[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz7hyyommi2e6":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":10,"seoTitleEn":33,"seoDescription":10,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda4882539e","SuperVPNGeckoVPN","SuperVPN & GeckoVPN Data Breach","supervpn-geckovpn","","2021-02-25T00:00:00.000Z","2021-02-28T22:30:29.000Z","2021-02-28T22:49:32.000Z","2026-07-19T19:48:54.437Z","Third party breach","https:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fone-of-the-biggest-android-vpns-hacked-data-of-21-million-users-from-3-android-vpns-put-for-sale-online\u002F",[16,18,19],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20210226221214\u002Fhttps:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fone-of-the-biggest-android-vpns-hacked-data-of-21-million-users-from-3-android-vpns-put-for-sale-online\u002F","https:\u002F\u002Fplay.google.com\u002Fstore\u002Fapps\u002Fdetails?id=com.jrzheng.supervpnfree&hl=en_US",20339937,"known",null,"unknown","Critical",[26,27,28,29,30,31],"Device information","Device serial numbers","Email addresses","Geographic locations","IMSI numbers","Login histories","\u003Cp>\u003Cstrong>The SuperVPN &amp; GeckoVPN data breach\u003C\u002Fstrong> exposed email, device, location and login information linked to 20,339,937 accounts in February 2021.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>\u003Cstrong>The confirmed data classes\u003C\u002Fstrong> are email addresses, device information, device serial numbers, IMSI numbers, geographic locations and login histories. The geographic field represents the country from which a login occurred; it does not establish that precise GPS coordinates were exposed. Login histories may show the dates and times at which a person accessed the service. An email address can be used for direct contact and account correlation, increasing the likelihood of targeted phishing. Persistent identifiers such as serial and IMSI numbers can make it easier to connect separate records to the same device. Passwords, usernames, full names and payment details are not among the verified classes for this dataset, so early claims about those fields are not presented here as confirmed exposure.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The canonical incident date is 25 February 2021. Initial reporting published the following day described a forum user offering archives associated with several free Android VPN services for sale. The subsequently verified set of 20,339,937 unique email records was catalogued under SuperVPN and GeckoVPN; a small number of records associated with a third VPN application appeared in the same file, suggesting that the services may have shared a platform or data infrastructure. The original sales claim referred to publicly reachable databases and default access credentials, but that access method was not independently established as the definitive cause. The record is classified as a verified breach, not a credential compilation, information-stealing malware output or an allegation supported only by an untested forum post.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people at greatest risk are those who used either the SuperVPN or GeckoVPN Android application by early 2021 and connected to the service with an email address. Anyone who used the same address for other accounts may receive more convincing messages that refer to VPN use. Country information and login timestamps could help a scammer tailor a message around travel, connection trouble or a subscription renewal. A device model, serial number or IMSI does not reveal an account password by itself, but it can strengthen social-engineering attempts designed to imply that the sender already knows the user or device. Precise GPS coordinates, message contents, browsing history and internet traffic carried through the VPN are not part of the confirmed scope and should not be inferred from this record.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>Your first priority\u003C\u002Fstrong> is to review the email account associated with SuperVPN or GeckoVPN for unfamiliar sessions, security alerts and unexpected password-reset requests. Enable multi-factor authentication on the mailbox and prefer an authenticator app, passkey or hardware security key over SMS where available. If the application remains installed, confirm its version and developer through the official app store; remove it if it is no longer needed, then review Android app permissions and saved VPN profiles for residual access. You should still replace any weak or reused password on the related email account with a strong, unique one. Do not follow links in messages claiming to offer VPN support, subscription renewal, device verification or refunds; begin any legitimate action through the saved app-store listing or another verified service channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Do not choose a VPN solely because it has a large installation count or is advertised as free. Check whether the provider identifies a legal entity, maintains reachable support, publishes a current privacy policy, undergoes independent security assessment and has a process for notifying users about incidents. A “no logs” statement is not sufficient on its own; read what the service collects for account creation, diagnostics, advertising and subscription functions. Leave sign-in alerts enabled on your email account and periodically verify its recovery address and phone number. An IMSI or device serial number cannot be rotated like a password, so possession of either value should never be treated as proof that a caller or message is legitimate. If your mobile carrier offers an additional account PIN or security passcode, enable it as another layer against SIM-swap and account-takeover attempts.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>To determine whether you appear in the SuperVPN &amp; GeckoVPN record, check each email address you may have used with either service through a trusted breach-search tool. Treat a match as evidence that the address appears in the verified dataset alongside device and login metadata, not as proof that your password was obtained. Include older addresses because an address changed after 2021 may still be present in the historical record. Enabling ongoing breach alerts will help you respond more quickly if the same address is found in another incident later. Never enter an IMSI or device serial number into a breach-check form and do not disclose those identifiers to an unsolicited caller or message sender. Use results only to make decisions about your own account security, not to infer another person's VPN activity or query other people's addresses without permission.\u003C\u002Fp>","SuperVPN & GeckoVPN Data Breach (20.3 Million Reported Records)","SuperVPN & GeckoVPN Data Breach. 20.3 Million reported records were reported. Reported data: Device information, Device serial numbers, Email addresses…","\u002Fuploads\u002Flogo\u002Fsuper_vpngecko_vpn.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":22},"SuperVPN & GeckoVPN","Technology","Unknown"]