Affiliate Disclosure: SecureGuides is reader-supported. When you buy through links on our site, we may earn a commission at no extra cost to you. Our reviews and rankings remain independent — read our affiliate disclosure.
Are free VPNs safe — a padlock representing the security risks covered in this guide

Are Free VPNs Safe? The Real Risks (2026 Research)

Are free VPNs safe? The honest answer, backed by multiple independent studies spanning nearly a decade: mostly no, and the specific reasons why are more concerning than a vague “you get what you pay for” warning. Real, peer-reviewed research and independent investigations have repeatedly found that most free VPN apps leak the data they claim to protect, track users through embedded ad networks, request permissions they have no legitimate need for, and in some cases were built to power criminal botnets. Here’s what the actual research found, study by study, not marketing claims from paid competitors.

Are free VPNs safe — a padlock representing the security risks covered in this guide
Photo by Gannu03. CC BY-SA 4.0, via Wikimedia Commons.

The Academic Baseline: A 2016 Study That Still Holds Up

What Researchers Actually Found

The most rigorous, peer-reviewed source on this topic is “An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps,” presented at the 2016 Internet Measurement Conference by researchers from CSIRO/Data61 (Australia), UNSW, and ICSI/UC Berkeley. They analyzed 283 Android VPN apps pulled from the Google Play Store. The findings were stark: 38% contained malware or malvertising; 18–20% didn’t encrypt user traffic at all despite being marketed as VPNs; and 84%+ leaked user traffic or data in some form. (ACM Digital Library; full paper PDF)

Why a 2016 Study Is Still Relevant a Decade Later

This isn’t outdated data being recycled for a lazy headline — it’s the methodological foundation that every subsequent study in this space has built on, and as the more recent research below shows in detail, the same categories of problems (leaks, malware, excessive permissions) keep reappearing in entirely fresh app crops year after year, strongly suggesting the underlying business incentives behind most free VPN apps simply haven’t meaningfully changed since 2016.

The 2024 Top10VPN Study: 88% Leaked Data

What Was Tested

Independent researcher Top10VPN tested the 100 most popular free VPN apps on Google Play, publishing results on June 7, 2024. The findings: 88% suffered some kind of data leak (IPv4, IPv6, DNS, or WebRTC); 71% shared personal data with third parties; over 80% contained third-party ad or marketing SDKs; and 15 apps specifically contained ByteDance SDKs. (Top10VPN Research)

What a “Leak” Actually Exposes

A DNS or WebRTC leak specifically defeats the entire point of using a VPN in the first place: your real IP address and the actual sites you’re browsing become visible to your local network or ISP anyway, despite the app confidently showing a green “Connected” status — meaning the app isn’t merely failing to add protection, it’s actively giving you a false sense of security while providing none of the protection it claims.

The April 2026 Mysterium VPN Review: Trackers Everywhere

18 Apps, 17 With Trackers

Using the open-source MobSF analysis tool, Mysterium VPN tested 18 popular free Android VPN apps, publishing results April 1, 2026, covered by Security Affairs. 17 of the 18 apps contained at least one tracker, averaging 5 trackers per app sourced from US, Chinese, and Russian ad and analytics networks. (Mysterium VPN)

Named Offenders

This study named specific apps: VPN Proxy Master requested 23 permissions (6 flagged “dangerous”); Secure VPN and VPN 360 requested 24 permissions each, the highest in the tested set, including camera, microphone, contacts, and call-log access with no plausible connection to VPN functionality; Turbo VPN was found sending traffic over 30+ plaintext, non-HTTPS URLs.

The July 2026 MVPNalyzer Study: The Most Current, Most Rigorous Research

Are free VPNs safe — smartphone app permissions
Photo by Acabashi. CC BY-SA 4.0, via Wikimedia Commons.

A Massive, Current Dataset

Researchers at the University of Michigan, University of New Mexico, and IIT Delhi published MVPNalyzer on July 10, 2026, analyzing 281 free Android VPN apps with a combined 2.4+ billion installs among the flagged apps — the most current and largest-scale research available on this topic as of this writing. (The Hacker News, July 2026)

The Findings

  • 246 of 281 apps (over 80%) contacted known ad or tracking servers.
  • 169 apps made no attempt to disguise or obfuscate VPN traffic at all.
  • 76 apps transmitted Advertising IDs specifically for cross-app tracking purposes.
  • 61 apps transmitted some user data in plaintext, unencrypted.
  • 29 apps leaked traffic outside the encrypted tunnel entirely, of which 24 leaked DNS traffic specifically — covering roughly 360 million installs among just those leaking apps.
  • 5 apps sent VPN configuration files completely unencrypted, a specific and serious risk since an intercepted config file can let an attacker hijack the tunnel itself.

Beyond Tracking: Malware and Criminal Botnets

A 2.5x Surge in Fake VPN Malware

Kaspersky’s official press release, November 20, 2024, reported that the number of users encountering malicious apps posing as free VPNs increased by 2.5 times in Q3 2024 compared to Q2, a trend that continued into Q4. (Kaspersky, Nov 2024)

The 911 S5 Botnet: Free VPNs Used as Attack Infrastructure

In May 2024, the Department of Justice announced the takedown of what may have been the largest botnet ever recorded — spanning over 19 million unique IP addresses across 190+ countries — built using free VPN apps distributed under the names MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN, and ShineVPN. Users installed these apps genuinely believing they were legitimate free VPN services; instead, their own devices were quietly conscripted as exit nodes for a massive criminal proxy network, without their knowledge or consent, for however long the app remained installed. These specific apps have since been shut down by law enforcement, but the case is a real, extreme illustration of how far the incentive structure of “free” can be pushed.

Hidden Ownership: The China Connection

A Real, Named Investigation

The Tech Transparency Project’s 2024 investigation found that over 20 of the top 100 free VPNs in the US Apple App Store showed evidence of Chinese ownership, none of which disclosed it clearly — some hidden behind layers of shell companies. These apps had a combined 70+ million downloads in the US alone. (Tech Transparency Project)

Apps Tied to a Sanctioned Company

Several named apps — Turbo VPN, VPN Proxy Master, Thunder VPN, Snap VPN, and Signal Secure VPN — were traced back to Qihoo 360, a company the US government has formally designated a Chinese military company, a status that carries real regulatory weight beyond a simple privacy concern. After inquiries from the Financial Times, Apple pulled Thunder VPN and Snap VPN from its store; Signal Secure VPN was quietly removed shortly after. (AppleInsider, April 2025)

Why “Free” VPNs Behave This Way: The Business Model Problem

Running a VPN Costs Real Money

A VPN provider has to pay for server infrastructure in dozens of countries, bandwidth for every user’s traffic, engineering staff, and customer support — none of which is free regardless of what the app’s price tag says. A paid VPN’s business model is straightforward: you pay a subscription, and that revenue funds the infrastructure and, ideally, independent audits. A free VPN with no visible revenue source has to fund all of that somehow, and the research throughout this article shows what commonly fills that gap: selling user data to advertisers, embedding trackers, or in the most extreme documented case, quietly using your device’s own bandwidth and IP address as infrastructure for someone else’s operation.

When You’re the Product, Not the Customer

This is the honest, unglamorous explanation behind every single study cited above: a free VPN with no other visible funding source usually recoups its real operating costs by monetizing the exact data and traffic you installed the app specifically to protect. It’s not that every single free VPN developer sets out to build something malicious — some genuinely start with good intentions and limited resources — but the underlying economics create consistent, predictable pressure toward exactly the outcomes these studies keep independently finding, year after year, across completely different apps, different research teams, and different countries.

The One Real Exception: A Genuinely Free, Audited Option

Not every free VPN fits this pattern — Proton VPN’s free tier is a documented exception worth knowing about, verified directly on protonvpn.com/free-vpn: no data cap, no ads, no logging, and a kill switch included even on the free plan, from a company whose paid tier has real, named independent audits. See our cheap VPN deals guide for the details and trade-offs (one device, no server choice). The existence of one legitimate free option doesn’t undermine the research summarized above — if anything it actually reinforces it, since Proton VPN funds its free tier through revenue from its paid subscriber base rather than through the data-harvesting business model the research keeps finding across the rest of the free VPN category.

Does This Apply to iPhone Too, or Just Android?

Most of the large-scale research cited above — the CSIRO study, Top10VPN, Mysterium, and MVPNalyzer — focused specifically on Android, largely because Android’s more open app-permission model makes this kind of automated analysis easier to run at scale. That doesn’t mean iOS is immune: the Tech Transparency Project’s Chinese-ownership investigation specifically covered the Apple App Store, and Apple’s own app review process has repeatedly missed disclosure problems that only came to light after outside journalists and researchers went looking. The honest takeaway is that iOS’s more locked-down permission model reduces some specific risks (unrestricted background access, for instance) but doesn’t eliminate the core issue of a free app needing to fund itself somehow, or of ownership being disclosed honestly.

How to Evaluate Any Free VPN Before Installing It

  • Check who actually owns the company — a legitimate provider discloses this clearly; if ownership is unclear or buried in shell companies, treat that as a real red flag, not a minor omission.
  • Read the requested permissions before installing — a VPN app has no legitimate functional need for camera, microphone, contacts, or call-log access; several named apps above requested exactly these.
  • Look for a specific, named, dated independent audit — not a vague “we value your privacy” claim, matching the same standard we apply to every paid VPN in our VPN comparison.
  • Be skeptical of unlimited free data with no visible business model — running VPN server infrastructure costs real money, and if a free app isn’t charging you, the research above shows what commonly fills that gap instead.
  • Consider a reputable paid VPN’s free trial or money-back guarantee instead — see our cheap VPN deals guide for real refund windows that let you test a properly-audited service risk-free.

Are Free VPNs Safe? Frequently Asked Questions

Are all free VPNs unsafe?
Not all — Proton VPN’s free tier is a documented, legitimate exception with a kill switch, no logging, and no data cap. But multiple independent studies spanning 2016 to 2026 consistently found the majority of free VPN apps leak data, track users, or request excessive permissions.

What’s the most common problem with free VPN apps?
Data leaks — the 2024 Top10VPN study found 88% of tested apps suffered some form of IP, DNS, or WebRTC leak, meaning the app fails at its core job while showing a false “Connected” status.

Can a free VPN actually contain malware?
Yes — Kaspersky reported a 2.5x increase in malware posing as free VPNs in Q3 2024, and the DOJ’s May 2024 takedown of the 911 S5 botnet showed free VPN apps being used to secretly conscript millions of devices into a criminal proxy network.

Why do free VPN apps need so many permissions?
They usually don’t need them for VPN functionality — the April 2026 Mysterium VPN review found apps like Secure VPN and VPN 360 requesting camera, microphone, contacts, and call-log access, which has no legitimate connection to routing network traffic.

Is it true some free VPNs have hidden ties to China?
Yes, per a real 2024 Tech Transparency Project investigation — over 20 of the top 100 free VPNs in the US Apple App Store showed undisclosed Chinese ownership, with several named apps tied to a US-sanctioned Chinese military company.

Why do so many free VPNs behave this way?
Running VPN infrastructure costs real money for servers, bandwidth, and staff. A free app with no subscription revenue and no other visible funding source has to cover those costs somehow, and the research above shows what commonly fills that gap: selling data, embedding trackers, or worse.

Is a paid VPN automatically safer than a free one?
Not automatically, but it removes the specific data-monetization incentive the research keeps finding in free apps, and lets you apply real, checkable standards — named audits, transparent ownership, published leak-testing — the way our VPN comparison does for paid providers.

Scroll to Top