The VPN incident timeline

Every logging scandal, breach, seizure and data sale we could document - from HideMyAss handing over LulzSec logs (2011) to the raids that found nothing (Mullvad 2023). This is the industry's receipt drawer.

  • 2026
    Mullvad co-founder revealed as main financer of Swedish far-right party ownership-scandal

    Swedish weekly Flamman revealed Mullvad founder/part-owner Daniel Berntsson donated 5M SEK in 2025 to Örebropartiet, which advocates 'remigration' (mass deportation). Mullvad calls it a private matter and notes the co-owners disagree; reported single-source (Flamman), with company response on record.

    evidence: Flamman →

  • 2026
    Darktrace documents Hola exit nodes used for malware and cryptomining other

    Eleven years after the 2015 exit-node scandal, Darktrace reported criminal abuse of Hola's user-powered proxy network for malware delivery and cryptomining. Hola's business model is still to route strangers' traffic through its users' machines.

    evidence: Darktrace →

  • 2026
    Operation Saffron dismantles 'First VPN' used by ransomware gangs seizure

    A global law-enforcement operation seized a bulletproof VPN service ('First VPN') used by roughly two dozen ransomware gangs, spanning 33 servers, and arrested an administrator. Continues the DoubleVPN (2020) and VPNLab (2022) takedown lineage.

    evidence: TechCrunch →

  • 2026
    Dutch authorities seize a Windscribe server - allegedly without a warrant seizure

    Windscribe said Dutch law enforcement took one of its servers in early February 2026, which the company alleged happened without a warrant; no user data was exposed. Follows the 2021 Ukraine seizure - Windscribe keeps operating through seizures without losing its no-logs story.

    evidence: CyberInsider →

  • 2026
    Perfect Privacy goes dark without a word other

    Perfect Privacy - a once-revered Swiss multi-hop no-logs VPN - stopped responding in 2025 and its site was fully offline by end of January 2026; no shutdown notice, no refunds process, subscribers' money gone. The cautionary tale for small privacy VPNs and for paying yearly.

    evidence: CyberInsider →

  • 2025
    PureVPN Linux client leaks IPv6 traffic after reconnect vulnerability

    An independent researcher documented that PureVPN's Linux clients (GUI and CLI) leak IPv6 traffic outside the tunnel after a network transition even with the kill switch enabled, while the UI reports 'connected'. Unfixed at disclosure time; vendor had already claimed kill-switch audit coverage.

    evidence: Anagogistis (independent researcher) →

  • 2025
    Windscribe co-founder cleared in Greek criminal case - no logs to give logs-court

    Windscribe's co-founder was criminally charged in Greece (via an INTERPOL MLAT) after one of its exit IPs was used to breach a server. The case collapsed in Windscribe's favour because the company provably holds no user logs. Second provider after PIA and Mullvad whose no-logs claim survived a criminal process.

    evidence: Windscribe (operator) →

  • 2025
    VPNSecure's new owners cancel all lifetime subscriptions ownership-scandal

    After an opaque sale (the Australian company had already relocated to Hong Kong in 2019), VPNSecure's new owners disabled every 'lifetime' account in April 2025, claiming they didn't know the plans existed, then offered no refunds. A consumer-rights scandal and a warning about lifetime VPN deals.

    evidence: Ars Technica →

  • 2024
    TunnelVision (CVE-2024-3661): DHCP routing trick decloaks VPN traffic vulnerability

    Leviathan showed a rogue DHCP server can push routing config that leaks VPN client traffic outside the tunnel, unaffected by kill switches. Decades-old DHCP flaw, industry-wide exposure; no single vendor at fault, all major platforms affected.

    evidence: Leviathan Security Group →

  • 2024
    Unsealed filings allege Onavo decrypted competitors' traffic other

    Documents unsealed in the FTC v. Meta case (March 2024) allegedly show Meta's Onavo VPN removed SSL encryption of rivals' analytics traffic and paid users to install it - the strongest evidence yet that 'free' VPNs operated by ad companies are wiretaps in waiting. Meta contests the characterisation; the filings speak for themselves.

    evidence: DocumentCloud / FTC filing →

  • 2024
    Avast fined $16.5M by FTC for selling browsing data via Jumpshot data-sale

    Antivirus/VPN giant Avast harvested detailed browsing data from its own products and sold it via subsidiary Jumpshot (exposed Jan 2020 by PCMag and Motherboard). The FTC's February 2024 settlement banned Avast from selling browsing data and imposed a $16.5M civil penalty. Avast also owns HideMyAss and AVG Secure VPN (via Gen Digital).

    evidence: FTC →

  • 2023
    TunnelCrack: most VPN clients leak traffic to local attackers vulnerability

    Academic research showed nearly every tested VPN client (Windows, macOS, iOS, Linux) was exploitable via 'localnet' or 'server IP' tricks that route traffic outside the tunnel. Affects the design of clients, not specific providers - several (incl. Mullvad) shipped mitigations after coordinated disclosure.

    evidence: TunnelCrack research site →

  • 2023
    Swedish police raid Mullvad - leave with nothing seizure

    Officers with a search warrant searched Mullvad's Gothenburg offices; because Mullvad stores no customer data, nothing could be seized and no customer was affected. The best-practice precedent for how a no-logs provider handles a raid.

    evidence: Mullvad (operator) →

  • 2022
    India's CERT-In directive forces 5-year logging; providers pull servers other

    The CERT-In directive required VPN providers to keep subscriber and IP logs for 5 years and report incidents in 6 hours. Proton, Mullvad and others removed physical Indian servers rather than comply; dozens of VPN apps were pulled from Indian app stores. A state-mandated logging regime, not a scandal - but the same effect.

    evidence: The Wall Street Journal →

  • 2022
    Europol takes down VPNLab.net seizure

    Europol-coordinated action seized VPNLab.net's infrastructure, alleging the service was used by ransomware and malware operators. Criminal-use VPNs are one seizure class; consumer VPNs are not affected by these.

    evidence: Europol →

  • 2021
    Zerodium offers bounties for 0-days in Windows VPN clients vulnerability

    Exploit broker Zerodium announced it would pay up to $1M+ for 0-days in NordVPN, ExpressVPN and Surfshark Windows clients - bugs that de-anonymise users or execute code. Same season, ExpressVPN disclosed a PATH-abuse privilege bug in its own Windows app.

    evidence: BleepingComputer →

  • 2021
    Kape buys ExpressVPN, now controls 4 big VPNs plus VPN review sites ownership-scandal

    Kape Technologies acquired ExpressVPN for $936M, putting an ex-adware company behind ExpressVPN, CyberGhost, PIA, ZenMate - and, via acquisition, popular 'independent' VPN review sites (vpnMentor, Wizcase). Industry consolidation plus conflicts of interest in one corporate group.

    evidence: CyberInsider (ex-RestorePrivacy) →

  • 2021
    ExpressVPN CIO exposed as UAE Project Raven operative ownership-scandal

    Reuters revealed ExpressVPN CIO Daniel Gericke was a paid operative in the UAE's Project Raven surveillance program and had signed an NSA-type non-disclosure plus a US deferred prosecution deal; Vice showed ExpressVPN knew 'key facts'. He stayed; the NSA fined him $335,000 in 2023. A surveillance-veteran running privacy product security.

    evidence: CyberInsider →

  • 2021
    Windscribe servers seized in Ukraine - no user logs found seizure

    Ukrainian authorities seized Windscribe servers in Kyiv over an abusive user. Servers were not full-disk encrypted (a real operational flaw Ars flagged), but no connection logs existed to hand over - the no-logs claim survived contact with law enforcement.

    evidence: Ars Technica →

  • 2021
    GeckoVPN / ChatVPN / SuperVPN user data sold on hacking forums data-sale

    In late February 2021 a seller offered a combined dataset of ~10M users (seller claimed 360M records) from SuperVPN, GeckoVPN and ChatVPN: emails, plaintext passwords, payment info and device IDs. Troy Hunt called it proof that trust in a VPN provider is crucial - these apps logged what they promised not to, then leaked it.

    evidence: Malwarebytes Labs →

  • 2020
    FBI/Europol seize DoubleVPN servers seizure

    An international operation seized DoubleVPN's servers and infrastructure, alleging the nested-connection VPN shielded ransomware and phishing crews. First of the modern criminal-VPN takedowns.

    evidence: TorrentFreak →

  • 2020
    OVPN wins court order: Swedish court rejects movie-company injunction - no data to hand over logs-court

    In September 2020 the Swedish Patent and Market Court rejected an information injunction brought by Rights Alliance against OVPN: the experts retained could not tie any user to torrent activity and OVPN produced no user data. Documented on the operator blog with court records.

    evidence: source →

  • 2020
    UFO VPN 'zero-log' app leaks 1.2TB database, ~23M users breach

    Chinese-owned (Hong Kong-registered Dreamfii) UFO VPN advertised a strict no-logs policy in its own marketing while leaving an open Elasticsearch cluster with 1.2TB of user logs, plaintext passwords and VPN session records for ~23M accounts. The same research wave flagged other Chinese-owned free VPN apps that summer.

    evidence: Comparitech →

  • 2020
    SuperVPN leaks 10 million user records breach

    The Android free VPN SuperVPN left user records - emails, passwords in weak form, payment data, device IDs - exposed and circulating from February 2020 (10M records; a larger ~360M-record dataset surfaced later). One of the worst free-VPN data dumps on record.

    evidence: Malwarebytes Labs →

  • 2019
    2019 leak cluster: TorGuard and VikingVPN server breaches surface alongside NordVPN's breach

    A trove of server configurations from 2017/2018 breaches of NordVPN, TorGuard and VikingVPN was posted publicly ('M' on 8chan/Telegram), with claims of captured TLS keys. TorGuard and VikingVPN confirmed older breaches of rented infrastructure; all three had promoted no-logging.

    evidence: TechRadar →

  • 2018
    Apple bans Facebook's Onavo VPN for traffic harvesting data-sale

    Apple kicked Facebook's Onavo Protect off the App Store for collecting app-usage data beyond its disclosed purpose; Facebook shut Onavo down in 2019. Unsealed filings in March 2024 alleged Onavo even decrypted competitors' (Snap, YouTube) analytics traffic.

    evidence: TechCrunch →

  • 2018
    PIA's no-logs policy holds up in court, twice logs-court

    In a 2016 FBI case (bomb threats) and again in June 2018, PIA was subpoenaed for user logs and could provide nothing beyond shared VPN server IP clusters - both documented in court records. The best-evidenced no-logs claim in the industry.

    evidence: CyberInsider (ex-RestorePrivacy) →

  • 2018
    NordVPN third-party server breached; disclosed 19 months late breach

    An attacker accessed a rented NordVPN server in a Finnish datacenter in March 2018, potentially extracting OpenVPN/TLS key material; NordVPN disclosed only in October 2019 after the 2019 leak cluster surfaced. Company says no usernames/passwords or traffic were exposed; the late disclosure is the scandal.

    evidence: NordVPN (operator) →

  • 2017
    PureVPN logs help FBI identify an alleged cyberstalker logs-proven

    PureVPN, sold as 'zero-log', produced connection logs that helped the FBI arrest an alleged cyberstalker in Massachusetts; the DOJ's own court filing shows the logs. PureVPN later said it would log only 'connection errors', a distinction nobody could audit.

    evidence: TorrentFreak →

  • 2016
    Crossrider adware platform rebrands as Kape Technologies adware

    Crossrider - whose developer platform monetised adware-infested browser installers - rebranded as Kape ('privacy tech') in 2016 and began buying VPNs: CyberGhost (2017), ZenMate, PIA (2019). The adware history is documented by Malwarebytes' own detection pages; Kape says it exited the business.

    evidence: CyberInsider (ex-RestorePrivacy) →

  • 2016
    PIA pulls out of Russia rather than run under server seizures seizure

    After Russian authorities began seizing VPN servers, Private Internet Access removed its entire Russian presence instead of operating under seizure - the good-kind precedent: exit a market rather than comply or log.

    evidence: TorrentFreak →

  • 2016
    IPVanish, a 'zero-log' VPN, handed DHS/HSI connection logs logs-proven

    Court records showed IPVanish gave Homeland Security a Comcast customer's real IP, session timestamps and hostname in 2014 despite advertising a strict no-log policy; a reddit post blew the whistle in 2016 and TorrentFreak confirmed from full filings in 2018. IPVanish was then sold twice more (StackPath 2017, j2 Global/Ziff Davis 2021).

    evidence: TorrentFreak →

  • 2016
    Proxy.sh withdraws entry from warrant canary, hints at gag order canary-gone

    Proxy.sh removed a line from its warrant canary covering node seizures/gag orders, implicitly signalling it may be under a secret order. The only documented warrant-canary death for a VPN provider.

    evidence: Ars Technica →

  • 2015
    Hola turns 10M+ users into exit nodes; bandwidth sold via Luminati (later Bright Data) other

    Researchers showed Hola's free tier turns user machines into exit nodes; an attacker used Hola exits for an 8chan DDoS, and Hola's bandwidth marketplace (Luminati, spun off as Bright Data) commercialised the same traffic. Bandwidth-sale business model built on user IPs.

    evidence: Newsweek →

  • 2013
    Proxy.sh VPN provider sniffed server traffic to catch a hacker logs-proven

    Proxy.sh confirmed it monitored a specific user's traffic on one US node to identify a harassment/hacking victim-tormentor, after emails from the target. Disclosed and narrow, but proof the provider can and will read traffic on its servers.

    evidence: TorrentFreak →

  • 2011
    HideMyAss logs help convict LulzSec member logs-proven

    HideMyAss published a blog post confirming it handed the FBI connection logs for user 'recoded' (Cody Kretsinger), who pleaded guilty to the Sony Pictures hack and was sentenced in 2013. The operator itself admitted it keeps data sufficient to identify users.

    evidence: HideMyAss (operator blog) →