The personal details and login credentials of 21 million users of VPN companies like SuperVPN, GeckoVPN, and ChatVPN was leaked in a Telegram group.
The the leaked records comprised 10GB of data and exposed 21 million unique records including full names, user names, country, billing details, email addresses, password strings etc.
The database was previously put up for sale on the Dark Web last year, but currently, it is available on Telegram for free.
The people who got their data exposed in the breach might become victims of blackmail, phishing scams, or identity theft since their full names and emails are leaked.
Source: https://www.hackread.com/personal-details-supervpn-geckovpn-users-telegram-leaked/
TPRM report: https://scoringcyber.rankiteo.com/company/super-vpn
"id": "sup211221822",
"linkid": "super-vpn",
"type": "Breach",
"date": "05/2022",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of a geographical region"
{'affected_entities': [{'customers_affected': 21000000,
'industry': 'VPN Services',
'name': 'SuperVPN',
'type': 'Company'},
{'customers_affected': 21000000,
'industry': 'VPN Services',
'name': 'GeckoVPN',
'type': 'Company'},
{'customers_affected': 21000000,
'industry': 'VPN Services',
'name': 'ChatVPN',
'type': 'Company'}],
'attack_vector': 'Data Leak',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': 21000000,
'personally_identifiable_information': 'Full names, email '
'addresses',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal details, login '
'credentials'},
'description': 'The personal details and login credentials of 21 million '
'users of VPN companies like SuperVPN, GeckoVPN, and ChatVPN '
'were leaked in a Telegram group.',
'impact': {'data_compromised': 'Full names, user names, country, billing '
'details, email addresses, password strings',
'identity_theft_risk': 'High'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes'},
'title': 'Data Leak of VPN Companies',
'type': 'Data Breach'}