← ActMobile (Dash VPN / FreeVPN)

2021 ActMobile (Dash VPN / FreeVPN) — exposed DB; HIBP 1.6M emails (unverified; company denied)

2021 1.6M records affected Share on X

Data compromised

Email addresses, IP addresses; broader account/device fields alleged by researchers (HIBP: emails + IPs)

Technical writeup

Unverified exposure claim: in October 2021, researcher Bob Diachenko and Comparitech reported an unprotected database whose SSL certificate and contents pointed to ActMobile—operators associated with Dash VPN and FreeVPN—including large volumes of account and device-related records (Comparitech described on the order of tens of millions of user/device rows). Have I Been Pwned subsequently loaded about 1.6 million unique email addresses plus IP addresses and (in early reporting) password hashes that later circulated on a hacking forum. ActMobile denied the data was theirs; HIBP flags the breach as unverified. Social posts sometimes cite “~10M” emails—that figure is not the HIBP attested unique-email count (1.6M). Catalogued with the HIBP email count and clear unverified/denial labeling.

Root cause

Unverified — allegedly exposed Elasticsearch/database attributed to ActMobile VPN brands; company denied

References