Can Police Trace a VPN? What Court Records Show
This question has an unusually good answer, because it's actually been tested — repeatedly, in public court records, not in theory. Several documented cases exist where law enforcement agencies formally demanded user data from VPN providers, and the outcomes split cleanly: some providers had genuinely nothing to hand over, and some did. Both outcomes are on the public record with named cases, dates, and court filings. Here's what actually happened.
The short, honest answer
Whether police can trace a specific VPN user depends almost entirely on what that specific provider actually logs — not on VPN technology in some general sense. A genuine no-logs architecture means there's nothing to hand over even under a valid legal order, because the data simply doesn't exist. A provider that logs more than it claims can and does comply with legal requests using exactly that data. The documented cases below show both outcomes happening to real, named, well-known providers.
Case: ExpressVPN, Turkey (2017) — server seized, nothing found
Turkish authorities seized an ExpressVPN server as part of an investigation into the 2016 assassination of the Russian ambassador to Turkey, after tracing suspicious account-deletion activity to an ExpressVPN-associated IP address. Investigators contacted ExpressVPN directly requesting logs; the company stated it possessed no customer connection logs capable of identifying which customer used the specific IPs in question, and no activity logs of what those customers accessed. The physical server seizure and inspection reportedly confirmed this — there was nothing on it to find. ExpressVPN has publicly stated this incident led it to stop operating physical servers in Turkey afterward, offering virtual Turkey locations hosted elsewhere instead.
Case: Private Internet Access, two separate FBI cases (2016 and 2018)
PIA's no-logs claim was tested in U.S. federal court twice, four years apart, in unrelated cases. In 2016, the FBI subpoenaed PIA (then operating as London Trust Media) during a bomb-threat investigation; the company's general counsel testified in court that PIA does not retain logs of customer internet activity and was unable to produce anything beyond confirming a general geographic region for the IP cluster involved. In 2018, in an unrelated hacking case heard in San Jose federal court, PIA was subpoenaed again — and again could not provide any data linking the account to specific online activity, for the same structural reason: the logs didn't exist to produce.
Case: IPVanish (2016) — the counter-example
This case is worth including precisely because it's the honest counter-example. In 2016, the U.S. Department of Homeland Security issued a summons to Highwinds Network Group (IPVanish's parent company at the time) during a child exploitation investigation. According to the publicly filed court affidavit, IPVanish initially indicated it had no usable data — but after a follow-up request, the company provided detailed information including the suspect's real source IP address and the exact dates and times of VPN connection and disconnection, despite marketing a "zero-log" policy at the time. IPVanish was acquired by a new company (StackPath) in 2017, which stated the incident predated its ownership and that current infrastructure does not retain such logs — but the 2016 case itself is a matter of public record regardless of subsequent ownership changes.
Case: PureVPN (2017) and HideMyAss (2011) — logs provided
PureVPN cooperated with an FBI cyberstalking investigation in 2017, providing connection timestamps that, combined with other evidence, helped identify the suspect — despite marketing itself around limited logging at the time. HideMyAss provided information in 2011 that assisted in identifying a LulzSec hacker involved in an attack on Sony Pictures, despite the service's privacy-focused marketing.
What actually determined the outcome in each case
Reading across all five documented cases, the differentiator wasn't the provider's marketing claims — every single one of them marketed strong privacy or no-logs policies at the time. The actual differentiator was the underlying technical architecture: whether the infrastructure was built to genuinely avoid retaining identifying data, versus infrastructure that retained more than the marketing suggested. A no-logs claim is a promise; a court-tested outcome is evidence of whether that promise reflected real architecture.
What this means for evaluating a provider
The jurisdiction factor
Where a VPN provider is legally based affects what it can be compelled to produce in the first place. Providers based in jurisdictions with no mandatory data retention laws — and outside intelligence-sharing arrangements like the Five/Nine/Fourteen Eyes alliances — face fewer legal obligations to collect or retain user data in the first place, which is part of why company jurisdiction is a legitimate factor in provider evaluation, not just marketing trivia.
The bottom line
Can police trace a VPN user? The honest, documented answer is: sometimes, and it depends entirely on the specific provider's actual data retention — not on VPN technology as a category. The public court record includes both outcomes, with named providers and dates, which makes this one of the rare privacy questions with real evidence behind the answer rather than just claims. Providers with a documented court-tested no-logs record are worth weighting accordingly: NordVPN and Surfshark both publish transparency reporting addressing this directly.
Related on VPN Review
What happens when a VPN gets subpoenaedVPN warrant canaries: signal or theater?Ready to switch or upgrade?
Check current promotional pricing on our sister site before you commit to a plan.
Frequently Asked Questions
Can police actually trace someone using a VPN?
It depends entirely on what that specific VPN provider logs. Documented court cases show both outcomes: providers with genuine no-logs architecture (ExpressVPN in 2017, PIA in 2016 and 2018) had nothing to hand over even under formal legal demands, while others (IPVanish in 2016, PureVPN in 2017, HideMyAss in 2011) provided data that helped identify users.
What happened when Turkish authorities seized an ExpressVPN server?
In 2017, Turkish authorities seized an ExpressVPN server during an investigation into the assassination of the Russian ambassador to Turkey. ExpressVPN stated it had no customer connection or activity logs capable of identifying the user in question, and the physical inspection of the seized server reportedly found nothing to contradict that.
Has any VPN provider been proven to keep logs despite claiming a 'zero-log' policy?
Yes. In a 2016 case documented in public court filings, IPVanish (then owned by Highwinds Network Group) provided a suspect's real IP address and VPN connection timestamps to Department of Homeland Security investigators, despite marketing a strict zero-logs policy at the time.
Why does a VPN provider's jurisdiction matter for whether police can trace users?
A provider's legal jurisdiction determines what it can be compelled to produce. Providers based in countries with no mandatory data retention laws and outside major intelligence-sharing alliances face fewer legal obligations to collect data in the first place, which affects what's even available to hand over if a legal demand arrives.