[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1k2zq9vemc0pw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":31,"seoTitle":16,"seoTitleEn":32,"seoDescription":16,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825276","lime-vpn","LimeVPN Data Breach","limevpn","limevpn.com","2020-10-08T00:00:00.000Z","2023-02-06T21:42:01.000Z","2026-07-03T15:12:04.419Z","2026-07-18T23:53:26.953Z","Third party breach","",[],23348,"known",null,"unknown","Medium",[24,25,26,27,28,29,30],"Email addresses","IP addresses","Names","Passwords","Phone numbers","Physical addresses","Purchases","\u003Cp>The LimeVPN data breach is a customer data incident from October 2020 associated with the VPN provider LimeVPN. The record contains 23,348 unique email addresses. The data classes include email addresses, IP addresses, names, passwords hashed with salted MD5, phone numbers, physical addresses, and purchase history. Due to the context of the VPN service, the expectation of privacy and the risk of payment\u002Fsubscription fraud are significant.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>VPN users usually receive the service with an expectation of privacy; therefore, the impact of the incident increases when the IP address, physical address, purchase history, and account information are found together. Salted MD5 password hashes may be considered weak by modern standards and pose a risk to other accounts if the password is reused.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, address, username, or location come together, attackers can approach the user as if there is a real service relationship. This information alone does not always mean account takeover; however, it can be used for phishing, fake support requests, account verification, and personalized fraud flows. The record does not list the full payment card field. Purchase history and contact information can be used in fake subscription renewal, refund, security alert, or payment update messages. The combination of IP and address increases privacy sensitivity.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is October 8, 2020, and the number of affected emails is recorded as 23,348. Reliable records show that LimeVPN customer data included email, IP and physical address, name, phone, purchase history, and salted MD5 password hashes. The existing data categories are compatible with this scope.\u003C\u002Fp>\u003Cp>When the scope is explained, no additional claim is made as if the entire VPN traffic content or connection logs have been leaked. These records should be evaluated through customer account, communication, purchase, and password fields.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have a LimeVPN account, have purchased a subscription, and have shared contact information. People using a privacy service may be more sensitive to targeted blackmail, fake security alerts, or account renewal messages.\u003C\u002Fp>\u003Cp>Those who use the same password on other accounts are prioritized. Users with a physical address and IP area should be careful against fake legal warning, invoice, or security threat messages.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching area should change their passwords on LimeVPN and on all accounts where the same password is used. Subscription and payment notifications should be verified from the official panel, and suspicious security alerts should not be opened through a link.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Email and payment information used in VPN and privacy services should be separated as much as possible. A password manager, two-factor authentication, and regular account closure\u002Fsubscription cleanup reduce long-term risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found within this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result is important in terms of the risk of being targeted in the context of a VPN account and privacy. A negative result means there is no match in this record; the same email should also be checked in other privacy or hosting services.\u003C\u002Fp>","LimeVPN Data Breach (23.3 Thousand Reported Records)","LimeVPN Data Breach. 23.3 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Flimevpn_com.webp",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"LimeVPN","VPN \u002F Privacy Service","Global"]