What we found
Hola VPN: FNot a VPN. A 280-million-user botnet that sold your bandwidth for ad fraud. Built-in backdoor. Removed from Chrome for malware. CEO admitted most users didn't know.
P2P network where every free user becomes an exit node routing strangers' traffic. Luminati/Bright Data sold bandwidth at $20/GB. CEO: 'users are NOT aware.' Trend Micro: 'unencrypted web proxy, not a VPN.'
Private Internet Access: DPIA is owned by a company that used to help inject ads into people's browsers.
Owned by Kape Technologies (formerly Crossrider), classified as adware by Symantec and MalwareBytes. Crossrider's SDK was used to inject ads into browsers. UC Berkeley/Google identified it as a major ad injector affiliate. CEO admitted 2018 rebrand was to escape "past activities." Founder Teddy Sagi convicted of fraud in Israel (1996). Kape went fully private in 2023 via Unikmind Holdings, eliminating public reporting. 180 employees laid off in 2025-2026.
NordVPN: DSomeone had complete control of a NordVPN server for weeks, could see everything passing through it, and NordVPN didn't notice for over a year.
2018 Finland server breach: attacker had 'God Mode' via datacenter's undisclosed remote management system. TLS and OpenVPN CA keys compromised. NordVPN did not detect the breach. 19-month disclosure delay. Up to 200 users at theoretical risk.
Hotspot Shield: DThe VPN that 'guarantees' privacy was caught injecting ads, hijacking shopping traffic for affiliate commissions, and sharing device identifiers with adverti...
CDT/FTC complaint (2017): JavaScript injection via iFrames, traffic redirection to affiliate partners (alibaba, ebay, target, bestbuy, macys), MAC/IMEI sharing with ad networks, carrier info over HTTP.
Surfshark: DSurfshark's Android app requests 42 permissions — including microphone, contacts, and phone numbers.
Android app: AppsFlyer marketing tracker, AD_ID permission. Also: RECORD_AUDIO, READ_CONTACTS, READ_PHONE_NUMBERS, ANSWER_PHONE_CALLS, QUERY_ALL_PACKAGES. 42 permissions.
ExpressVPN: DExpressVPN is owned by a company that used to inject ads into browsers.
Parent Kape Technologies (formerly Crossrider) classified as adware by Symantec/MalwareBytes. Injected ads via browser extensions. Founder Teddy Sagi convicted of fraud. Went private 2023, eliminating oversight. 180 employees laid off.