SuperVPN / GeckoVPN / ChatVPN 21 Million Users Exposed — February 2021
If you are a customer of SuperVPN / GeckoVPN / ChatVPN, here’s what’s now in circulation.
A breach of SuperVPN, GeckoVPN, and ChatVPN exposed approximately 21 million user records — including connection metadata that contradicts the providers' "no-logs" marketing claims.
A breach of SuperVPN, GeckoVPN, and ChatVPN in February 2021 exposed approximately 21 million user records, including connection metadata. The exposed data appears to contradict the providers' public "no-logs" marketing claims — a recurring pattern across consumer VPN providers in recent years.
Watch SuperVPN / GeckoVPN / ChatVPN
Get alerted the next time SuperVPN / GeckoVPN / ChatVPN files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about SuperVPN / GeckoVPN / ChatVPN’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.
For privacy-focused users — streamers protecting personal IP addresses, journalists, activists, executives traveling in restrictive jurisdictions — this breach is a reminder that "no-logs" claims are only as trustworthy as the provider's actual operational discipline. When a VPN provider gets breached, the privacy guarantee evaporates regardless of marketing language.
Recommended VPN posture
What You Should Do
- Stop using SuperVPN, GeckoVPN, and ChatVPN immediately
- Switch to a reputable, audit-verified provider (Mullvad, IVPN, ProtonVPN)
- Choose providers that have been independently security-audited
- For maximum privacy, run your own WireGuard server on a trusted VPS
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Instructure Canvas LMS suffers massive data theft affecting 275M users
Education technology company Instructure confirmed a breach of its Canvas learning management system…
"No-Logs" VPN Claims Crack Under SuperVPN Lesson — Privacy Analysis
The SuperVPN/GeckoVPN/ChatVPN 21M breach (article #54) exposed connection metadata that contradicts …
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…