
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
What happened
In February 2021, a series of "free" VPN services were breached including SuperVPN and GeckoVPN, exposing over 20M records. The data appeared together in a single file with a small number of records also included from FlashVPN, suggesting that all three brands may share the same platform. Impacted data also included email addresses, the country logged in from and the date and time each login occurred alongside device information including the make and model, IMSI number and serial number.
Data exposed
Frequently asked questions
The SuperVPN & GeckoVPN data breach occurred on February 25, 2021. It was added to Have I Been Pwned's breach catalog on February 28, 2021.
20,339,937 accounts were affected by the SuperVPN & GeckoVPN data breach, according to Have I Been Pwned's records.
The SuperVPN & GeckoVPN breach exposed the following data types: Device information, Device serial numbers, Email addresses, Geographic locations, IMSI numbers, Login histories.
Yes. Have I Been Pwned has verified the SuperVPN & GeckoVPN breach, meaning there's confirmed evidence the exposed data is genuine and tied to real accounts.
Use KazaSec's free Email Breach Checker (/tools/breach-check) to check whether a specific email address has surfaced in the SuperVPN & GeckoVPN breach, or any other known breach — the tool never stores what you search.
Our free Email Breach Checker tells you whether a specific email address has surfaced in this breach — or any other known breach — without ever storing what you search.
Check your email →Talk to us about this
We help organizations find and fix the gaps that lead to a breach, before they do.