Original Release Date: 7/23/2020
A large data leak was discovered exposing virtual private network (VPN) logs of approximately 20 million users worldwide. Affected VPN services include UFO VPN, FAST VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, and Rabbit VPN, largely available through Google Play Store and Apple App Store. All seven of these VPN services were created by Dreamfii HK Limited, a Hong Kong-based developer, which claimed that they did not store logs or user data. The breach occured due to an unsecured ElasticSearch cloud database and affects both free and paid services. Exposed information includes names, home addresses, email addresses, activity logs, cleartext passwords, Bitcoin payment information, device information, and PayPal API links. Users are urged to exercise caution when selecting VPN services and research options prior to purchase or use.