• Home
  • Apps
  • Apps News
  • Seven VPN Services Including UFO VPN, Rabbit VPN, Fast VPN Leaked Over 1.2TB of Private User Data: Report

Seven VPN Services Including UFO VPN, Rabbit VPN, Fast VPN Leaked Over 1.2TB of Private User Data: Report

VPN services are supposed prevent ISPs from tracking user data — but, a new report has found seven VPN apps have leaked private data.

Share on Facebook Tweet Snapchat Share Reddit Comment
Seven VPN Services Including UFO VPN, Rabbit VPN, Fast VPN Leaked Over 1.2TB of Private User Data: Report

Photo Credit: Google Play store

UFO VPN and many other apps are still listed on the Google Play store

Highlights
  • VPN apps found to have leaked over 1.2TB of private data
  • UFO VPN, Fast VPN, Rabbit VPN, Secure VPN are some of them
  • They reportedly have a common recipient for payments

Virtual Private Network or VPN services including UFO VPN, Rabbit VPN, Free VPN, and four more have been found to have leaked over 1TB of private user information, as per a new report. A report stated that these VPNs exposed a database of user logs and API access records without a password or authentication. A separate report pointed out that UFO VPN was just one of the several VPN service providers that were leaking private information.

At the start of July, Comparitech found that Hong Kong-based VPN provider UFO VPN exposed personal user information like plain text passwords, VPN session secrets, IP addresses, connection timestamps, geo-tags, and device and OS characteristics. The company was informed about the same and more than two weeks later, it reportedly fixed the issue, stating that no information was leaked. The leak affects both free and paid customers and reportedly all users of the service are potentially affected, taking the number to 20 million users. This amounts to 894GB of leaked data.

Following this discovery, vpnMentor found that UFO VPN was not the only one and six others that were seemingly connected to a common app developer and white labeled for other companies were found to be doing the same. These include Fast VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, and Rabbit VPN. Notably, all of these apps claim they do not log any user original IP address or user activity. It was found that a total of 1.2TB of data was leaked.

The good news is that the biggest VPN companies that most people probably use, have not been implicated in this report.

The team at vpnMentor found that the VPNs share an Elasticssearch server, have a single recipient for payments, Dreamfii HK Limited, and share a lot of the assets. They reached out to the various VPN services involved and while some of them did not respond, others stated after several days that the issue had been fixed. Most of these VPN apps are still listed on the Google Play store.

Potential impact of data leak

This data leak could lead to phishing and fraud, blackmail, viral attack, hacking, doxing, and other forms of cybercrimes. Over 20 million people worldwide could have been exposed to this leak. Users are advised change their passwords or to switch to a more secure VPN service provider.

 


Why do Indians love Xiaomi TVs so much? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

 

Comments

For the latest tech news and reviews, follow Gadgets 360 on Twitter, Facebook, and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel.

Vineet Washington Vineet Washington writes about gaming, smartphones, audio devices, and new technologies for Gadgets 360, out of Delhi. Vineet is a Senior Sub-editor for Gadgets 360, and has frequently written about gaming on all platforms and new developments in the world of smartphones. In his free time, Vineet likes to play video games, make clay models, play the guitar, watch sketch-comedy, and anime. Vineet is available on vineetw@ndtv.com, so please send in your leads and tips. More
Airtel Xstream Broadband Users Can Get Xstream Box at a Refundable Security Deposit of Rs. 1,500
 
 

Advertisement

Advertisement

© Copyright Red Pixels Ventures Limited 2020. All rights reserved.
Listen to the latest songs, only on JioSaavn.com