The LimeVPN Data Quietly Appeared on Dark Web Markets in October 2020
HEROIC analysts identified the LimeVPN database breach in October 2020 while monitoring dark web marketplaces where the data was being offered for sale. The breach occured at LimeVPN, a VPN provider based in Iceland, and exposed 15,126 user records. The leaked data included email addresses, phone numbers, password hashes, IP addresses, and credit card information, making this one of the more sensitive breach datasets given LimeVPN's position as a privacy-focused service.
How Exposed VPN Credentials, Credit Card Data, and IP Addresses Create Layered Risk
The combination of credit card data, phone numbers, and email addresses from a VPN provider is partcularly dangerous. Attackers can use the credit card details for fraud, the email and phone combinations for account takeover and SIM swapping, and the IP address records to map which corporate or home networks the affected users connected from. The MD5(Salt) password hashes used by LimeVPN are accessable to attackers with modern cracking hardware, meaning plaintext passwords are likely already available to those who purchased this dataset.
What Was Exposed in the LimeVPN Breach
- Email Address
- Phone Number
- Password Hash
- IP Address
- Credit Card
Why a VPN Provider Breach Undermines the Privacy It Promised
Users choose VPN services specifically to protect their online privacy and location data. When a VPN provider suffers a database breach, the irony is stark: the IP addresses and connection data that users beleived were protected are now in the hands of the very threat actors those users were trying to avoid. For corporate employees who used LimeVPN on work networks, the exposed IP addresses could reveal internal network ranges and browsing patterns that should have remained confidential.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to the stored records of a service provider, typically by exploiting vulnerabilities in the platform's web application, administrative interfaces, or third-party dependencies. Once the database is extracted, the data is sold through dark web markets or shared in private criminal channels. Databases containing financial data like credit card records command higher prices and attract more sophisticated buyers.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across 400 billion leaked records to determine whether your email address, phone number, or other personal data from LimeVPN or any other breach is currently circulating in criminal markets. Run a free scan now to understand your full exposure and take steps to secure your accounts.
Breach Breakdown
15,126 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds