Skip to main content

Seven VPN apps accused of exposing more than a terabyte of private data

A group of free VPN apps reportedly exposed a treasure trove of private data of millions of users. Discovered by vpnMentor, a total of seven VPN providers, all of which explicitly claimed they didn’t record their users’ activities, left more than a terabyte of browsing logs out in the open for anyone to access.

The leaked data silo housed a wide range of sensitive data, some of which was personally identifiable too. VpnMentor claims it included records of the websites users visited, plain-text passwords, PayPal payment information, device specifications, email addresses, and more.

Related Videos

While the data since then has been taken down, vpnMentor was independently able to confirm the data was channeled from these VPN apps by browsing through new accounts and cross-verifying it with the updated database.

In addition, all of the affected VPN apps are owned by the same Hong Kong-based parent company and were simply rebranded versions of the same VPN service. They were distributed under variations of generic names such as Super VPN, Fast VPN, Flash VPN, and more — a pattern commonly found in such data leak incidents. Most of them had more than 10 million downloads on the Google Play Store and iOS App Store and their listings haven’t been pulled yet.

We’ve reached out to Google and Apple for more information and we’ll update the story when we hear back.

“We do not track user activities outside of our Site, nor do we track the website browsing or connection activities of users who are using our Services,” one of them called UFO VPN boldly wrote in its privacy policy.

A spokesperson for UFO VPN argued that the database didn’t feature any personal information, and that the coronavirus prevented its staff from securing the server. The email addresses, they added, were of users who had sent them feedback and accounted for less than 1% of the entire data.

“Due to personnel changes caused by COVID-19, we‘ve not found bugs in server firewall rules immediately, which will lead to the potential risk of being hacked. And now it has been fixed,” the spokesperson told vpnMentor.

VPN apps are capable of monitoring your internet traffic and hence, it’s key to ensure the one you’ve installed has a secure infrastructure in place. If you were using any of these affected apps, here are a few alternatives.

Editors' Recommendations

What is 5G? Speeds, coverage, comparisons, and more
The 5G UW icon on the Samsung Galaxy S23.

It's been years in the making, but 5G — the next big chapter in wireless technology — is finally approaching the mainstream. While we haven't yet reached the point where it's available everywhere, nearly all of the best smartphones are 5G-capable these days, and you're far more likely to see a 5G icon lit up on your phone than not.

There's more to 5G than just a fancy new number, though. The technology has been considerably more complicated for carriers to roll out since it covers a much wider range of frequencies than older 4G/LTE technology, with different trade-offs for each. It's also a much farther-reaching wireless technology, promising the kind of global connectivity that was once merely a dream found in futuristic sci-fi novels.

Read more
NordPass adds passkey support to banish your weak passwords
password manager lifestyle image

Weak passwords can put your online accounts at risk, but password manager NordPass thinks it has the solution. The app has just added support for passkeys, giving you a far more secure way to keep all your important logins safe and sound.

Instead of a vulnerable password, passkeys work by using your biometric data as your login ‘fingerprint.’ For example, you could use the Touch ID button on a Mac or a facial recognition scanner on your smartphone to log in to your account. No typing required.

Read more
GPT-4: how to use, new features, availability, and more
A laptop opened to the ChatGPT website.

ChatGPT-4 has officially been announced, confirming the longtime rumors around its improvements to the already incredibly impressive language skills of OpenAI's ChatGPT.

OpenAI calls it the company's "most advanced system, producing safer and more useful responses." Here's everything we know about it so far.
Availability

Read more