Multiple VPN Services

NJCCIC Data Breach Notification

Original Release Date: 7/23/2020

Summary

A large data leak was discovered exposing virtual private network (VPN) logs of approximately 20 million users worldwide. Affected VPN services include UFO VPN, FAST VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, and Rabbit VPN, largely available through Google Play Store and Apple App Store. All seven of these VPN services were created by Dreamfii HK Limited, a Hong Kong-based developer, which claimed that they did not store logs or user data. The breach occured due to an unsecured ElasticSearch cloud database and affects both free and paid services. Exposed information includes names, home addresses, email addresses, activity logs, cleartext passwords, Bitcoin payment information, device information, and PayPal API links. Users are urged to exercise caution when selecting VPN services and research options prior to purchase or use.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.