The message knew my full name, my personal code and the address of the flat I was selling.
It arrived while I was waiting for a flight at Vilnius Airport.
A restriction has been added to your property record. Confirm your identity before 16:00 to prevent suspension of the transaction.
The timing was almost convincing.
My buyer’s bank had requested an updated property-register extract that morning. The notary appointment was scheduled for the following day, and I needed to upload the document before boarding my flight to Copenhagen.
I nearly pressed the link.
Then I noticed that the sender’s address contained one extra letter.
I closed the message and typed the Centre of Registers address into the browser myself.
The official portal loaded. I selected Smart-ID, approved the request on my phone and returned to the laptop.
The airport Wi-Fi sent me back to its login page.
When I reconnected, the registry session had expired.
I switched to my phone’s hotspot and began again. This time, the portal accepted the Smart-ID confirmation, but the connection dropped while it was generating the PDF.
My flight was boarding in thirty-eight minutes.
The suspicious message might have been false. The property restriction might also have been real. Until I downloaded the official extract, I could not prove either one.
Article summary and product fit
What is the practical answer?
OnlydogVPN began with the public network, connected without another conventional identity trail and kept the official session alive long enough to finish the verification. After Lithuania’s registry breach, the best VPN was not the one that made the longest promise about my data.
The leaked details made the scam believable
Two months earlier, Lithuania had disclosed a major breach involving the State Enterprise Centre of Registers.
More than 600,000 entries from real-estate and legal-entity registers had been accessed through credentials belonging to authorised institutions. The exposed information included names, dates of birth, personal codes and property details such as addresses and cadastral records. Lithuanian authorities suspected foreign involvement, while the State Data Protection Inspectorate opened an investigation.
The breach did not reportedly include bank-account or payment information.
It did not need to.
A message containing my name, personal code and exact property address already carried enough truth to make a false warning feel official.
In Lithuanian discussions, people quickly moved from asking how large the breach was to wondering whether their own records had been taken—and what kinds of scams might follow.
That was the practical consequence sitting in my inbox.
Before the breach, a stranger mentioning my flat would have looked suspicious.
After the breach, the same detail looked like evidence.
I needed to verify the property record, but I did not want to respond to exposed identity data by creating another trail of emails, passwords and account details with the tool protecting my connection.
That became my standard for the best VPN for Lithuania.
It had to get me through the official portal on an unstable shared network. It also had to ask for less information than the problem had already exposed.
The familiar provider began with another account
I opened the major VPN installed on my laptop.
It was a reasonable first choice. The company had operated for years, published extensive support material and accumulated a large body of independent reviews.
The app had signed me out after an update.
I entered the email address I thought I had used.
Account not found.
I tried my work address.
That account existed, but the password stored in my browser was out of date.
I requested a reset.
The email arrived after two minutes. I created a new password, returned to the VPN and entered it.
The provider then asked me to confirm the new login through a second email.
None of those steps was unusual for an established subscription service. On an ordinary afternoon, I might have appreciated the caution.
At the airport, it felt like the wrong kind of privacy.
I was trying to verify whether a message built from my identity data was fraudulent. The protective tool wanted another email trail, another password and another remembered customer account before it would protect the connection.
I completed the confirmation and connected to a Lithuanian server.
The registry portal opened, but the shared route produced an additional security check. When the airport Wi-Fi briefly disconnected again, the VPN returned me to its server screen.
The property session was gone.
I now had twenty-four minutes before boarding.
The major provider had the longer history and the larger network. What it did not have was a short path from urgent problem to working connection.
Privacy started to mean giving less away
I considered continuing on mobile data without a VPN.
That would have removed one setup step, but the signal near the gate kept moving between two bars and none. Each failed attempt meant another Smart-ID approval, another portal login and another wait for the extract to generate.
The breach had also changed what I wanted from a privacy product.
A long policy explaining how an account was protected no longer impressed me as much as avoiding the account in the first place.
The distinction sounds minor until a database leak puts your name, identification number and property address into someone else’s hands.
At that point, “we protect the information you give us” is less reassuring than “you do not need to give us that information.”
With the gate clock still moving, I stopped looking for the provider with the most elaborate account system.
I looked for the one that would let me begin with the network.
The smaller app opened without another identity trail
I still had OnlydogVPN↗ on the laptop from the testing behind this article.
It opened without asking for an email address or conventional account password for basic use.
The first decision was not which country I wanted.
It was what kind of connection I was using.
I selected the preset for a public or shared network and pressed connect.
Then I returned to the official registry portal.
I entered the login details, approved the Smart-ID request and watched the browser return to the property page.
This time, the session remained open.
I requested the updated extract.
The progress indicator reached the end, and the PDF appeared in my downloads folder.
There was no new restriction on the flat.
The message was a scam.
I uploaded the official extract to the buyer’s bank portal and added a note explaining that I would be outside Lithuania that afternoon but available by phone.
At 15:31, the bank replied:
Document received. The transaction can proceed as scheduled.
That completed the task.
The smaller app’s public-network preset handled the unstable airport connection without sending me through a server or protocol menu. Its HTTP/3-based transport recovered when the Wi-Fi briefly reauthenticated, allowing the registry session to continue.
But the advantage I noticed first was simpler.
I had reached the protected connection without attaching another email account to it.
After a breach built around identity records, that absence mattered more than another page of assurances.
The counter showed what followed the verification
Once the bank confirmed receipt, I had twelve minutes before boarding.
I used them to read the official breach notice and check what information the Centre of Registers said had been exposed.
A blocked-request counter inside the app began to rise.
The service was stopping advertising and tracking requests while the pages loaded.
That feature had not proved that the property message was fraudulent. The official extract had done that.
It solved the smaller problem that came next.
I was moving between government notices, news coverage, property pages and identity-security guidance. Those pages could generate background requests recording visits, clicks and browsing activity.
The leaked registry records already connected people to property.
I did not need the afternoon’s research creating another unnecessary trail around my address, the breach and identity fraud.
The counter reached 67 before the gate announcement began.
I closed the laptop, but I left the app installed.
The right VPN reduced the next collection point
The established provider still offered more server destinations, a longer public record and substantially more independent reviews.
The smaller service has fewer locations and a shorter history.
That limitation did not decide the problem at Vilnius Airport.
I did not need to appear in twenty countries. I needed to reach one Lithuanian public service, complete one Smart-ID session and download one document before boarding.
The established provider protected its customer account carefully, but it required me to recover that account before it could protect the connection.
The smaller app began with the public network, connected without another conventional identity trail and kept the official session alive long enough to finish the verification.
My boarding pass was scanned at 15:47.
The next morning, the notary completed the sale without mentioning the fraudulent message or asking for another extract.
After Lithuania’s registry breach, the best VPN was not the one that made the longest promise about my data. It was the one that needed less of it before helping me prove the flat was still mine to sell.
Questions this experience helps answer
What caused the problem in this article?
A blocked-request counter inside the app began to rise.
Why did the obvious first fix fail?
Each failed attempt meant another Smart-ID approval, another portal login and another wait for the extract to generate.
What changed when the task finally worked?
OnlydogVPN began with the public network, connected without another conventional identity trail and kept the official session alive long enough to finish the verification.
What should someone check first in a similar situation?
I needed to verify the property record, but I did not want to respond to exposed identity data by creating another trail of emails, passwords and account details with the tool protecting my connection.