← All categories
VPNs
Privacy tools with privacy problems. One is a botnet. One was adware. One hired a spy. Only one passed the police raid test.
9 devices analyzed. Set your privacy comfort level to filter.
What we found
Hola VPN: FNot a VPN. A 280-million-user botnet that sold your bandwidth for ad fraud. Built-in backdoor. Removed from Chrome for malware. CEO admitted most users didn't know.
P2P network where every free user becomes an exit node routing strangers' traffic. Luminati/Bright Data sold bandwidth at $20/GB. CEO: 'users are NOT aware.' Trend Micro: 'unencrypted web proxy, not a VPN.'
Private Internet Access: DPIA is owned by a company that used to help inject ads into people's browsers.
Owned by Kape Technologies (formerly Crossrider), classified as adware by Symantec and MalwareBytes. Crossrider's SDK was used to inject ads into browsers. UC Berkeley/Google identified it as a major ad injector affiliate. CEO admitted 2018 rebrand was to escape "past activities." Founder Teddy Sagi convicted of fraud in Israel (1996). Kape went fully private in 2023 via Unikmind Holdings, eliminating public reporting. 180 employees laid off in 2025-2026.
NordVPN: DSomeone had complete control of a NordVPN server for weeks, could see everything passing through it, and NordVPN didn't notice for over a year.
2018 Finland server breach: attacker had 'God Mode' via datacenter's undisclosed remote management system. TLS and OpenVPN CA keys compromised. NordVPN did not detect the breach. 19-month disclosure delay. Up to 200 users at theoretical risk.
Hotspot Shield: DThe VPN that 'guarantees' privacy was caught injecting ads, hijacking shopping traffic for affiliate commissions, and sharing device identifiers with adverti...
CDT/FTC complaint (2017): JavaScript injection via iFrames, traffic redirection to affiliate partners (alibaba, ebay, target, bestbuy, macys), MAC/IMEI sharing with ad networks, carrier info over HTTP.
Surfshark: DSurfshark's Android app requests 42 permissions — including microphone, contacts, and phone numbers.
Android app: AppsFlyer marketing tracker, AD_ID permission. Also: RECORD_AUDIO, READ_CONTACTS, READ_PHONE_NUMBERS, ANSWER_PHONE_CALLS, QUERY_ALL_PACKAGES. 42 permissions.
ExpressVPN: DExpressVPN is owned by a company that used to inject ads into browsers.
Parent Kape Technologies (formerly Crossrider) classified as adware by Symantec/MalwareBytes. Injected ads via browser extensions. Founder Teddy Sagi convicted of fraud. Went private 2023, eliminating oversight. 180 employees laid off.
How audits work in this category
Common standard: ISAE 3000
What it covers: Verifies that the VPN provider's server configuration and operational practices match their stated no-logs policy during the audit window.
What it misses: Cannot verify what happens outside the audit window. Scope negotiated with the provider. "No-logs" has no legal definition. Limited assurance = "nothing came to our attention."
Product Auditor Standard Trust signals
ExpressVPN DKPMG, Cure53, F-SecureISAE 3000, pen test, pen testSpecialist audit, Big Four
Mullvad VPN CCure53, Cure53source code review, pen testSpecialist audit
NordVPN DDeloitte, Cure53ISAE 3000, pen testSpecialist audit, Big Four
Private Internet Access DDeloitteISAE 3000Big Four
Proton VPN CCure53, Securitumsource code review, pen testSpecialist audit
Surfshark DDeloitte, Cure53ISAE 3000, pen testSpecialist audit, Big Four
Gold standard for this category:
  • Open-source code
  • Specialist security audit (Cure53)
  • Bug bounty programme
  • RAM-only servers
Achieves all four. Has never cited a Big Four audit.
For the auditors' own track record, see Who Audits the Auditors?

Your privacy tolerance