iTelegram's t.me link-shortening domain briefly went offline earlier this week after a compliance action linked to US sanctions inadvertently affected the entire domain instead of a specific Telegram link.
Users began reporting on Monday that t.me short links were inaccessible after the domain was placed under a "serverHold" status, effectively making it unavailable across the internet. The registry status suggested that the action had been initiated by the domain's registry operator, causing widespread disruption to Telegram's link-sharing functionality.
Following the outage, Telegram CEO Pavel Durov reached out to DomainME, the registry responsible for managing the .me top-level domain, requesting an investigation into the issue.
On Tuesday, DomainME clarified the reason behind the disruption, stating, "t.me was on hold due to the OFAC compliance, but it is back online now."
The reference to OFAC points to the US Treasury Department's Office of Foreign Assets Control, which oversees and enforces US economic and trade sanctions. The same day the domain became unavailable, OFAC announced sanctions against First VPN Service, alleging that the platform had been used by multiple ransomware groups to conceal malicious activities targeting US businesses, hospitals, and government organizations.
As part of the sanctions, OFAC designated the VPN service's alleged administrator, Ukrainian national Dmytro Rashevskyi, along with associated infrastructure, including the domains 1vpns.com and 1vpns.net, as well as cryptocurrency wallet addresses. The sanctions are intended to prevent US individuals and businesses from engaging with the VPN provider.
According to reports, the sanctions documentation specifically referenced the Telegram support link t.me/FirstVPNService. This appears to have led to an unintended compliance action in which the entire t.me domain was placed on hold instead of only the sanctioned Telegram link.
In a subsequent statement, DomainME said, "the .ME Registry works closely with law enforcement to monitor and mitigate issues across the .ME domain in accordance with applicable laws, including sanctions requirements." The company suggested that the suspension was part of its sanctions compliance process rather than a simple technical error.
The t.me domain has since been restored and now redirects users to Telegram's primary website.
Meanwhile, the FBI has warned that First VPN Service, operational since 2014, has been widely used by cybercriminals. Investigators say at least 25 ransomware groups have relied on the VPN platform. While the service promoted itself as a privacy-focused VPN, authorities allege it has also been connected to botnet operations, distributed denial-of-service (DDoS) attacks, online scams, and hacking campaigns.
The FBI further stated, “First VPN Service was almost exclusively advertised in known criminal dark web forums such as Exploit[.]in and XSS[.]is, two of the most prominent Russian-language online forums which provide marketplaces for cyber criminals to buy and sell unauthorized access to computer systems, stolen personal identifying information, hacking tools, and contraband,” the agency added.