
Operation Saffron
Europol-coordinated May 2026 law enforcement operation that seized 33 servers behind the criminal VPN First VPN.
Operation Saffron, Europol's May 2026 seizure of the criminal VPN service First VPN, took down 33 servers across 27 countries without reducing that month's ransomware attack volume.
Last refreshed: 3 August 2026
Why did seizing First VPN's 33 servers not reduce May 2026 ransomware tempo?
Timeline for Operation Saffron
Mentioned in: G7 cyber exercise ends without readout
Cybersecurity: Threats and DefencesMentioned in: Qilin leads ransomware a second month
Cybersecurity: Threats and DefencesMentioned in: Crews now cross-claim each rival victim
Cybersecurity: Threats and DefencesMentioned in: Europol seizes First VPN in Saffron raid
Cybersecurity: Threats and DefencesBackground
Operation Saffron was a Europol-coordinated international law enforcement operation announced on 21 May 2026, targeting First VPN, a criminal bulletproof VPN service active since 2014 and used by at least 25 ransomware gangs including Phobos and Avaddon. The operation seized 33 servers across 27 countries, dismantling the shared anonymisation infrastructure ransomware affiliates used to mask command-and-control and exfiltration traffic; First VPN's administrator was located in Ukraine, and no arrest was announced.
Operation Saffron sits in a sequence of Europol-supported enforcement actions against criminal infrastructure. The pattern is consistent across these operations: law enforcement removes a shared service or named actor from the ecosystem, but the affiliate supply that actually conducts ransomware attacks is not meaningfully disrupted. BlackFog's May 2026 ransomware report recorded 95 publicly disclosed attacks worldwide in the same month as the Saffron announcement, with 37 active groups and no consolidation, confirming that the bottleneck in the criminal ecosystem is affiliate supply rather than infrastructure.
For defenders, Operation Saffron is useful chiefly as a signal of which services ransomware actors consider operationally essential, bulletproof anonymisation rather than specialised attack tooling. First VPN's 12-year lifespan also illustrates the longevity of criminal infrastructure that exploits jurisdictional fragmentation successfully.