SuperVPN & GeckoVPN Data Breach (2021): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The SuperVPN & GeckoVPN Data Breach (2021) (reported February 25, 2021) exposed Device information, Device serial numbers, Email addresses and Geographic locations belonging to roughly 20.3M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Breaking down the breach
The records became public in a single file that combined data from the named services. Reported details state that the file included email addresses together with the country from which each login occurred and the date and time of those logins. Device fields listed the make and model of the handset or router, its IMSI number and its serial number. No information has been released on how the file was obtained or on the exact date range of the logins it contained.
How a breach like this happens
Services that maintain large volumes of authentication and device data can lose control of that data through unauthorised access to storage systems or through misconfigured repositories that allow public retrieval. When multiple brands share the same backend infrastructure, a single point of exposure can surface records belonging to all of them at once. The method used in any specific case remains undisclosed unless the operators publish a technical report or an independent investigation releases findings.
SuperVPN & GeckoVPN and its sector
SuperVPN and GeckoVPN are among the consumer virtual-private-network applications that market themselves as free or low-cost options for encrypting internet traffic and masking IP addresses. Providers in this sector routinely collect account identifiers, connection timestamps and device identifiers to manage sessions and enforce usage limits. Because these services handle traffic from many users who may not review privacy policies in detail, the datasets they hold can include both account details and technical information that links a person to specific devices and locations.
What was likely exposed
The published facts list the exposed fields as device information, device serial numbers, email addresses, geographic locations, IMSI numbers and login histories. These categories correspond to the contents described in the February 2021 file. No further categories have been confirmed, and the operators have not released an inventory of every field present in the dataset.
What's at stake
Email addresses combined with login timestamps and device identifiers can be used to map an individual’s online activity over time and to target further attempts at account access. IMSI and serial numbers can assist in linking a record to a specific handset, which may be relevant in investigations or in attempts to profile a user across services. The organisation faces the operational task of securing the affected systems and notifying users whose records appeared in the file.
Were you affected?
Individuals who used SuperVPN or GeckoVPN can check whether their email address appears in known breach datasets by running a free exposure scan through a reputable service that aggregates public breach records. Changing passwords for any associated accounts and reviewing connected devices for unfamiliar activity are standard first steps when email addresses and device identifiers have been exposed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ZAP-Hosting Data Breach (2021)Stripchat Data Breach (2021)Robinhood Data Breach (2021)CoinMarketCap Data Breach (2021)Latest breaches
Read GalaxyWarden’s full analysis of the SuperVPN & GeckoVPN Data Breach (2021) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.