A problem, discovered by a security researcher known in cyberspace as GeopJr, affects 35,509 accounts on Unjected, exposing sensitive informationranging from full names and dates of birth to email addresses and location details.

The site's authentication weaknesses allowed GeopJr to not only modify user profiles, such as changing their photos, but also access their direct messages with other users and site staff.
Unjected, which bills itself as the “largest platform for the unvaccinated” online, first appeared in May 2021. It immediately gained media attention, but was removed from the Apple Store for violating COVID-19 misinformation guidelines.
Read also: Do you use Google Chrome? Beware! Malware steals personal data!
Despite the adversities, the website did not stop evolving, enriching its services with new features. One of these was the innovative “mRNA FREE blood match & fertility directories”, where users had the opportunity to offer so-called clean blood, sperm or eggs, to other members of the community.
In July 2022, Daily Dot revealed, through its in-depth investigation of GeopJr, that the Unjected platform’s admin panel was widely accessible to the public. This security vulnerability allowed GeopJr, among other things, to add, modify, or even disable website pages and user accounts
Shelby Thomson, co-founder of Unjected, decided not to respond to emails sent to her by the Daily Dot at the time, despite intense efforts to fix the site, which led to its repeated ban from the internet. After a series of complaints from users about protection , technical glitches and outages , the site was finally restored. Although the main problems were fixed, several bugs remained unresolved.
GeopJr spoke to the Daily Dot this month, noting that they decided to conduct a new inspection of the site, nearly two years after the initial technical issues were identified, and concluded that Unjected remained “just as unsafe as before.”.
“Once again, Unjected fails to implement necessary security measures, putting thousands of users at risk,” said GeopJr.
Unjected recently received an email from the Daily Dot, which pointed out serious vulnerabilities in the platform last week, but failed to adequately address them. While some efforts were made to resolve the data leak, as reported by GeopJr, these actions caused more problems for the site, including the potential for user accounts to be unjustifiably deactivated without the necessary identity verification.
Due to Unjected’s failure to protect its users’ personal data, the Daily Dot decided not to describe in detail how the vulnerabilities were discovered. However, these issues allowed GeopJr to gain access to profile information that should have been unpublishable. In addition, GeopJr discovered a separate authentication issue that allowed him to access all of the platform’s direct messages.
See more: iPhone notifications leak users' personal data
The Daily Dot's analysis of 8,323 private conversations on the site, spanning from July 2023 to March 2024, reveals that even the most loyal users are starting to wonder about Unjected's security.
In a direct communication with the Unjected administration on January 10, a user expressed himself saying: “Thank you for contributing to the creation of this platform. I hope you have strict measures in place to protect the privacy of people who have not registered.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In another announcement made on December 13, 2023, a user also expressed concern that the website's data could end up in the hands of the US government and be shared with its own authorities
“I am quite concerned about this platform that collects data from prisoners. There is a possibility that the US government could hack it and obtain evidence against those who refuse to comply with the Biden administration’s policies,” the user wrote. “I am really concerned… I am not sure if I will continue to use this platform… I need to research more about how cybersecurity and offer my support to their customers.”
On February 9 of this year, a complaint was recorded from another user about the website, describing it as “dark” and “difficult to navigate,” expressing concern about possible hacking and that he often avoids logging in due to this fear.
“The messaging component is underdeveloped, as it seems to crash every time I try to use it, giving me the impression of a poorly designed website. “That was my observation,” they wrote. “I’m waiting for a hacking attackto see if I’ll end up on the blacklist!”
Other private data includes users' precise geographic coordinates, based either on the city and state they have entered on the website, or on their choice to allow their browser to determine a more precise location.
In a statement to the Daily Dot, Unjected appears to baselessly accuse the journalist in question of somehow managing to breach the website's security.
"At Unjected, we are convinced that we are under government surveillance. Thank you for helping us make Unjected the safest haven for the unvaccinated. We invite you to use your hacking skills for good and contribute to the resistance against the New Order, instead of targeting organizations that fight for humanity. At some point, this will all make sense to you."
Unjected said it created a promotional code bearing the journalist's name, before urging its audience to "Stay Natural, Free and Independent.".

“When you’re ready to ditch Tinder or Bumble and find a great, healthy relationship, take advantage of the special offer with the code MIKAELISLONELY at Unjected.com. Enjoy 25% off your first month’s subscription, an offer valid for all Daily Dot readers,” he added.
See also: Rio Tinto: Staff personal data may have been leaked
Despite the security concerns, Unjected has not issued any statement on its website or social media profiles indicating that its users' personal data is exposed to potential breaches .
Source: dailydot
