How did they got Purevpn's customer base emails? They got hacked, i guess. And they(PureVPN) are really hiding something from the customers!
Dear User,
We are writing this email to give you 'Second Major Update' on PureVPN Fake Email Issue.
Our VPN service is functioning 100% fine and there is no interruption whatsoever. While we are investigating the cause of the email, we reemphasize that, as we do not store any of our users credit card nor PayPal information in our on-site databases, there has been no compromise in our users billing information. Similarly, service troubleshoot logs (connection attempts, users IPs, etc) are safe and intact as we do not store such logs on site. Furthermore, as we vouch for privacy, security and anonymity on the internet, hence we do not store actual VPN service usage logs.
Preliminary reports suggest that we are hit with a zero day exploit, found in WHMcs; 3rd party CRM that we use on our website
We are able to confirm that the breach is limited to a subset of registered users Email IDs and names.