News • 22 May 2026

Criminal VPN Dismantled in
First International Takedown.

Operation Saffron

A coordinated international police operation has dismantled First VPN, a service that gave ransomware gangs and cyber criminals the anonymity they needed to operate undetected. Led by French and Dutch authorities with support from Europol, the UK’s National Crime Agency, and security firm Bitdefender, this marks the first time law enforcement has successfully taken down a criminal VPN service of this scale.

The Operation

What happened in
Operation Saffron

01
FOUR-YEAR INVESTIGATION

The operation began in December 2021. Over four and a half years, investigators gained access to the First VPN service, obtained a copy of its user database, and identified the connections used specifically by cyber criminals.

02
ADMINISTRATOR ARRESTED

The administrator behind First VPN was arrested in Ukraine. Their home was searched and 33 servers were dismantled, along with the seizure of multiple domain names including 1vpns.com, .net, and .org.

03
506 USERS IDENTIFIED

Intelligence gathered during the investigation has already exposed over 500 known users of the service. Over 80 intelligence packages have been shared with law enforcement agencies worldwide.

04
21 INVESTIGATIONS SUPPORTED

The intelligence from this single operation has already fed into 21 separate criminal investigations, demonstrating the ripple effect of dismantling the infrastructure that cyber criminals depend on.

Context

Why this matters for
every business

Criminals Lose Cover

First VPN was specifically designed for criminal use, offering anonymised payments and hidden infrastructure. Removing it strips away a key layer of protection that threat actors relied on.

Patience Pays Off

This was not a quick raid. Investigators spent four and a half years building their case, proving that law enforcement is willing to play the long game against cyber crime infrastructure.

International Cooperation

France, the Netherlands, the UK, Europol, and private sector firms all worked together. Cyber crime crosses borders, and so must the response.

Infrastructure Is the Target

Rather than chasing individual attackers, law enforcement is increasingly targeting the shared services that enable cyber crime at scale. Take down the tools, and you disrupt entire networks.

Ransomware Disrupted

First VPN appeared in almost every major Europol cyber investigation in recent years. Its removal directly impacts the operational capability of ransomware gangs who depended on it.

Anonymity Is Not Guaranteed

Criminals assumed they were beyond reach. This operation proves that even purpose-built criminal infrastructure can be infiltrated, mapped, and dismantled over time.

Action

What this means
for your security

REVIEW YOUR VPN POLICY

Legitimate VPNs remain an important security tool. But this is a reminder that the technology itself is neutral. Make sure your business uses reputable, audited VPN providers and that staff understand the difference.

MONITOR FOR EXPOSURE

Operations like this generate intelligence that often surfaces in breach databases and dark web monitoring feeds. If your organisation has been targeted by ransomware in recent years, new leads from this takedown could be relevant.

LAYER YOUR DEFENCES

Criminal infrastructure will be rebuilt. New services will replace First VPN. The lesson is not that law enforcement has won, but that your own security layers need to be strong enough to withstand attacks regardless of what tools criminals use.

Key Numbers

Operation Saffron by the numbers

33 Servers Seized

The physical infrastructure behind First VPN was dismantled across multiple locations, along with all associated domain names and onion services.

506 Users Identified

Over five hundred known criminal users of the service have been identified and linked to cyber crime activity through the seized database.

80+ Intelligence Packages

Europol has already distributed over 80 intelligence packages to agencies worldwide, generating actionable leads across multiple ongoing investigations.

4.5 Years in the Making

The investigation ran from December 2021 to May 2026 - a sustained, patient effort that culminated in the arrest, server seizure, and infrastructure takedown.

Privacy Policy

At Workflo, we are committed to protecting your privacy and ensuring the security of your personal data. This privacy policy outlines how we collect, use, disclose, and protect your personal information as a data controller. By engaging our services, you acknowledge and consent to the practices described in this policy.

Information We Collect

We may collect and process the following types of personal data:

  • Contact information, including your name, address, phone number, and email address.
  • Financial information, such as billing details and payment records.
  • Information necessary to provide our services, including project details and relevant documentation.
  • Communication records and correspondence with you.
  • Any other information you provide to us voluntarily.

Purpose and Legal Basis for Processing

We process personal data for the following purposes:

  • Your consent given at the time of engaging our services.
  • The processing is necessary for the performance of our contract with you.
  • Compliance with legal obligations.

Please note that providing us with certain personal data is a requirement of our contract with you. If you fail to provide the requested information, we may be unable to provide our services effectively.

Disclosure of Personal Data

We may share your personal data with the following parties:

  • HM Revenue and Customs (HMRC) for tax compliance purposes.
  • Professional indemnity insurers for insurance coverage.
  • Debt collection service providers for recovering outstanding payments.
  • Product manufacturers, if necessary for warranty claims or technical support.

Additionally, we may disclose personal data if required or permitted by law, including:

  • Law enforcement agencies, upon their lawful request.
  • Courts and tribunals in connection with legal proceedings.
  • The Information Commissioner's Office (ICO) as required by data protection regulations.

Should you request us not to share your personal data with the above parties, we may need to cease our services.

Third-Party Service Providers

We may engage third-party service providers, including service agents, debt recovery agents, field tracing agents, and subcontractors, to assist in delivering our services and fulfilling our legitimate interests. These providers are bound by contractual obligations to handle your personal data securely and only process it for the specified purposes.

Subject Access Requests (SARs)

You have the right to request access to the personal data we hold about you, subject to applicable laws. To submit a subject access request, please send a written request to the address provided below. To expedite the process, include relevant details to verify your identity and locate the requested information, such as your name, address, work address, date of work, and relevant invoice numbers.

We are committed to responding to SARs promptly, within one month of receipt, as required by the Data Protection Act 2018 (DPA 2018). However, there may be circumstances where we are permitted to refuse access, such as when there has been little or no change to the data since a previous request.

You may authorise someone else, such as a friend, relative, or solicitor, to request information on your behalf. To grant such authorisation, please sign a letter stating your consent and the authorised person's details.

Rectification of Personal Data

If you believe that any personal data we hold about you is inaccurate or incomplete, please notify us promptly. We will take reasonable steps to rectify and update the information as necessary.

Withdrawal of Consent

If you have provided consent for the processing of your personal data, you have the right to withdraw that consent at any time. To withdraw your consent, please inform us promptly. Please note that the withdrawal of consent does not affect the lawfulness of processing prior to the withdrawal, and we may still have a legal basis to process your data in certain circumstances.

Marketing Activities and Data Usage

At Workflo, we may use your personal data for limited marketing activities, subject to your consent where required by applicable laws.

  • Consent: We will obtain your explicit consent before using your personal data for direct marketing purposes, where required by applicable data protection laws.
  • Marketing Communications: With your consent, we may send you marketing communications via email, phone calls, or other means of communication.
  • Opt-out: You have the right to opt-out of receiving marketing communications from us at any time.
  • Data Sharing: We will not share your personal data with third parties for their direct marketing purposes without obtaining your consent.
  • Data Retention: We will retain your personal data for marketing purposes only as long as your consent is valid or as required by applicable laws.

Marketing, Contact Form and Data Usage

We may use personal data you submit via our website forms for the purposes of responding to your enquiry, providing you with the correct information, product, or service you have requested, and, with your consent, sending you marketing information related to our services.

  • Consent: When completing a form on our website, you will be asked to confirm your consent for Workflo to process your personal data in accordance with this Privacy Policy.
  • Opt-out: You can withdraw your consent and opt out of marketing communications at any time by following the unsubscribe link in our emails or contacting us.
  • Data Sharing: We will never share your personal data with third parties for their direct marketing purposes without your consent.

Automated Decision-Making

We do not engage in automated decision-making processes that significantly impact you or involve sensitive personal data.

Use of CCTV

In order to ensure the security and safety of our premises, we utilise Closed-Circuit Television (CCTV) surveillance systems. The primary purpose is to prevent and detect unlawful activities, protect the security of our premises, assets, and personnel, and enhance the safety of individuals within the premises.

Data Security

We take data security seriously and implement appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration, or disclosure. These measures include encryption, access controls, regular security assessments, and employee training on data protection.

Data Breach Notification

In the event of a data breach that poses a risk to the rights and freedoms of individuals, we will promptly notify the relevant authorities and affected individuals, as required by applicable data protection laws.

Cookies and Tracking Technologies

Our website may use cookies or other tracking technologies to enhance user experience. For more information on our use of cookies, please review our Cookie Policy.

Third-Party Links/Websites

Our website may contain links to third-party websites or services. Please note that our privacy policy does not apply to those external sites, and we encourage you to review the privacy policies of those sites.

Children's Privacy

Our services are not intended for children under a certain age. We do not knowingly collect personal data from children.

Changes to the Privacy Policy

We may update this privacy policy from time to time to reflect changes to our data handling practices or legal requirements. The most current version of the policy will be available on our website.

Contact Information

For any questions or concerns related to data protection or this privacy policy, please contact:

Kirsty Cole
privacy@workflo.solutions
Workflo
Workflo House Unit 16 Shairps Business Park
Houston Ind Estate, Livingston
West Lothian EH54 5FD
Phone: 0330 055 9435

Call Us