Internet Freedom Weekly: News Recap, July 27th–31st, 2026
A busy week. A VPN that kept 58 million connection logs got breached. A research teardown found two EU-listed apps secretly signed from Minsk and routing data through Russian infrastructure. A court blocked Texas from forcing websites to filter "harmful" speech. India started reviewing net neutrality. And a telehealth company got sued for sending your health data to Meta. We covered all of it.
A "no-logs" VPN kept 58 million logs — and got breached
The Mysterium VPN Research Team verified a breach of NotVPN (also known as SplitVPN), a Russian VPN marketed with explicit no-logs promises. The leaked database contains approximately 23.4 million user records, 13.6 million device records, and — most damningly — nearly 58 million connection logs recording which device connected to which server and when. The logs run continuously up to the day of the breach. NotVPN's own marketing promised: "We never store your activity or connection logs. 100% privacy guaranteed." The database says otherwise. If you used NotVPN or SplitVPN, treat your email and associated IPs as compromised.
Nicegram and eSIM Plus — here's what’s hiding inside
Following OCCRP reporting that Nicegram (50M+ downloads) and eSIM Plus (1M+ downloads) are presented as Lithuanian products while allegedly developed from Belarus, the Mysterium VPN Research Team performed a static teardown of both Android packages. The findings: eSIM Plus is cryptographically signed by "Mobyrix, Minsk, Belarus" — a Belarusian signature on an app marketed as Lithuanian. It also ships live integrations with Yandex AppMetrica and Voximplant, routing through a .ru endpoint. Nicegram shares the same development operation but doesn't carry those Russian SDKs in the version we analyzed. The lesson: an app's listed publisher and its actual origin can be two different things — and the binary is where the truth is.
The 5th Circuit blocked Texas's "harmful speech" filtering law
The US 5th Circuit Court of Appeals blocked a Texas law that would have required websites to filter content deemed "harmful." The ruling strikes down a state-level mandate for government-directed content moderation — and the core problem with such laws is always the same: "harmful" is defined by whoever holds political power at the time. Laws built around vague harm standards don't stay narrow. They expand to cover whatever the current majority finds inconvenient, and they push platforms toward systematic over-moderation of the most important speech.
China is censoring the anniversary of the Zhengzhou floods
Five years after catastrophic flooding killed hundreds in Zhengzhou — including passengers trapped in a flooded subway tunnel — Chinese authorities are censoring online memorials, personal accounts, and any content that contradicts the state's narrative of effective disaster response. The censorship targets grief itself. One suppressed piece read: "Sometimes forgetting is as terrible as the disaster." A government that can erase disaster memory can also erase the accountability questions that disaster raised. That's what information control is ultimately for.
The UK's immigration AI is misclassifying child refugees as adults
A Guardian investigation found that AI age-assessment tools used by UK immigration authorities exhibit significant bias, causing child refugees to be incorrectly classified as adults. Children misclassified lose access to the legal protections, support, and procedural rights that exist specifically because they're children. Error rates are higher for people with darker skin — meaning child refugees from the Global South are the most likely to be misidentified. The government is deploying biased surveillance tools on the most vulnerable people it encounters, and the people bearing the cost of the errors have no power to contest them.
Russia fired workers who refused to censor LGBTQ+ books
Russia's largest publishing group terminated employees who refused to comply with censorship orders targeting LGBTQ+ content. They weren't activists. They were editors and staff who drew a line at participating in their community's erasure. The line cost them their jobs. This is how institutional censorship scales: not through police raids, but through quiet employment consequences that distribute compliance across enough ordinary workplace decisions that it stops looking like state censorship. The playbook travels. It isn't unique to Russia.
Google's Play Store age verification API is rolling out globally
Google is expanding its Play Age Signals API, which lets app developers access age range data for child accounts without requiring ID uploads. The system is built on Family Link, is fully opt-in, and doesn't demand government identification from anyone. That makes it meaningfully more privacy-respecting than most age verification legislation we've covered. It also won't stop determined minors who create alternative accounts — which is the honest gap between "creates friction" and "reliably verifies age" that legislators consistently paper over.
xAI is suing Minnesota over its AI nudification ban
Elon Musk's xAI filed a federal lawsuit challenging Minnesota's HF 1606, which bans apps enabling the creation of non-consensual AI-generated sexualized images. xAI doesn't contest the goal — it contests the scope, arguing the law covers consensual imagery and artistic content, and imposes strict liability regardless of what mitigations a provider has in place. The harm being addressed is real. The First Amendment argument has some substance. The question is whether the law is precisely enough targeted to survive challenge — and whether this lawsuit might produce a narrower, more durable version of the same protection rather than gutting it entirely.
The FTC sued Hims & Hers for sending health data to Meta and Snap
The FTC, joined by Utah and California, sued telehealth provider Hims & Hers for sharing consumers' sensitive health data with Meta, Snap, and other advertising platforms — while publicly promising patient privacy. The data was shared via customer lists and third-party tracking technologies embedded on the Hims website. The company also allegedly enrolled users in recurring subscriptions before any medical consultation occurred, and designed its cancellation flow to be deliberately difficult to navigate. "We protect your privacy" is not a guarantee without enforcement. This case is the enforcement.
India is reviewing its net neutrality rules for 5G
India's government has referred a review of its net neutrality rules to the Telecom Regulatory Authority of India, prompted by questions about whether 5G network slicing is compatible with the current equal-treatment framework. The use cases being cited — healthcare, autonomous vehicles, industrial applications — have genuine technical merit. The concern is that once exceptions are carved into a net neutrality framework for technical reasons, the boundary between "technical necessity" and "commercial opportunity" is very difficult to maintain. India's 2018 framework was one of the world's strongest. The TRAI process will determine whether it stays that way.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
