LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › SuperVPN & GeckoVPN Data Breach (2021)

HIGH severityConfirmedHow we verify

SuperVPN & GeckoVPN Data Breach (2021): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·February 25, 2021

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

SuperVPN & GeckoVPN Data Breach (2021)

Reported February 25, 2021. Approximately 20.3M people affected.

HIGH
Severity
20.3M
People affected
6
Data types exposed
February 25, 2021
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The SuperVPN & GeckoVPN Data Breach (2021) (reported February 25, 2021) exposed Device information, Device serial numbers, Email addresses and Geographic locations belonging to roughly 20.3M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the SuperVPN & GeckoVPN Data Breach (2021) breach?
20.3M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In February 2021, records from SuperVPN and GeckoVPN were exposed in a single dataset that also contained a small number of entries from FlashVPN. The incident, reported on 25 February 2021, involved 20.3 million records containing device information, device serial numbers, email addresses, geographic locations, IMSI numbers and login histories. The presence of data from multiple brands in one file indicates that the services may have operated on a shared platform.

Breaking down the breach

The records became public in a single file that combined data from the named services. Reported details state that the file included email addresses together with the country from which each login occurred and the date and time of those logins. Device fields listed the make and model of the handset or router, its IMSI number and its serial number. No information has been released on how the file was obtained or on the exact date range of the logins it contained.

How a breach like this happens

Services that maintain large volumes of authentication and device data can lose control of that data through unauthorised access to storage systems or through misconfigured repositories that allow public retrieval. When multiple brands share the same backend infrastructure, a single point of exposure can surface records belonging to all of them at once. The method used in any specific case remains undisclosed unless the operators publish a technical report or an independent investigation releases findings.

SuperVPN & GeckoVPN and its sector

SuperVPN and GeckoVPN are among the consumer virtual-private-network applications that market themselves as free or low-cost options for encrypting internet traffic and masking IP addresses. Providers in this sector routinely collect account identifiers, connection timestamps and device identifiers to manage sessions and enforce usage limits. Because these services handle traffic from many users who may not review privacy policies in detail, the datasets they hold can include both account details and technical information that links a person to specific devices and locations.

What was likely exposed

The published facts list the exposed fields as device information, device serial numbers, email addresses, geographic locations, IMSI numbers and login histories. These categories correspond to the contents described in the February 2021 file. No further categories have been confirmed, and the operators have not released an inventory of every field present in the dataset.

What's at stake

Email addresses combined with login timestamps and device identifiers can be used to map an individual’s online activity over time and to target further attempts at account access. IMSI and serial numbers can assist in linking a record to a specific handset, which may be relevant in investigations or in attempts to profile a user across services. The organisation faces the operational task of securing the affected systems and notifying users whose records appeared in the file.

Were you affected?

Individuals who used SuperVPN or GeckoVPN can check whether their email address appears in known breach datasets by running a free exposure scan through a reputable service that aggregates public breach records. Changing passwords for any associated accounts and reviewing connected devices for unfamiliar activity are standard first steps when email addresses and device identifiers have been exposed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanySuperVPN & GeckoVPN security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See SuperVPN & GeckoVPN’s full breach history →

More recent breaches

ZAP-Hosting Data Breach (2021)November 22, 2021Stripchat Data Breach (2021)November 5, 2021Robinhood Data Breach (2021)November 3, 2021CoinMarketCap Data Breach (2021)October 12, 2021

Latest breaches

Read GalaxyWarden’s full analysis of the SuperVPN & GeckoVPN Data Breach (2021) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram