On February 23, a VPN Broke Its Own Promise: RinVPN Leaked 9,035 Users
HEROIC found 9,035 records in RinVPN on 23-Feb-2025, exposing email addresses, IP addresses, and bcrypt password hashes from a VPN service that was supposed to keep those exact details private.
Why This RinVPN Breach Is Dangerous
February 23, 2025 is the date that matters here. That is when RinVPN, a Vietnamese VPN provider running at rinvpn.net, leaked a full user database into the hands of attackers. The irony is the whole product. People pay a VPN specifically to keep their IP address off the open internet. RinVPN's own database then leaked those same IP addresses alongside the email accounts that paid for the service.
For a VPN user, deanonymization is the worst case scenario. An IP address tied to a real email address removes the protection they were buying. If the user signed up to evade surveillance, circumvent regional controls, or access sensitive content anonymously, this leak is the opposite of what they paid for.
What Was Exposed in RinVPN
- 9,035 user records dated 23-Feb-2025
- Email addresses used to create RinVPN accounts
- IP addresses tied to customer sessions, the most sensitive field for a VPN leak
- bcrypt password hashes, not plaintext but still crackable for weak passwords
- Breach type recorded as a Database compromise, with the data listed in English
Why This Matters
Most VPN users assume their provider keeps zero logs. The presence of IP addresses inside the RinVPN dataset tells you this particular provider did keep them, or at least kept enough operational data that IPs could be exported. For anyone in Vietnam using the service to protect politically sensitive browsing, business communication, or personal privacy, that is a material risk, not an abstract one.
The bcrypt hashing is a partial silver lining. bcrypt is slow to crack, which buys time. It does not solve the problem, because a determined attacker with a GPU rig can still break weak or common passwords. Any RinVPN user who reused their VPN password on other services should assume that password is exposed and rotate it across every account.
How VPN Provider Breaches Like RinVPN Happen
Smaller VPN providers often run their billing and account systems on commodity stacks separate from the VPN traffic nodes themselves. That customer database is the part that leaks. Attackers usually gain entry through SQL injection, an unpatched admin panel, or stolen operator credentials. Once inside, they export the user table and post it on forums or Telegram, either for reputation or sale.
The fact that RinVPN stored IP addresses at all is the structural failure. Privacy focused VPNs that genuinely run a no logs policy should not have IPs to leak in the first place.
Check If You Are Affected
HEROIC indexes more than 400 billion compromised records across the dark web and underground marketplaces where the RinVPN data is now circulating. A single free scan checks your email, IP, and password fingerprint against this breach and the wider dataset. If you have ever used RinVPN, scan now, rotate the password anywhere else you used it, and consider moving to a provider with an independently audited no logs record.
Breach Breakdown
9,035 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds