Many people use VPN services when downloading applications or visiting other websites across regions. Some VPN services are advertised as being log-free and do not record user behavior and will not share it with others. Based on the general principle of trust, users do not think too much about this matter. However, a security research company recently discovered that 7 VPN services leaked up to 1.2TB of user data. Users, whether free or paid, should be careful.

7 VPN services were found to have leaked 1.2TB of user data, and only one has been removed from the market now
According to security research unit Comparitech According to research, UFO VPN, a VPN service provider headquartered in Hong Kong and with more than 10 million Play Store installation downloads, found that the company disclosed user logs and API access records on the Internet. Ordinary people can access and view them without entering a password or any identity verification. The disclosed information includes plain text passwords and IP information, operating systems, etc. that can identify VPN users and track their online activities. The vulnerability affects both free and paid users, and according to Comparitech, more than 20 million entries are added to the log every day, and UFO VPN happens to have 20 million users on its website with 894GB of data. Security personnel issued a warning to the service provider on the day they discovered the unprotected database (7/1), calling attention to the setting errors but there was no corresponding response or improvement.

until 7/5,VPNmentor The discovery of this security vulnerability is not limited to UFO VPN. A total of 7 Hong Kong VPN providers, UFO VPN, FAST VPN, Free VPN, Super VPN, Flash VPN, Secure VPN and Rabbit VPN, all share a common code and infrastructure White Label VPN. Information about these VPN vendors is also being leaked, and each service has between 10,000 and 1 million installation downloads, bringing the total leaked data to 1.2TB. All VPN services share a public Elasticsearch server and have the same payment recipient, Dreamfii HK Limited. Three of the services even have almost identical official websites (see the picture below), and these services still advertise no logs on their own websites, which is really ironic.

Currently, only Rabbit VPN has been removed from the Play Store, and other services are still available for download and installation. Consumers should be extra careful when choosing a VPN. Do not overly trust the statements made by various websites and services, and do not arbitrarily disclose their own relevant information on the Internet. Choosing a trustworthy VPN is the first step to protect yourself.
◎Data source:Comparitech、VPNmentor
Source: KOCPC Chinese