Seven VPN Services Including UFO VPN, Rabbit VPN, Fast VPN Leaked Over 1.2TB of Private User Data: Report

VPN services are supposed prevent ISPs from tracking user data — but, a new report has found seven VPN apps have leaked private data.

Advertisement
By Vineet Washington | Updated: 20 July 2020 18:27 IST
Highlights
  • VPN apps found to have leaked over 1.2TB of private data
  • UFO VPN, Fast VPN, Rabbit VPN, Secure VPN are some of them
  • They reportedly have a common recipient for payments

UFO VPN and many other apps are still listed on the Google Play store

Photo Credit: Google Play store

Virtual Private Network or VPN services including UFO VPN, Rabbit VPN, Free VPN, and four more have been found to have leaked over 1TB of private user information, as per a new report. A report stated that these VPNs exposed a database of user logs and API access records without a password or authentication. A separate report pointed out that UFO VPN was just one of the several VPN service providers that were leaking private information.

At the start of July, Comparitech found that Hong Kong-based VPN provider UFO VPN exposed personal user information like plain text passwords, VPN session secrets, IP addresses, connection timestamps, geo-tags, and device and OS characteristics. The company was informed about the same and more than two weeks later, it reportedly fixed the issue, stating that no information was leaked. The leak affects both free and paid customers and reportedly all users of the service are potentially affected, taking the number to 20 million users. This amounts to 894GB of leaked data.

Following this discovery, vpnMentor found that UFO VPN was not the only one and six others that were seemingly connected to a common app developer and white labeled for other companies were found to be doing the same. These include Fast VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, and Rabbit VPN. Notably, all of these apps claim they do not log any user original IP address or user activity. It was found that a total of 1.2TB of data was leaked.

Advertisement

The good news is that the biggest VPN companies that most people probably use, have not been implicated in this report.

The team at vpnMentor found that the VPNs share an Elasticssearch server, have a single recipient for payments, Dreamfii HK Limited, and share a lot of the assets. They reached out to the various VPN services involved and while some of them did not respond, others stated after several days that the issue had been fixed. Most of these VPN apps are still listed on the Google Play store.

Potential impact of data leak

This data leak could lead to phishing and fraud, blackmail, viral attack, hacking, doxing, and other forms of cybercrimes. Over 20 million people worldwide could have been exposed to this leak. Users are advised change their passwords or to switch to a more secure VPN service provider.

Advertisement

 


Why do Indians love Xiaomi TVs so much? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Advertisement

 

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Mars and Jupiter Probes on Watch as Interstellar 3I/ATLAS Nears Sun
  2. This Is When Apple Can Announce Its October Event
  3. Lava Bold N1 Lite Listed on Amazon Ahead of Official Launch in India
  4. Samsung Launches Galaxy A07, Galaxy F07, and Galaxy M07 4G in India
  1. Mars and Jupiter Probes Set to Monitor Interstellar Comet 3I/ATLAS During Its Sun Approach This Month
  2. M5 iPad Pro, AirTag 2 Launch Countdown: This Is When Apple Can Announce October Event
  3. WhatsApp for Android Said to Be Testing a Feature That Lets Users Reserve Their Usernames
  4. Samsung Galaxy A07, Galaxy F07, and Galaxy M07 4G Launched in India: Price, Specifications
  5. Lava Bold N1 Lite With 5,000mAh Battery Listed on Amazon Ahead of Launch: Price in India, Specifications
  6. Samsung Galaxy Z Fold 7 Special Edition China Launch Date Announced: Expected Features
  7. Google Said to Be Testing ‘More Efficient’ MediaTek Modem for Pixel 11 Series
  8. Call of Duty: Black Ops 7 Beta Early Access Goes Live as Players Report Cheating
  9. Department of Consumer Affairs to Probe E-Commerce Platforms Over Hidden Cash-on-Delivery Charges
  10. Ubisoft Launches Tencent-Backed Subsidiary, Vantage Studios, to Run Assassin's Creed, Far Cry, and Rainbow Six
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.