Breadcrumb

  • Home
  • VPN - not as secure as you thought. And sometimes not at all.

Search form

Main navigation

  • Home

HOME | ALL TECHNOLOGY

VPN - not as secure as you thought. And sometimes not at all.

Friday, 22 May, 2026 - 00:19

The USA's Federal Bureau of Investigation has taken down "First VPN Service" . So has Europol. So they both say in public statements.

But there's a problem.

More than 12 hours after the notices were issued, and because we wanted to find the company's logo to insert in this article, we found this:

dead not dead - First VPN Service

Then we found something else. This isn't "First VPN Service" it's "First VPN" , a service.  In fact, there is no connection between this and the site we were looking for. We've been misled by a search engine. 

So we fiddled about and found that the site we were looking for is at 1vpns.com. 

And that, we discovered not at all to our surprise, is a Russian site hiding behind Cloudflare. If you want to know what we think of that shower criminal-helping irritants, just search WMLR. 

The FBI, to whom we have reported Cloudflare for its support for criminals but received no reply, says 

First VPN Service's website was accessible at 1vpns[.]com, 1vpns[.]org, and 1vpns[.]net, as well as an onion service accessible via the Tor Network. First VPN Service also hosted a Jabber server at 1jabber[.]com. 

It makes no mention of Cloudflare. 

The FBI says "

 This operation was conducted by France’s Direction Régionale de la Police Judiciaire Brigade de Lutte Contre la Cybercriminalité (BL2C), and the Dutch National Police, National High Tech Crime Unit (NHTC), with assistance from Ukraine, the United Kingdom,
Switzerland, and Luxembourg.

It was the French who, readers will remember, ultimately broke, with huge help from others, the Encrochat network (and then proved to be a bit too possessive about the information they gathered, hampering investigations in countries they had worked with) and the less well known (this time with the Dutch) Matrix network. 

OK, so that 's the political stuff out of the way. Now onto what happened with First VPN Service and why does it matter.

VPN PRIVACY IS OFTEN A MYTH. 

It is widely - but not widely enough - known that many VPN providers claim that they do not keep logs but that statement is often not true. Across the internet, your traffic may be hidden (ish) from your ISP but it is not hidden from the VPN operator. Of course not. Even a three year old knows that every touch leave a trace and that's why there's jam on the door knob proving that the child did, in fact, leave the room when told not to. 

Of course, there are more complex explanations, too. 


<h3>For an examination of Forensics relevant to Financial Crime see https://youtu.be/Ks-qpNbwKTM?si=j2NlcDMHMEtoSVUZ</h3>


A VPN, a virtual private network, is a program that sits on a server somewhere between you and the website you want to visit. All kinds of claims are made for them, some true and some true-ish but exaggerated. Some claims are completely false.

The one thing you can rely on is that when you tell your browser to connect to a website the software that you have willingly installed on your computer, phone, etc.  intercepts that request, redirects it to the VPN server and then retransmits it to the website you actually want to visit. From that point, all communications with that site go via the intervening server. The target website thinks that the VPN server is you (which is why you can use a VPN to watch geo-blocked TV) and your computer (and your ISP thinks (ish) that you are visiting the VPN server. Your ISP (and incidentally your local government) do not, at least in theory, know where your traffic goes to or originates on the other side of the VPN. 

So that's all cosy and nice. 

But what if the VPN was run by criminals who do, in fact, store not only your IP address and the URL of the site you want to visit but also intercept all the traffic. 

But it's all encrypted, you will cry.

Yeah, right. 

When you install any software that includes encryption, that encryption is defined by the software company. WhatsApp says it's end to end encryption but then it says "we intend to introduce personalised advertising." Apple says it encrypts almost everything in iOS but cases where the phone delivered advertising related to the contents of telephone conversations are consistently reported.

When a company says the data is encrypted "end to end" what it really means it "except when it crosses our servers."

And that's the weakness in many VPN services. It is widely reported that some of the leading VPN companies were formed by Eastern Europeans with known links to organised crime - and that several of those leading VPNs are owned or controlled by a small, related, group of persons.

This is where the First VPN Service case makes sense,

Run by Russians, sold all over the world, hidden by Cloudflare and plundering all manner of data about its users.

Your browser reveals much about you. Websites know a lot about you, your computer, your operating system the moment you connect. This isn't anything to do with cookies and the privacy policy (badly named) that you see is too late. It's got you and that data has already been passed into a processing system. 

And then the bad buys decrypt your traffic. They know your banking information, they have a photograph of you, they know the kind of websites you visit and if you have any food, drinks, sports or sexual preferences. 

All those "we have accessed your camera and...." You know you can dismiss them except....

All your data can be collected, collated, analysed. And as it is cross-referred so do your email addresses, phone numbers and even videos (those you actually make) can be collated. 

Then they can be doctored with simple manipulation tools. 

On those VPNs controlled by criminals, your image, your mannerisms, your voice are all there. 

A 5 second video of you walking a dog with a pretty girl, or pretty boy, takes klless than five minutes to create. This isn't new: we did static images to demonstrate the tech to create blackmail photos in 1996. But convicing videos, made to order, are relatively new. 

Websites run by criminals are not new: ask Cloudflare - they have made a business out of protecting them for years. 

So we are seeing nothing new but we are seeing a convergence of long-established techniques.

And we are seeing the product of (sorry to say this) shitty education and awareness over decades. 

Criminals will always find ways to exploit people's ignorance. We just make it easy.

What is a "no logs" VPN?

You will realise from the above description that there are three types of information that a VPN server sees. 

  • Activity logs:This is the stuff that flows from you to the ultimate website and back. 
  • Connection logs: This is your IP address, information about your machine and its operating system, the time and date of connection, the website (URL and IP address) you visit and DNS queries (every website has a DNS and it is this that Cloudflare hides) as well as the volume of data transferred. 
  • Aggregated logs: This is all about patterns of use: how many visitors use the service to go to a particular site, or types of site. 

This information is almost certainly being stored by your Internet Service Provider and, honestly, for most people it shouldn't be a concern until it's collecting properly personal information that should be secure e.g. bank logins. But getting that information is much easier than hacking an ISP. It's at risk every time you log onto a public wifi, hotel internet network or in a conference. 

There are too many VPNs to list and most of them claim "no logs" and there is no way we can check which companies are telling the truth. 

We do know that some companies have verifiable audits.

Firetrust is a sister to the excellent antispam system by Firetrust They designed the software with no logging capability so it's not a question of whether the logs are there and hidden. Also Surfshark which is certified and has a large global following.

But security happens - or breaks - everywhere.  Some years ago we signed up for ProtonVPN which is very highly regarded. Almost immediately we had suspicious activity on the card we had used to pay. Coincidence? Dunno. We'd had none before. 

About this section

From FinTech to RegTech, from "AI" to security, from the terraverse to the metaverse, if there's a technology element, we're interested. But this is not an area for PR. It's an area for considered, structured articles that advance arguments. Think Op-Ed with a purpose.

Opinion pieces or "Op-Eds" are the home-made bombs of the publishing world. So long as they meet editorial standards, are not intentionally offensive with a view to causing hurt or insult and are relevant to our field of endeavour, we will look at submissions.

We like contentious, we like contrarian views. We don't like pretty much any -ism . We recognise that Opinion pieces are one person's view and are not balanced (if they are balanced and reach a reasoned conclusion, they are probably more suited to the Articles section). We do not like empty expressions (reaching out, going forward, circling back etc), acronyms and buzzwords. English, only please.

To submit an Opinion / Technology piece, please complete the Contact form.

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.