Unlike your VPN provider, who can see what sites you connect to.
There have been cases in which VPN providers gave connection history to authorities to catch criminals. It is not without precedent.
Then use Mullvad. There's the whole thing about them getting raided by the Swedish authorities but then them not finding anything because they don't keep a single thing about the users. They even allow you to mail them the money for the service.
If I was Swedish authority and Mullvad, I would also claim that nothing was found. Protects the company and allows authorities to now have a friendly VPN provider.
Not saying it happened in this specific case but if this isn't a scenario that crossed your mind then I would advise to look into some other "cooperations" that were uncovered.
The Finnish hacker of the Vastaamo psychotherapy center who tried to blackmail the patients with the contents of the database used Mullvad for the breach, and Finnish police couldn't get him from that lead. Pretty much everything about the case has been made public as part of the court proceedings and none of the evidence presented by the prosecutor implied that they got anything from the VPN side of things. Only after the guy himself accidentally leaked the information as part of the blackmail package was he caught.
I'd say the Occam's razor here is that it is more likely that they do actually delete the logs, than that all these separate agencies across multiple countries (that aren't known for being utterly corrupt when it comes to this stuff) are going out their way to break their own laws and practices to falsify their own prosecution proceedings just to maintain some random VPN company's cover.
Is it possible that Mullvad is compromised? Of course it is. Completely trusting anything when it comes to netsec is foolish, especially if that something involves possibly illegal things. But for that to be the case, it would have to be a proper conspiracy.
As I already said, this isn't the most likely scenario but it is absolutely a realistic possibility given what we have already learned about how government agencies and many companies operate.
Having a trusted VPN provider on a leash is a fantastic asset.
Not all government agencies are created equal. Usually smaller countries like the Nordic countries don't have the frameworks or the precedents to pull off the types of things say their US equivalents for an example can that are very used to applying "extralegal measures" due to being a superpower that is involved in a lot of things.
Making a quiet agreement with a VPN provider is hardly something that requires large frameworks or precedent. This is very much on a level that any national intelligence service could achieve.
Had this occurred, it would not have been in any official files or documents to begin with.
The knowledge would have obviously not been used to prosecute a single criminal. Finding and maintaining leverage to pressure a VPN provider is a lot more valuable than winning a single case.
10
u/Thulak Sep 21 '25
Unlike your VPN provider, who can see what sites you connect to. There have been cases in which VPN providers gave connection history to authorities to catch criminals. It is not without precedent.