What Happens When a VPN Gets Subpoenaed: Real Cases
A subpoena isn't a request a company can simply ignore, but it's also not a guarantee of getting anything useful — and the gap between those two facts is exactly where a VPN provider's actual architecture matters most. Walking through documented, publicly filed cases shows precisely what a subpoena legally compels, what it doesn't, and why the outcome varies so dramatically between providers even when the legal process itself is identical.
What a subpoena actually is, legally
A subpoena is a formal legal demand for information, typically issued as part of a criminal investigation. Unlike a request, it generally carries legal weight — a company receiving a valid subpoena from a court with jurisdiction over it is legally obligated to respond, though the specific response required depends on what data actually exists to produce and the provider's own jurisdiction's laws governing compliance.
Case walkthrough: Private Internet Access, 2016 (bomb threat investigation)
The FBI traced a series of bomb threats to IP addresses associated with Private Internet Access (then operating as London Trust Media) and issued a subpoena demanding user information. According to the criminal complaint filed in the case, the company's response was that the only information it could provide was that the IP address cluster in question originated from the east coast of the United States — a general regional inference, not user-identifying data. The company also disclosed its accepted payment methods (card processors, PayPal, and several cryptocurrencies) but could not connect any specific payment to the suspect. The FBI ultimately identified the suspect through other, non-VPN evidence — surveillance footage and a separate payment trail unrelated to the VPN subscription itself.
Case walkthrough: Private Internet Access, 2018 (hacking investigation)
Two years later, in an unrelated case heard in San Jose federal court, PIA was subpoenaed again for logs related to a hacking investigation. The company's general counsel testified directly in court that PIA does not retain the kind of activity logs being requested, and once again could not produce data linking the account to specific online activity — not because of a legal refusal, but because the underlying data simply didn't exist to comply with. This was the second time the same claim was tested in court, independently, with the same outcome.
Case walkthrough: IPVanish, 2016 (the case where compliance actually worked)
This case illustrates the other side of the same legal process. The Department of Homeland Security issued a formal summons for records to Highwinds Network Group (IPVanish's parent company) during a child exploitation investigation, requesting data associated with a specific IP address and timeframe. Unlike the PIA cases, IPVanish's infrastructure at the time did retain relevant connection data — and after an initial response and a follow-up request, the company provided the suspect's real IP address and the specific dates and times of VPN connection and disconnection, information that directly enabled investigators to identify the individual through a subsequent subpoena to the suspect's residential internet provider.
What separates these outcomes
All three cases followed essentially the same legal process — a formal government request, made through the appropriate legal channel, directed at a VPN provider. What varied wasn't the legal mechanism; it was whether each provider's actual infrastructure retained the specific data being requested. This is the single most important takeaway: a subpoena can only compel a company to produce data that exists. It cannot compel a company to produce data it never collected, regardless of how the request is worded or how much legal pressure accompanies it.
Transparency reports: the ongoing version of this same information
Beyond individual dramatic cases, several major providers now publish regular transparency reports specifically disclosing how many legal requests they've received and what they were able to (or unable to) provide in response. Private Internet Access's public transparency reporting, for instance, states plainly that as a no-logging provider it is structurally unable to provide logs for law enforcement requests, and discloses the volume of such requests received each quarter regardless of outcome. This is the same underlying information as the dramatic court cases, made routine and ongoing rather than requiring an individual criminal case to surface it.
What this means practically for choosing a provider
- A documented history of "nothing to produce" under actual legal pressure is meaningfully stronger evidence than an unaudited marketing claim of "no logs" that has never actually been tested.
- Regular transparency reporting shows a provider is willing to be measured on this specific question on an ongoing basis, not just when a dramatic case forces disclosure.
- Jurisdiction still matters — even a genuinely no-logs provider based somewhere with strong mandatory data retention laws could face pressure to change its practices going forward, which is a different question from what happened historically.
The bottom line
A subpoena is a real legal instrument that compels a genuine response — but "response" and "useful data" are not the same thing, and the documented cases above show exactly why. Two provider case studies produced "nothing to give" as a legally sufficient answer under direct court testimony; one produced identifying data that helped solve a serious case. The legal process was identical each time; the actual infrastructure wasn't. That's the question worth asking about any provider before relying on a no-logs claim you can't independently verify. Providers with public, ongoing transparency reporting on this exact question: NordVPN and Surfshark.
Ready to switch or upgrade?
Check current promotional pricing on our sister site before you commit to a plan.
Frequently Asked Questions
Does a VPN provider have to comply with a subpoena?
Generally yes, if it's a valid subpoena from a court with jurisdiction over the company — but compliance means providing whatever data actually exists, not creating data that was never collected. A genuinely no-logs provider can legally comply by truthfully stating it has nothing to produce.
What actually happened when the FBI subpoenaed Private Internet Access?
In two separate, unrelated cases in 2016 and 2018, PIA was subpoenaed for user activity logs. In both cases, documented in public court filings and testimony, the company could not produce identifying data because it does not retain that type of log — the same outcome tested twice, independently, four years apart.
Can a VPN provider refuse to comply with a legal subpoena?
Providers generally cannot simply refuse a valid subpoena from a court with proper jurisdiction, but they aren't obligated to produce data they don't have. The distinction between the legal obligation to respond and the technical reality of what data exists is exactly what separates cases where nothing was produced from cases where identifying data was handed over.
What's the difference between a subpoena and a warrant for VPN user data?
Both are formal legal demands, but warrants typically require a higher legal standard (probable cause, judicial approval) and can authorize more invasive actions like physical server seizure, as happened to ExpressVPN in Turkey. A subpoena is a compelled request for specific records or testimony without necessarily authorizing physical seizure.