VPNs at SMBtech

VPN Industry Faces Scrutiny Over Tracking, Surveillance Risks And Streaming Demand

Surprisingly Useful AI Article Enhancements

The virtual private network industry is under pressure from multiple directions, with new research revealing that the vast majority of mobile VPN apps contain tracking software, a US senator pushing for revised government guidance on VPN security limitations, and enterprise security experts warning that many commercial VPN solutions cannot withstand state-sponsored cyber threats.

At the same time, consumer interest in VPNs continues to grow, driven by geo-restricted streaming libraries and major sporting events that have made location spoofing a routine part of the modern viewing experience.

Investigation finds 85 per cent of mobile VPN apps contain trackers

An investigation by Swiss privacy company, Proton, has found that 85 per cent of the mobile VPN apps available in US app stores contain third-party tracking components that collect device identifiers, location data and network information before passing it to advertising infrastructure.

Proton’s research team analysed more than 7,000 mobile VPN apps worldwide before narrowing the focus to 390 VPN services actively downloaded through the Apple App Store and Google Play in the United States. The team cross-referenced download volume data from mobile-app intelligence firm, AppTweak, with tracker-detection data from Exodus Privacy, an open-source project that scans Android applications for known analytics, advertising and profiling code.

Of the 390 apps examined, 64 were found to actively access users’ GPS location. Those 64 apps alone were downloaded approximately 3 million times in June 2026, representing roughly 20 per cent of all VPN downloads in the dataset. Across the full sample, Apple and Google permitted the flagged apps to be downloaded more than 13.2 million times in the US in a single month.

Forbes covered the findings with a blunt framing, describing them as “the ultimate act of betrayal” for users who installed a VPN to avoid surveillance.

Chinese-owned VPN apps obscure their origins

Ownership emerged as a separate concern in Proton’s report. Of the 390 VPN services examined, 64 are owned by Chinese companies. Under Chinese corporate law, companies are required to hand over user data to state authorities on request, which means these apps cannot structurally guarantee the privacy their marketing promises.

Of those 64 Chinese-owned apps, 31 obscure their ownership behind shell companies registered in Singapore, Hong Kong and the United Kingdom, making it difficult for a US consumer to identify who is operating the VPN they have installed.

Proton named several of the apps involved, including VPN Proxy Master, VPN-Fast VPN Super and X-VPN, which collectively accounted for over 3 million US downloads in June 2026.

The underlying business model drives the problem. Apple and Google take roughly 30 per cent of every in-app purchase, meaning free VPN apps must find alternative revenue streams. The advertising and data-broker ecosystem that funds mobile games and utilities is equally available to VPN developers. Many US-owned apps in Proton’s dataset entered commercial agreements with foreign companies that embedded tracking software as part of the arrangement.

App store review processes do not currently catch these practices because Apple and Google rely heavily on developers’ self-reported privacy declarations rather than independently verifying whether an app behaves as its privacy policy claims.

Senator presses NSA to update VPN security guidance

In Washington, Oregon Senator, Ron Wyden, is pressing the National Security Agency to revise its cybersecurity guidance to warn Americans that a standard commercial VPN may not protect them from sophisticated foreign surveillance.

A Congressional Research Service analysis requested by Wyden’s office found that foreign intelligence services monitoring large parts of the internet may be able to connect a VPN user to specific websites by matching the timing and volume of encrypted data entering and leaving a VPN server.

The method, known as traffic analysis, does not require an adversary to break the service’s encryption and could expose a user’s online behaviour even while the underlying data remains unreadable.

“Encryption strength alone does not protect users from an advanced, persistent threat conducting bulk traffic collection,” the CRS wrote.

The concern centres largely on single-hop VPNs, which route a user’s traffic through one provider’s server before sending it to its destination. Anyone capable of monitoring or compromising that server may be able to correlate the traffic entering the VPN with the traffic leaving it.

“Americans facing advanced foreign threats deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote in a letter to NSA Director, General Joshua Rudd.

Wyden asked the NSA to provide unclassified answers by October 14.

The CRS noted that services such as Tor, Nym and Apple’s iCloud Private Relay make traffic analysis harder by splitting information about a user and their destination across multiple servers, although Private Relay does not cover all device traffic. None guarantee full anonymity.

Current NSA and Cybersecurity and Infrastructure Security Agency guidance focuses primarily on preventing hackers from exploiting vulnerabilities in remote-access VPN products to enter government or corporate networks. It recommends measures such as rapidly installing security updates, requiring multifactor authentication and reducing the number of exposed features.

The Office of the Director of National Intelligence offered a separate assessment, describing VPNs as useful for basic cybersecurity and advising consumers to examine a provider’s encryption, privacy and data-retention practices. ODNI also noted that a VPN provider may know a customer’s identity and retain records of their activity.

Enterprise VPNs face state-sponsored threats

The security limitations of commercial VPNs extend into the enterprise sphere. French defence and cybersecurity firm, Thales, has warned that the vast majority of VPN solutions are incapable of protecting organisations against state-sponsored actors with advanced technical expertise and substantial resources.

Thales pointed to France’s ANSSI cyberthreat landscape report, which found that state-sponsored actors had exploited zero-day vulnerabilities in a commercial enterprise VPN solution before the vendor had released a security patch. The attackers were then able to move laterally within compromised networks and gain access to internal resources.

According to the CESIN barometer cited by Thales, more than half of French companies believe the threat of state-sponsored cyberattacks is increasing, while 40 per cent consider cyber espionage to be a high risk.

Free VPN solutions drew particular criticism. Thales cited an ICSI study finding that 75 per cent of free VPN services include trackers that allow providers to resell connection data. A separate study found that 88 per cent of free VPNs leak data, either intentionally or unintentionally.

The company warned that some paid professional VPNs still rely on outdated protocols such as PPTP, developed by Microsoft in the 1990s, whose encryption and authentication mechanisms have been considered obsolete for more than a decade. Thales recommended that organisations adopt VPNs built on the IPsec protocol combined with the IKEv2 key exchange protocol and certificate-based authentication rather than passwords.

The NIS2 Directive identifies the security of remote access as a specific objective and requires covered entities to encrypt their communications, making VPN selection a compliance question as well as a security one.

Consumer VPN demand grows alongside streaming

While the security picture raises questions about the trustworthiness of many VPN providers, consumer demand for VPN services continues to climb, driven substantially by streaming access.

The 2026 US Open tennis tournament has become the latest major event to prompt viewers to consider VPN use. With ESPN holding exclusive US broadcast rights and Australian broadcaster, 9Now, streaming the tournament for free, publications including PCMag have published guides advising viewers outside Australia to use a VPN to access the free stream.

PCMag recommended connecting to an Australian server via a VPN to access the 9Now livestream, noting that viewers could avoid the cost of US-based streaming subscriptions. ESPN’s own streaming service starts at $30 per month, while live TV services carrying the tournament range from Sling at $20 per month to YouTube TV at $65 per month.

Separately, consumer interest in VPNs for unlocking geo-restricted streaming libraries continues to grow. One technology journalist documented their experience installing Proton VPN on a smart TV and finding content unavailable in their home market across Netflix and YouTube.

The journalist found that Netflix’s catalogue varied considerably by country, with different instalments of film franchises available in different regions. YouTube’s free Movies and TV section, which according to Deadline contains over 4,000 TV episodes and 1,500 movies, was accessible from a US-based VPN server but unavailable in most other countries.

The experience was not without limitations. Amazon Prime detected the VPN and locked its country-specific catalogue, and some content on other platforms still required separate purchase or rental.

Choosing a VPN that delivers on its promises

The convergence of tracking concerns, surveillance risks and growing consumer demand has placed renewed focus on what distinguishes a trustworthy VPN from one that treats its users as a product.

Independent third-party audits have emerged as the primary signal. A VPN provider that publishes findings from a major auditing firm confirming that no logs are retained, and repeats the exercise on a recurring basis, provides a level of accountability that marketing claims alone cannot match.

Ownership transparency is the second key factor. A VPN based in a jurisdiction with strong privacy law, operated by a company that discloses who runs it and where its servers are physically located, offers a structural advantage over services hidden behind shell companies.

Proton, which published the tracker investigation, operates under Swiss data protection law and has open-sourced its client applications. The company acknowledged that its report serves as competitive positioning, but the underlying findings are verifiable through independent tools. Exodus Privacy is open source and AppTweak is a commercial third party, and the full report has been covered by multiple outlets with no stake in Proton’s business.

In Australia, consumer interest in VPN setup and configuration has also been notable, with publications running guides on how to configure VPN services for both privacy and streaming purposes.

For consumers, the practical takeaway is clear: the label “VPN” on an app store listing guarantees nothing about privacy. The gap between what VPN apps promise and what they deliver has become a documented problem, and the burden of due diligence remains with the user.

Last Updated on September 3, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.

Leave a Reply