 
The activity also involves abusing common vulnerabilities and exposures (CVEs) in Cisco devices, such as CVE-2018-0171 and CVE-2008-4128, as a way to discover and exploit poorly configured networking appliances. 
The U.S. 
Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2008-4128 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by July 16, 2026. 
The threat actors behind the campaign are tracked under various names, including Berserk Bear, Crouching Yeti, Dragonfly, Energetic Bear, Ghost Blizzard, Energetic Bear, and Static Tundra. 
In August 2025, Cisco warned of active exploitation of CVE-2018-0171, urging customers to apply the necessary fixes as soon as possible. 
"This is an ongoing issue that has impacted various U.S. and foreign networks across multiple sectors, including the Defense Industrial Base, communications, energy, financial services, government facilities, and healthcare sectors," the U.S. 
National Security Agency (NSA) said. 
Article reasoning-pattern comparisonThis article: 7.6%Ravie Lakshmanan: 1.5%The Hacker News: 2.0%Confirmation Bias7.6%This article: 0.0%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias0.0%This article: 4.5%Ravie Lakshmanan: 2.2%The Hacker News: 3.3%Availability Heuristic4.5%This article: 3.2%Ravie Lakshmanan: 1.6%The Hacker News: 1.4%Representativeness Heuristic3.2%This article: 0.0%Ravie Lakshmanan: 1.0%The Hacker News: 0.6%Hindsight Bias0.0%This article: 0.0%Ravie Lakshmanan: 2.2%The Hacker News: 2.5%Overconfidence Bias0.0%This article: 3.0%Ravie Lakshmanan: 2.6%The Hacker News: 2.9%Framing Effect3.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 1.1%Loss Aversion0.0%This article: 3.5%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias3.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 1.3%Optimism Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.3%The Hacker News: 1.6%Pessimism Bias0.0%This article: 14.4%Ravie Lakshmanan: 8.0%The Hacker News: 6.8%Negativity Bias14.4%This article: 3.1%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias3.1%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 4.2%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias4.2%This article: 0.0%Ravie Lakshmanan: 1.4%The Hacker News: 0.4%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 4.0%Ravie Lakshmanan: 2.2%The Hacker News: 1.4%Recency Bias4.0%This article: 3.2%Ravie Lakshmanan: 0.3%The Hacker News: 0.2%Primacy Effect3.2%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 5.5%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem5.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 25.2%Ravie Lakshmanan: 4.8%The Hacker News: 4.0%Appeal to Authority25.2%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.6%False Dilemma0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 15.4%Ravie Lakshmanan: 3.8%The Hacker News: 4.3%Hasty Generalization15.4%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 6.0%Ravie Lakshmanan: 1.2%The Hacker News: 1.1%Appeal to Emotion6.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 9.4%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)9.4%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 1.0%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 16.5%Ravie Lakshmanan: 4.0%The Hacker News: 2.3%Ambiguity (Equivocation)16.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 26.9%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote26.9%This article: 12.7%Ravie Lakshmanan: 2.8%The Hacker News: 1.0%Quote-first Misdirection12.7%This article: 10.7%Ravie Lakshmanan: 2.4%The Hacker News: 2.4%Biased Writer Voice10.7%This article: 3.1%Ravie Lakshmanan: 2.5%The Hacker News: 4.4%Indoctrination3.1%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 2.6%Ravie Lakshmanan: 0.5%The Hacker News: 3.0%Attempt to Sell a Product or S…2.6%

806 words analyzed.

Speakers

15speakers69%attributed speech252writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 1 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 2 words • 0.0% coverageOffice of Foreign Assets Control (OFAC) • 31 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageTreasury Department • 31 words • 100.0% coverageEuropean and North American authorities • 38 words • 0.0% coverageWriter's voice • 35 words • 100.0% coverageTreasury • 33 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageU.S. officials • 26 words • 0.0% coveragedepartment • 44 words • 100.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageU.K. and E.U. • 26 words • 0.0% coverageU.K. and E.U. • 26 words • 0.0% coverageU.K. and E.U. • 28 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageU.K. government • 28 words • 100.0% coverageU.K. and E.U. • 22 words • 100.0% coverageWriter's voice • 23 words • 0.0% coverageE.U. • 34 words • 100.0% coverageE.U. • 22 words • 100.0% coverageE.U. • 25 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageFederal Bureau of Investigation (FBI) • 31 words • 0.0% coverageagency • 23 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageCybersecurity and Infrastructure Security Agency (CISA) • 28 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageCisco • 21 words • 100.0% coverageU.S. National Security Agency (NSA) • 32 words • 0.0% coverageNational Security Agency (NSA) • 5 words • 0.0% coverage
Selected voice

department

100%flagged-word coverage
44 attributed words7.9% of attributed speech85% writer coverage
0%50.0%100.0%Unattributed Quote+90.5 ptsWriter: 9.5%department: 100.0%100.0%Quote-first Misdirection+86.1 ptsWriter: 13.9%department: 100.0%100.0%Biased Writer Voice-4.4 ptsWriter: 4.4%department: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.