The VPN That Beat the Cops By Doing Nothing

 

So I've been going down a bit of a VPN rabbit hole lately (as one does), and I kept landing on the same name: Mullvad. I was well familiar with it during my time in Cyber Threat Intelligence, but I began to wonder, why was it everywhere? During my research, I also learned about an interesting event that took place linked to Mullvad...a raid.

The Raid That Went Nowhere

 

Back in April 2023, at least six officers from Sweden's National Operations Department showed up at Mullvad's Gothenburg office with a search warrant. The operation was tied to a German blackmail investigation (some IP addresses had been traced back to Mullvad's servers) and Germany asked Sweden to lean on them for it.

They wanted computers. Specifically, computers "with customer data."

There was just one problem: that data didn't exist. Mullvad doesn't log IPs, browsing activity, or connection timestamps, full stop. So after some back and forth with lawyers and the prosecutor, the police left the building with nothing. Pretty wild that a company can just... shrug at a police raid and be completely fine, but here we are.

Fourteen Years and Not a Scratch

Mullvad VPN - Privacy is for the people 

The thing that gets me is how Mullvad handled the aftermath. They didn't present us with the usual "we're reviewing our policies" corporate-speak or panic announcement/email. Just a blog post pointing out they'd been running the service for over 14 years, implying: this is how it's always worked, nothing to see here. Confidence like that is hard to fake.

The Downside of Being This Private

Here's where it gets a bit more complicated though. Being this aggressive about not logging anything means Mullvad genuinely cannot tell who's using their network for what. No visibility means no way to flag bad actors either. This feeds back to the point I made earlier, where I was seeing this VPN service deeply woven into cybercrime toolkits.

Mullvad's own CEO admitted this too. The company became something of a "safe haven for bad stuff" simply as a side effect of doing privacy properly

IPs got blacklisted, hosting providers pulled out, law enforcement kept knocking. Eventually they killed off port forwarding entirely, specifically because criminals were abusing it and Mullvad had no way to police it without breaking their entire privacy model.

So the same design that makes Mullvad basically bulletproof against government pressure is the exact thing that occasionally makes it attractive to the wrong crowd.

It would appear that privacy is a package deal, you don't get to keep the good parts and filter out the bad ones.

Worth It?

I keep coming back to the same conclusion: a VPN that can't hand over your data because it genuinely doesn't have it is a fundamentally different promise than a VPN that pinky-promises not to look. I am not going to name any because it is likely you already know of several of them.

One is a policy. The other is architecture. Mullvad picked architecture, and a failed police raid is about as strong a proof-of-concept as one will get. How interesting!

mullvad.net