CyberGhost VPN’s Quarterly Transparency Report: April, May, and June 2026

Transparency reports aren’t meant to be dramatic. Their value comes from publishing the same information, quarter after quarter, so anyone can see what requests we receive and how we handle them.

In the second quarter of 2026, CyberGhost VPN received 64,006 DMCA complaints and five police requests. Our bug bounty program also received 49 submissions, including two valid issues.

Here’s a closer look at the figures from April, May, and June.

Legal Requests: Our Q2 Numbers

The requests we report fall into two main categories:

    • DMCA complaints: Notices alleging that a CyberGhost VPN IP address was used to download or share copyright-protected material.
    • Police requests: Requests from law enforcement agencies seeking information related to an investigation.
AprilMayJuneQ2 total
DMCA complaints21,19722,29320,51664,006
Police requests3115

CyberGhost VPN doesn’t keep activity logs or connection logs such as browsing history, DNS queries, originating IP addresses, VPN server IP addresses, or session timestamps. Our VPN servers also use RAM-only infrastructure, which wipes data when a server reboots rather than writing browsing activity to a hard drive.

This means we don’t hold the browsing or connection records typically sought through these requests. We review and respond to each request in line with applicable law and our policies.

DMCA Complaints

64,006
AprilMayJune
21,19722,29320,516

CyberGhost VPN received 64,006 DMCA complaints during Q2 2026. Monthly volumes were relatively consistent, ranging from 20,516 complaints in June to 22,293 in May.

This was an increase of approximately 19.6% from the 53,533 complaints recorded in Q1 2026.

These numbers represent notices received. They shouldn’t be read as a count of confirmed copyright infringements, individual users, or separate incidents. Multiple notices may refer to the same IP address or alleged activity.

Because CyberGhost VPN doesn’t store records connecting browsing activity to an individual VPN user, we don’t have the activity or connection data requested in these complaints.

Police Requests

5
AprilMayJune
311

We received five police requests during Q2: three in April, one in May, and one in June. This compares with four requests during the first quarter of the year.

Police requests can relate to a wide range of investigations. The number of requests received doesn’t indicate that an allegation has been verified or that a CyberGhost VPN user was involved.

We assess each request individually. However, our no-logs policy means we don’t retain browsing histories, DNS queries, connection timestamps, or IP address records that could be used to reconstruct a person’s activity while connected to the VPN.

Q2 Bug Bounty Results

Independent security research gives us another way to examine our systems and identify potential issues.

Through our Bug Bounty program on YesWeHack, security researchers can report suspected vulnerabilities affecting CyberGhost VPN’s eligible products and infrastructure. Each submission is reviewed to determine whether it is unique, within the program’s scope, reproducible, and presents a valid security risk.

Here are the figures for Q2 2026:

Three of the 49 submissions duplicated issues that had already been reported, leaving 46 unique submissions.

Two unique submissions were classified as valid. These were passed to the relevant teams for assessment and remediation where required. The remaining 44 unique submissions did not meet the program’s criteria for a valid issue. This category can include reports that are informational, out of scope, not reproducible, or do not present a security impact.

A report being categorized as invalid doesn’t mean it was ignored. Each submission still goes through the triage process, helping the team distinguish genuine vulnerabilities from expected product behavior, duplicates, and issues that fall outside the program’s scope.

Transparency Through Consistent Reporting

The volume of requests and security submissions will change from one quarter to another. Our approach is to keep publishing the figures, explain how they are categorized, and provide enough context for readers to understand what they mean.

We’ll return with our next Transparency Report covering July, August, and September 2026.

Leave a comment

Write a comment

Your email address will not be published. Required fields are marked*