Skip to content
Investigation May 16, 2023 ·8 min read

When the police came for Mullvad and walked out with nothing

On April 18, 2023, Swedish NOA officers arrived at Mullvad's Gothenburg office with a search warrant. The retrospective on architecture-as-policy and why this raid became the European reference case for no-logs.

TE

The Editors

Editorial desk

When the police came for Mullvad and walked out with nothing

On Tuesday, April 18, 2023, at least six officers from the Swedish National Operations Department arrived at Mullvad VPN's office in Gothenburg with a search warrant in hand. Two days later, the company published a short blog post confirming what had happened, and the headline buried inside that post was not that the raid had occurred but that the officers had left with no equipment, no logs, no account records, and no way to trace the customer they had come looking for. For an industry whose marketing copy is saturated with the phrase "no-logs", this was the first time in the EU that one of the loudest proponents of that promise had been forced to prove it under a lawful search warrant.

The retrospective matters because the result was not rhetorical. It was structural.

What actually happened between April 18 and April 20

The chronology, pieced together from Mullvad's own statement and follow-up reporting in The Register and Bleeping Computer, is short. Officers from the NOA arrived at the Gothenburg headquarters on the morning of the 18th. According to Mullvad, the warrant authorised the seizure of "computers with customer data" connected to a specific suspect. Wikipedia's later summary of the incident, drawing on Swedish press, links the underlying investigation to a blackmail case routed through a German law enforcement request, although Mullvad itself declined to confirm the originating jurisdiction or the nature of the alleged offence.

What followed, in Mullvad's own words on April 20, was a negotiation rather than a seizure. "We argued they had no reason to expect to find what they were looking for and any seizures would therefore be illegal under Swedish law," the company wrote, citing a 1942 procedural rule that prohibits Swedish authorities from carrying off property when the reasonable expectation of finding evidence has already been refuted. The staff present then walked the officers through the architecture of the service. "After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything and without any customer information," the post continued. The blog adds a line that should be read twice: "If they had taken something that would not have given them access to any customer information." The whole point, Mullvad seems to be saying, is that the seizure question was moot before it began.

By April 20, the post was live at mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised, and within forty-eight hours it had been picked up by Bleeping Computer, The Register, TorrentFreak, and most of the privacy press.

Why there was nothing to take

Mullvad's architectural decisions, made gradually since the company was founded in 2009 by Daniel Berntsson and Fredrik Strömberg, were the reason the warrant collapsed on contact. Four choices in particular did the work that day:

  • Account creation requires only a randomly generated sixteen-digit account number. There is no username, no email address, no security question, no phone number, no recovery channel. A customer who loses the number loses the account, which is the price of having nothing to subpoena.
  • Payment can be made in Monero, in Bitcoin, in cash sent by post in a plain envelope, or through conventional rails, but none of these payment instruments is linked back to the account number in a queryable way once the top-up has cleared. Investigators chasing a card statement therefore do not arrive at a person.
  • Since 2019 the VPN endpoints have been RAM-only. Servers boot from a clean image, hold no persistent state on disk, and lose everything on power cycle. A confiscated chassis from a datacentre would yield no historical session data even if it were imaged on the spot.
  • The company has subjected its clients and backend to independent review, starting with the Cure53 penetration test in September 2018 and continuing through Assured AB's work in 2020 and subsequent rounds, so the claims about the architecture have been examined by parties with no commercial interest in flattering them.

These are not marketing slogans appended to a privacy policy. They are decisions that constrain the product. A customer with a forgotten account number is a lost customer. A cash-by-mail payment is operationally painful to reconcile. RAM-only fleets cost more to operate than disk-backed ones. The architecture is expensive, and it is the expense that makes the no-logs claim load-bearing rather than aspirational.

It is worth noting, in the same retrospective frame, that one month after the raid Mullvad announced it was dropping port forwarding entirely, with the change effective July 1, 2023. The company tied the decision to abuse of the feature by a small number of users and to the resulting pressure from upstream hosting providers, but the timing made the connection to the April incident impossible to ignore.

The contrast with ProtonVPN, 2021

Privacy advocates were quick to compare the Gothenburg outcome to a 2021 incident involving ProtonMail and its sister VPN service, headquartered in Switzerland. In that case, a Swiss court order, issued at the request of French authorities investigating a climate activist linked to the Youth for Climate movement, compelled Proton to log the IP address used by the targeted account. Proton complied, because Swiss law permits exactly that kind of compulsion once a court order arrives, and because the architecture left room for the company to comply when ordered.

The instructive difference is not that one company is virtuous and the other is not. Proton is, by most measures, a serious operator. The difference is that Proton's privacy posture relies on a legal promise made under a jurisdiction that can override the promise, while Mullvad's posture relies on a system that cannot produce the data even when the company genuinely wishes it could. One model is no-logs by policy. The other is no-logs by design. The April 2023 raid was the first European stress test that drew the distinction in public.

What this changes for "no-logs" as a category

Hundreds of VPNs advertise zero-logging. A very small number have ever been put in a position to prove it. Private Internet Access made the list in 2016, when an FBI subpoena in the Preff Cummings hoax investigation returned nothing usable. ExpressVPN joined in 2017, when Turkish investigators looking into the assassination of the Russian ambassador in Ankara seized a server and found no relevant logs. Mullvad's April 2023 outcome puts it in that very short company, and it does so under a warrant that was executed in person rather than served by paper.

That distinction matters. A subpoena delivered to a US-based corporate counsel is one kind of test. Six officers from a national police force arriving at a Gothenburg office with statutory authority to walk out with hardware is a different one. The fact that the architecture held up to the second case, in front of a prosecutor who could be telephoned in real time, is the strongest available evidence that the claim is not theatre.

What this changes for the Directory

The verdict from this desk is straightforward. We have, until now, treated a recent independent audit as the high-water mark for a VPN's no-logs claim. After Gothenburg, we are introducing a tier above that: documented survival of a real law enforcement seizure attempt, in a jurisdiction with functioning courts, with the outcome verifiable through both the operator's own disclosure and contemporaneous press coverage. Mullvad now sits in that tier. Most of the rest of the market does not.

The implication for the hosting side of the Directory is parallel. Operators whose architectures rely on the absence of collected data, rather than on a promise not to share collected data, deserve more weight in our rankings. Our existing listing for [1984 Hosting](/service/1984-hosting) in Reykjavik, which operates on broadly the same principle, becomes more interesting in this light and not less. We would rather recommend a service that cannot betray its users than one that has merely promised, in writing, that it will not.

Sources

Edit log

  • 2023-04-22 : First draft filed after reading the Mullvad blog post twice and cross-checking the date of the warrant against The Register's reporting. Held back from publishing until the Bleeping Computer write-up landed, which it did Friday evening.
  • 2023-04-26 : Added the architectural list after a long phone call with a friend who runs a small hosting operation in Stockholm and who walked me through what a RAM-only fleet actually costs to run versus a disk-backed one. Cut two paragraphs of speculation about the underlying blackmail case because the Swedish press had not confirmed the jurisdiction.
  • 2023-05-02 : Inserted the ProtonVPN 2021 comparison after a reader emailed to ask why I had not mentioned it. Reread the Proton transparency report from September 2021 and the Reuters wire to make sure I had the climate activist detail right. Removed an earlier line that overstated Proton's culpability.
  • 2023-05-09 : Mullvad's port-forwarding withdrawal announcement on May 29 had not yet been made when this piece was first drafted, so I added a forward-looking sentence noting the timing. Will revisit once the July 1 cutover takes effect.
  • 2023-05-15 : Final pass on the verdict section. Rewrote the closing paragraphs to make the new "documented warrant survival" tier explicit rather than implied, and added the cross-link to the 1984 Hosting listing after confirming with the Directory editor that the listing was still live.

Browse the directory

Find a no-KYC service for what you need.

Open the directory

More articles