
Operation Saffron
Europol-coordinated May 2026 law enforcement operation that seized 33 servers behind the criminal VPN First VPN.
Last refreshed: 7 June 2026
Why did seizing First VPN's 33 servers not reduce May 2026 ransomware tempo?
Timeline for Operation Saffron
Mentioned in: Qilin leads ransomware a second month
Cybersecurity: Threats and DefencesMentioned in: Crews now cross-claim each rival victim
Cybersecurity: Threats and DefencesMentioned in: Europol seizes First VPN in Saffron raid
Cybersecurity: Threats and DefencesBackground
Operation Saffron was a Europol-coordinated international law enforcement operation announced on 21 May 2026, targeting First VPN, a criminal bulletproof VPN service active since 2014 and used by at least 25 ransomware gangs including Phobos and Avaddon. The operation seized 33 servers distributed across 27 countries, dismantling the shared anonymisation infrastructure that ransomware affiliates used to mask command-and-control and exfiltration traffic. First VPN's administrator was located in Ukraine.
Operation Saffron sits in a sequence of Europol-supported enforcement actions against criminal infrastructure, alongside the E-Note exchange seizure and the Scattered Spider arrest. The pattern across these operations is consistent: law enforcement removes a shared service or named actor from the criminal ecosystem, but the affiliate supply that actually conducts ransomware attacks is not meaningfully disrupted. BlackFog's May 2026 ransomware report recorded 95 publicly disclosed attacks worldwide in the same month as the Saffron announcement, with 37 active groups and no consolidation — confirming that the bottleneck in the criminal ecosystem is not infrastructure but the human pool of affiliates.
For defenders, Operation Saffron is useful as a signal of which services ransomware actors consider operationally essential — bulletproof anonymisation rather than specialised attack tooling. First VPN's 12-year lifespan also illustrates the longevity of criminal infrastructure that successfully exploits jurisdictional fragmentation. The operation does not reduce threat tempo materially, but it raises the operational friction cost for the gangs that relied on First VPN and forces migration to alternatives that may be less operationally mature.