DLBI: Free VPN Data Leaks Increasingly Used to Attack Corporate Networks
A study by cybersecurity firm DLBI reveals that data leaks from free VPN services are increasingly leveraged by cybercriminals to carry out credential-reuse attacks on corporate infrastructure.

DLBI: Corporate Networks Increasingly Targeted by Attacks Exploiting Free VPN Data Leaks
Tashkent, Uzbekistan (UzDaily.uz) – Cybercriminals are increasingly leveraging data leaks from free VPN services to launch attacks on corporate networks, a new study by DLBI, a threat intelligence and dark web monitoring service, reveals.
DLBI experts examined over 200 datasets, encompassing publicly released data dumps and database samples advertised for sale as user data from VPN services. Furthermore, specialists deployed honeypots—simulated corporate VPN services—to log unauthorized access attempts.
The study found that over 35% of login attempts on these honeypots used username and password combinations already identified in the analyzed free VPN service leaks. An additional 20% of attempts involved modified versions of these passwords, automatically generated by specialized scripts.
DLBI highlighted that the significant number of attacks employing credential reuse accounts for the rising demand for VPN service databases on the dark web. Experts suggest this trend also contributes to the proliferation of short-lived VPN services, which quickly cease operations after attracting users, without directly seeking financial profit from them.
Ashot Oganesyan, founder and technical director of DLBI, commented that password reuse is emerging as a prevalent method for compromising corporate services, with VPN infrastructure facing particularly intense pressure from malicious actors.
He elaborated that while attackers previously struggled to link stolen credentials to specific companies, they now utilize information leaked from government entities in conjunction with corporate email addresses that users themselves provide when registering for various online services.
DLBI advises companies to prioritize protection against credential-reuse attacks. Specifically, experts recommend implementing specialized solutions to monitor for exposed user credentials in leaks and to automatically block accounts or enforce password resets for compromised accounts.

