Independent audits of free VPN apps have found the same problems for a decade: some apps do not encrypt traffic properly, many leak data outside the tunnel, most embed trackers, and a minority are outright malware or proxyware that rents out users’ connections. The most recent research, from 2025 and 2026, adds a newer concern: several of the biggest free apps belong to hidden corporate families that share code, servers and even encryption passwords.
Not every free VPN is dangerous, and some free services are run by reputable organizations. The evidence still shows that free VPN apps deserve more scrutiny than almost any other app category, because a VPN app can see everything you do online.
What the major studies found
| Study or investigation | Year | Apps examined | Findings | Source |
|---|---|---|---|---|
| Ikram et al., CSIRO Data61/ICSI/UC Berkeley | 2016 | 283 Android apps using the VPN permission | 18% no encryption; 84% leaked IPv6 and 66% leaked DNS traffic; 38%+ flagged by antivirus engines; 75% used tracking libraries; 4 intercepted TLS | IMC, 2016 |
| Wilson, McLuskie, Bayne, Abertay University | 2020 | iOS VPN apps | Most still sent some data over plain HTTP; outdated servers, HTTPS interception capability, questionable privacy policies | ARES, 2020 |
| UFO VPN and six related apps | 2020 | 7 white-label free VPN apps | 1.2 TB and about 1.08 billion log entries exposed, including passwords, IP addresses and visited sites, despite no-log claims | The Register, 2020 |
| ACCC v. Meta (Onavo Protect) | 2023 | 1 free VPN app, 270,000+ Australian installs | App-usage data used for Meta market research without clear disclosure; A$20m penalty | ACCC, 2023 |
| HUMAN Satori, “PROXYLIB” | 2024 | 28 Google Play apps, 17 posing as free VPNs | Phones secretly enrolled as residential proxy nodes via an SDK; apps removed | BleepingComputer, 2024 |
| FBI/DOJ, 911 S5 botnet | 2024 | Windows VPN apps incl. MaskVPN, DewVPN, ShieldVPN | Proxy backdoor installed with the VPN; 19 million+ IP addresses in 190+ countries | FBI IC3, 2024 |
| Tech Transparency Project | 2025 | Top 100 free VPNs, US App Store, 2024 | 20 with undisclosed Chinese ownership, 70 million+ US downloads | TTP, 2025 |
| Mixon-Baca, Knockel, Crandall | 2025 | 21 Android apps, 972 million+ downloads | Shared hard-coded Shadowsocks passwords allowed decryption; deprecated cipher; location data collected despite privacy policy | FOCI, 2025 |
| Google Threat Intelligence Group, IPIDEA | 2026 | Apps with four proxy SDKs, incl. VPN apps | Devices used as exit nodes for a proxy network used by 550+ threat groups in one week | Google, 2026 |
Weak or missing encryption
The 2016 study by Ikram and colleagues analyzed 283 Android apps that requested Android’s VPN permission, drawn from more than 1.4 million Google Play apps. It found that 18% tunneled traffic without encryption, even though most promised privacy or security (Ikram et al., 2016).
The problem did not disappear. The 2025 “Hidden Links” study found that apps in two hidden families shipped Shadowsocks proxy configurations with hard-coded passwords. Because anyone who downloads the app gets the same password, the researchers showed they could decrypt traffic from those apps when they used Shadowsocks. One family also used rc4-md5, a deprecated cipher (Mixon-Baca, Knockel and Crandall, 2025). The three families in the study together had more than 700 million Google Play downloads.
Traffic leaking outside the tunnel
A VPN that sends some traffic around the tunnel exposes exactly what users want to hide. In the 2016 study, about 84% of apps did not tunnel IPv6 traffic and 66% did not tunnel DNS lookups, often because of misconfiguration or missing IPv6 support (Ikram et al., 2016).
The Abertay University study of iOS VPN apps in 2020 found that a large majority still sent certain data over unencrypted HTTP (Wilson, McLuskie and Bayne, 2020).
Trackers, ads and excessive permissions
Free apps need revenue, and the most common source is advertising. In 2016, 75% of the VPN apps studied embedded third-party tracking libraries and 82% requested access to sensitive resources such as user accounts and text messages. Two apps injected JavaScript into users’ traffic for ads and tracking, and one redirected e-commerce traffic to advertising partners (Ikram et al., 2016).
The 2025 study found that some apps sent users’ ZIP codes, derived from their IP address, to a Firebase endpoint even when the app had not asked for location permission, despite privacy policies saying they did not collect addresses (Mixon-Baca, Knockel and Crandall, 2025).
Malware and proxyware
The most serious category is apps that use the VPN as cover for something else.
- In 2016, over 38% of the 283 apps contained some malware presence according to VirusTotal, even though 37% had more than 500,000 installs (Ikram et al., 2016).
- In the 2024 PROXYLIB case, HUMAN’s Satori team found 28 Google Play apps, 17 of them disguised as free VPNs, that turned phones into nodes of a residential proxy network through a library in the LumiApps SDK. Google removed the apps and updated Play Protect (BleepingComputer, 2024).
- Also in 2024, the FBI said the 911 S5 proxy botnet spread through free VPN apps including MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN and ShineVPN, often bundled with pirated software. It compromised more than 19 million IP addresses in over 190 countries (FBI IC3, 2024). These were mainly Windows apps, but the business model is the same as on mobile.
- In 2026, Google’s Threat Intelligence Group took action against IPIDEA, which it called the world’s largest residential proxy network. Developers were paid to embed SDKs (Castar, Earn, Hex and Packet) that turned users’ devices into exit nodes. Google named IPIDEA-linked VPN brands including Galleon VPN, Radish VPN and Door VPN, and said Play Protect now warns users about and removes apps with these SDKs (Google, 2026).
If your phone becomes a proxy exit node, strangers’ traffic, including criminal activity, can appear to come from your home IP address.
“No logs” claims that did not hold up
In July 2020, researchers found an exposed database belonging to UFO VPN. It and six related Hong Kong-based apps (FAST VPN, Free VPN, Super VPN, Flash VPN, Secure VPN and Rabbit VPN) shared one white-label back end. The leak totaled about 1.2 TB and 1.08 billion log entries, with IP addresses, connection times, websites visited and, according to researchers, plaintext passwords. UFO VPN disputed the password finding (The Register, 2020).
Data collection can also be a business model. Onavo Protect, a free VPN owned by Facebook (now Meta), was marketed in Australia as a way to protect personal information. Australia’s Federal Court found that its listings did not disclose that app-usage data was shared with Meta for market research, and ordered two Meta subsidiaries to pay A$10 million each (ACCC, 2023).
Hidden owners
Ownership matters because the operator of a VPN can see your traffic. The Tech Transparency Project found that 20 of the top 100 free VPNs in Apple’s US App Store in 2024 had undisclosed Chinese owners, several linked to Qihoo 360, a company sanctioned by the US Commerce Department in 2020 (TTP, 2025). The 2025 academic study confirmed links among such providers through shared code, servers and credentials. See our mobile VPN market report for the publishers involved.
Problems with paid VPNs
Paid VPNs have problems too, though usually milder ones. Consumer Reports’ 2021 evaluation of 16 VPNs on Windows, carried out with University of Michigan researchers, found that 12 made inaccurate or hyperbolic claims about the protection they offered, and 8 lacked a current public security audit (Consumer Reports, 2021). The worst free-app findings go further, to malware, proxyware and decryptable traffic.
What users can do
- Check the developer. On Google Play, tap the developer name and look for a real company with a website, a physical address and a clear privacy policy.
- Look for an independent security review. Google Play shows a badge for VPN apps that passed a MASA assessment, though the badge is only a baseline.
- Be wary of “free, unlimited, no sign-up” apps with ads. That combination appears repeatedly in the apps flagged above.
- Watch for proxy or “earn money” features. Any app that pays you or offers free service in exchange for “sharing bandwidth” may route other people’s traffic through your phone.
- Keep Play Protect on. Several of the cases above ended with Google removing apps through Play Protect.
- Prefer free tiers from transparent providers. Some reputable companies and nonprofits offer free plans with audits and published ownership.
Methodology
Sources are peer-reviewed papers, regulator and law-enforcement publications, a technology-industry threat report and reputable news coverage, all directly accessible as of October 1, 2026. Where possible, findings come from the primary document (paper PDF, ACCC release, FBI alert, Google blog); the HUMAN and UFO VPN cases rely on detailed reporting by BleepingComputer and The Register.
The 2016 study is a decade old and apps have changed since; it serves as a baseline, not a current measurement. Each study used different methods and samples, so their percentages cannot be added up or compared directly. No apps were tested for this report. Findings published only by VPN companies or affiliate sites are excluded.