Cybersecurity researchers have discovered unencrypted data from about a million users of Quickfox, a free virtual private network (VPN) service primarily used to access Chinese websites outside mainland China.
See also: Zerodium: Asks for zero-day exploits for Windows VPN computers

See also: NSA, CISA: Guidelines for strengthening the security of VPN solutions
Commenting on the finding, WizCase says the data revealed a variety of personally identifiable information (PII) of the service's users, including names, phone numbers and more.
"No password or login credentials were required to view this information, and the data was not encrypted. Based on the exposed files, our team estimates that the breach affected at least one million Quickfox users," WizCase writes.
Security researchers claim they tried to bring the leak to Quickfox's attention, but the free VPN provider has yet to respond to their greetings.
The data was discovered through misconfiguration in Quickfox's ElasticSearch server thanks to incomplete ELK stack security.
The researchers explain that ELK (Elasticsearch, Logstash, and Kibana) are three open source applications that help streamline searches through large files, such as the logs of a web service like Quickfox.
The total data leaked consisted of over 500 million records, totaling 100 GB. Approximately one million of these records contained user PII, including MD5 passwords.
See also: Why use a VPN for Netflix
However, what is worrying is that the leaked data not only contained the IP address assigned to the user, but also the user's original IP address from which they connected to the VPN service. WizCase was also surprised that the service collects data about other software installed on the user's device.
Information source: techradar.com
