Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
Researchers and breach reports have documented free VPN risks; they are not hypothetical. A study by CSIRO’s Data61, UNSW and UC Berkeley tested 283 Android VPN apps on Google Play. VirusTotal flagged 38% for malware, 75% used third-party trackers, 18% did not encrypt traffic and 84% leaked IPv6. The sample included paid apps too. In 2023, a SuperVPN breach exposed 360 million records, and the FBI still publishes a removal guide for free VPN apps tied to the 911 S5 botnet.
This guide covers the risks, real cases and how to check an app. Reputable free plans exist; the point is to choose carefully.
What the Research Found
The CSIRO-led team published in 2017 on 2016 data. It also found 82% of apps requested sensitive permissions and 16% routed traffic through other users’ devices. Two apps injected JavaScript, and four intercepted encrypted connections. Tom’s Guide noted the two apps with the most malware detections were paid.

Free VPN Risks in Real Breaches
In 2020, seven Hong Kong-based free VPNs, including UFO VPN and Rabbit VPN, leaked user data. In 2023, SuperVPN exposed 360 million records, including email addresses, original IPs and visited websites, bitlaunch summarises.

Your Device as Someone Else’s Proxy
The 911 S5 botnet used free VPN apps to turn users’ devices into proxies for others, Dataconomy notes, and the FBI keeps a removal guide. Symptoms include unexplained upload traffic and constant CAPTCHAs.
Data as the Business Model
Gizmodo’s 2026 iPhone testing found most free App Store VPNs cap data at 500 MB to 2 GB, and that many uncapped apps fund themselves by selling browsing data. Our free VPN data limits guide compares plans.
Checking a Free VPN
Check who runs it and where, whether an audit backs its no-logs claim, how it makes money, which permissions it asks for, and whether it leaks. Our DNS leak guide covers the leak test.

Free VPN Risks on iPhone
The App Store reviews apps, but Gizmodo still warns that uncapped free VPNs often rely on data sales. Read the App Store privacy labels before installing. Our free VPN for iPhone guide covers safer picks.
Permissions to Question
A VPN needs network access. It does not need your contacts, texts or call logs. The CSIRO-led study found 82% of apps asked for sensitive permissions.
Removing a Suspect App
Uninstall it, check for leftover VPN profiles in system settings, and change passwords you used while it ran. If you suspect 911 S5-style abuse, the FBI’s removal guide lists steps.
Paid Is Not Automatically Safe
The two apps with the most malware detections in the study were paid, Tom’s Guide noted. Check audits and ownership for paid apps too.
Free VPN Risks for Families
Children often install free apps without checking. Review the VPN apps on family devices, remove unknown ones and use the device’s parental controls for content.
Free Trials Instead
A paid provider’s trial or refund window lets you test without the risks of an unknown free app. Our free VPN trial guide explains how they work.
Leak Testing
The CSIRO-led study found 66% of apps leaked DNS and 84% IPv6. Test any VPN, free or paid, with our leak guides before trusting it.
Quick Check
Before installing a free VPN, ask four questions: who runs it, who paid for its audit, how it earns money and what it asks to access. No clear answer means skip it.
Ads and Injected Content
Two apps in the study injected JavaScript into users’ traffic for advertising and tracking, the researchers found. Unexpected adverts on sites that never showed them are a warning sign.
Free VPN Risks vs Paid Plans
Paid plans remove the incentive to sell data but still need checking. Our VPN audit tracker shows which paid providers had independent audits.
Who Runs the App
Look for a named company, a physical address and a privacy policy that says what is logged. Anonymous developers and vague policies are reasons to walk away.
Quick Rule
Named owner, audit, paid customers funding the free tier, minimal permissions, no leaks. Anything less, skip it.
Keeping It Updated
Whatever you install, keep it updated, since fixes close leak paths found after release.
Old Study, Current Lesson
The CSIRO-led data is from 2016, and Google has removed many of the apps since. The breaches of 2020 and 2023 and the 911 S5 case show the same risks continued. Our guide to VPN for Students covers campus Wi-Fi, school rules and study abroad.
Browser Extensions
Free proxy extensions carry similar risks, since they see all browser traffic. Our VPN vs proxy guide explains the difference.
Safer Free Options
Paid users fund Proton VPN’s free plan, which has no data cap and five Securitum audits in our table. Our Proton VPN free guide covers its limits, and our free VPN roundup covers others.
How We Research
This page draws on the CSIRO-led study as reported by CSIRO, TorrentFreak, ABC and Tom’s Guide, bitlaunch’s breach summary, Dataconomy on 911 S5 and Gizmodo’s 2026 iPhone testing. We cross-checked these sources against each other, and where they conflict or something can’t be verified, we say so in the text rather than guessing. We checked time-sensitive figures, including prices in US dollars, on 8 October 2026. The main source we relied on is CSIRO’s study summary. Our full approach lives on the About Us page.
Free VPN Risks FAQ
Many are; a 2016 study found malware in 38% of Android VPN apps tested.
Often through adverts or selling data, Gizmodo warns.
Yes; SuperVPN exposed 360 million records in 2023.
Some, such as Proton VPN Free, funded by paid users and audited.
Yes; 911 S5 apps turned devices into proxies.
The Verdict
Free VPN risks include malware, tracking, leaks and botnets. Use a free plan only from a provider with paid customers, audits and a clear business model.
