Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

The end of anonymous protest — How facial recognition puts democracy at risk

Imagine attending a peaceful demonstration, only to have hidden cameras scan your face, match your identity, and log your details into a police database within seconds. This scenario is at the heart of a debate that reignited in Italy last week, highlighting a high-stakes clash between public safety and personal privacy.

Although Italian lawmakers passed the bill on Tuesday with added safeguards, the decision reflects Europe’s expanding appetite for biometric monitoring. A practice Europeans once watched unfold with dread in authoritarian states is now quietly taking root at home.

From London and Paris to Amsterdam and Berlin, police forces across democratic Europe are increasingly piloting AI-powered face-scanning in public spaces and at political demonstrations.

While European leaders frame the technology as a necessary tool to combat crime, privacy advocates warn that facial recognition creates a chilling effect on the right to peaceful assembly and free expression. And the long-term risk may be even more troubling: once facial recognition is normalized, expanding its reach may be the next natural step.

How police in Europe use facial recognition at protests

Facial recognition technology (FRT) is a biometric tool that uses AI to identify individuals by analyzing their facial geometry — such as the distance between the eyes or the contour of the jawline — against a database. This software creates a unique digital signature, often called a "faceprint," which can be integrated directly into CCTV networks, drones, apps, and mobile police units.

Law enforcement deploys FRT in several ways, with Live Facial Recognition (LFR) being the most controversial. LFR scans real-time video feeds to cross-reference passersby against police watchlists almost instantaneously.

Despite significant legal pushback — including a landmark 2020 UK Court of Appeal ruling that found South Wales Police's deployment unlawful — London's Metropolitan Police deployed LFR across two major demonstrations last May.

Similarly, Hungarian authorities used biometric scanning to monitor participants during the 2025 Budapest Pride March.

A placard warns of live facial recognition in progress on the High Street on December 7, 2024 in Southend, England, United Kingdom.

(Image credit: Photo by John Keeble/Getty Images)

By contrast, retrospective facial recognition (RFR) functions more like traditional fingerprinting. Rather than scanning crowds live, police analyze recorded footage or photographs after an event to identify suspects.

This is the technology Italian lawmakers attempted to regulate last week, though police forces across the UK, France, the Netherlands and other European nations have already routinely deployed it.

At first glance, RFR might appear less intrusive — simply another investigative tool for law enforcement to access when necessary. However, human rights experts argue the distinction is misleading.

According to Chloé Berthélémy, Senior Policy Advisor at European digital rights network EDRi, the difference between live and post-event scanning is "largely a procedural distinction."

Speaking to TechRadar, Berthélémy warned: "In human rights terms, there is no salient difference between real-time and post-remote biometric identification. Threats posed to rights and freedoms are not reduced just because authorities or companies have extra time to review footage."

Berthélémy also cautions against the rise of Algorithmic Video Surveillance (AVS) — a system she labels "fundamentally unreliable." AVS uses AI software to analyze live video feeds and automatically flag suspicious or dangerous behavior.

Unlike facial recognition, AVS doesn't log facial features. Instead, it is trained to detect behavioral anomalies and physical triggers, such as sudden crowd surges, unattended luggage, weapons, fires, or individuals falling.

The 2024 Paris Olympic Games served as a testing ground for this technology, making France the first EU member state to legalize AI video analytics.

What European law says about facial recognition and our right to privacy

While facial recognition technology poses a risk to personal privacy, explicit statutory frameworks governing its use remain scarce.

Despite nearly a decade of police trials, the UK still lacks specific legislation governing facial recognition — a gap that Jasleen Chaggar, Senior Legal and Policy Officer at Big Brother Watch, warns has created a "real legal vacuum."

Chaggar explained to TechRadar that British police forces instead rely on a patchwork of common law precedents, existing data protection acts, and broader human rights legislation.

Although the UN Human Rights Committee called on the UK to end police facial recognition at protests, Chaggar notes that governments have resisted statutory regulation, citing police "operational independence."

"This has effectively given police a very long leash to experiment with these technologies," Chaggar told TechRadar. "And now we're in a tipping point situation where it's about to be expanded all over the country, and there's a real necessity for those legal frameworks to be in place."

❌We don't consent to biometric ID checksPolice will be using live facial recognition at @boardmasters festivalThis tech doesn’t just record what you do, your face becomes a barcode in the same way as your fingerprint or DNA#StopFacialRecognition⤵️https://t.co/9do8SIF81t pic.twitter.com/VSgXMTuX1YAugust 6, 2026

In contrast, the European Union's AI Act establishes a binding legislative framework across all member states. While offering greater legal clarity than the UK's approach, digital rights campaigners view the legislation as only a partial victory.

Dr. Matt Mahmoudi, campaign lead for Amnesty International's 'Ban the Scan' initiative, warns that failing to enact a total ban on public biometric surveillance creates broad national security exemptions that jeopardize fundamental rights.

"And it's not just the right to privacy. It's not just the right to protest and the freedom of assembly and expression. It's also the right to equality and non-discrimination," Mahmoudi told TechRadar.

The end of anonymous dissent?

Before facial recognition technology was deployed in public spaces, citizens attending demonstrations could rely on a degree of practical anonymity. Biometric surveillance fundamentally alters that expectation.

Digital rights experts interviewed by TechRadar agree that this level of intrusion steadily erodes civic space. The knowledge that your face is being scanned and cross-referenced against a police watchlist actively deters citizens from attending demonstrations.

“You may decide not to exercise your democratic rights because you're afraid of how it might be perceived by the authorities,” Big Brother Watch's Jasleen Chaggar explained.

Yet this chilling effect extends far beyond the physical cameras deployed at a single rally.

Facial recognition does not operate in isolation. It depends on extensive, often covert data harvesting. To construct watchlists, authorities aggregate imagery from diverse sources, including scraped social media profiles, government identity databases, police custody photos, CCTV archives, and commercial biometric databases.

AI facial recognition tech concept on man face

(Image credit: HQuality / Shutterstock)

As Amnesty International’s Dr. Matt Mahmoudi explains, extensive data aggregation transforms ordinary digital footprints into a pervasive surveillance dragnet.

"Facial recognition is not a simple technology, but a system that effectively weaponizes your entire daily life," Mahmoudi told TechRadar.

Beyond baseline privacy concerns, the underlying technology remains prone to systemic errors.

During eight pilot trials conducted by London's Metropolitan Police between 2016 and 2018, 96% of initial alerts generated were false positives.

Academic research and independent audits consistently show that these algorithmic inaccuracies disproportionately target non-white individuals, women, and ethnic minorities.

The human cost of these algorithmic errors was starkly shown in 2024, when Metropolitan Police officers stopped and searched Sean Thompson — a Black anti-knife-crime campaigner — after live facial recognition software falsely matched his face to a watchlist.

Although computer vision algorithms have advanced in recent years, privacy campaigners emphasize that inherent system limitations remain. As Big Brother Watch's Jasleen Chaggar highlights, because facial recognition relies on probabilistic matching — calculating similarity scores rather than absolute matches — the technology can never be entirely error-free.

Beyond faces: the evolution of biometric surveillance

Even as lawmakers scramble to regulate facial recognition, law enforcement's appetite for public surveillance continues to expand.

In the UK, the growth is reinforced by stricter protest laws like the 2023 Public Order Act, with police monitoring group Netpol warning that enforcement will inevitably rely on an increased use of live facial recognition during demonstrations.

The Conservatives are also calling for greater use of the technology to investigate crimes, while Devon and Cornwall police have already confirmed the use of FRT during the upcoming Boardmasters Festivals.

The obvious immediate danger is that eliminating anonymous dissent could permanently reshape democratic participation. However, privacy advocates warn of an even broader threat: biometric surveillance expanding beyond simple identification into behavioral classification.

Border control authorities are already experimenting with pairing facial recognition with emotion detection and gait analysis — the automated tracking of how an individual walks — which campaigners say could be used to target political demonstrations.

Amnesty International’s Dr. Matt Mahmoudi says that normalizing facial recognition paves the way for other speculative tools that could "fundamentally erode the presumption of innocence."

This rapid technological expansion forces a fundamental question upon democratic societies: how much liberty are citizens expected to trade for security? When scanning a crowd becomes routine policing, public squares risk morphing from spaces of free expression into arenas of perpetual surveillance — where a face is only the initial data point.

This Russian VPN has been accused of breaching its no-log policy — here's what we know

  • Split VPN has been accused of breaching its no-log policies
  • It allegedly leaked 58M connection logs, which SplitVPN denies as its own
  • Users trusting a no-log policy is not enough

Russian SplitVPN (formerly NotVPN) has been accused of breaching its own no-log policy after a data leak exposed a MySQL database containing a variety of data linked to the service, including a staggering 58 million alleged connection logs.

While the VPN provider — whose service is widely used to bypass blocks in countries with heavy censorship — told TechRadar that any allegations it keeps logs are false, the incident highlights the limitations of no-logs policy when things go wrong.

Even with the best VPNs, no-log policies are often based on trust rather than verifiable safeguards, meaning they may not give users a clear picture of the risks users could face if their VPN were exposed to a breach — particularly in countries where criminal prosecution due to the illegal use of VPNs is real.

A no-logs VPN policy means a VPN pledges not to collect or share users' information, including search queries, websites visited, time spent on them, and downloads, while they are connected to one of its servers.

However, it remains difficult for users to verify these claims for themselves. That is why the most secure VPNs have their policies regularly audited by independent organisations, ensuring their privacy promises are genuine and not just a fabricated image.

SplitVPN's alleged data breach

On July 21, a threat actor on the Altenen cybercrime forum distributed a 17 GB SQL database claimed to have been stolen from SplitVPN and which allegedly contained a staggering amount of connection logs alongside user records, devices and payments.

The research team at Mysterium VPN analysed the database and claimed part of it (known as 'deviceproxy') indeed contained around 58 million connection logs.

Although this consisted of anonymised metadata indicating which device had connected to which server and at what time rather than complete browsing histories, SplitVPN maintains that it does not retain such data in accordance with its no-logs policy.

Graph with SplitVPN alleged data breach's findings (August 2026)

(Image credit: MysteriumVPN)

SplitVPN told TechRadar that while the leaked subscription metadata — including email addresses, users' countries of origin, subscription status, masked credit card information and device names — is authentic, the deviceproxy table instead is entirely fabricated.

"The third-party listing claims 58 million connection logs, but this is a fabrication added to inflate the price," a company spokesperson said.

"Because we do not generate or store device-server-timestamp mappings, any records claiming to show this are not from our infrastructure," they added. "The exposed data contains only basic account information, which fully aligns with our no-logs commitment."

SplitVPN added that immediately after discovering the breach, they changed all VPN server node IPs, rotated all access credentials and encryption keys, closed the vulnerability, and engaged external security specialists to audit their infrastructure. Operations have now returned to normal.

The lesser of two evils

While it is arguably nearly impossible to independently verify the deviceproxy data’s authenticity, both scenarios present users with fundamental issues.

If allegations are true, the existence of these logs would directly contradict Split VPN's no-logs policy. When cross-referenced with the IP address of the most recent connection and hardware identifiers, these logs could be sufficient to determine who connected, from where, to which server, and when, putting millions of users in areas with heavy censorship at serious risk.

If claims are fabricated, users are still forced to rely on conflicting statements that they cannot independently verify, with leaked official data potentially causing concern amongst users living in countries where VPN usage is banned.

To ensure your privacy is respected, always look for a privacy policy audit and additional security features including kill switches, double VPN servers, and post-quantum encryption. Advanced technologies such as RAM-only servers or advanced cryptographic privacy can really make a difference. Ultimately, words pass, but technical expertise remains —especially when it’s your data that’s under threat.

Hackers caught hijacking this Chinese Windows VPN's installers to spread malware

  • Fortinet experts found malicious code in QuickFox VPN's Windows installer
  • The attack actively avoided personal gaming computers
  • QuickFox has since removed the malicious components from version 3.59.6

Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese Windows VPN application.

According to a new report from Fortinet’s FortiGuard Labs, attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.

As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience."

However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted malware campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript.

To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6.

TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.

A highly targeted backdoor

QuickFox's app logo

(Image credit: QuickFox)

The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers.

If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.

However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.

When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including IP addresses, active processes, MAC addresses, and usernames.

Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.

While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.

How to stay safe

While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.

The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.

If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system.

Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.

'The largest in history:' Russia blocks over 20 popular VPNs in major internet crackdown

  • On August 4, users in Russia reported widespread disruptions to 20+ VPNs
  • The attack targets the IPs and entire subnets of major hosting providers
  • On August 5, connectivity appeared to have been restored for some

Citizens attempting to bypass Russia's stringent digital censorship are facing fresh obstacles, as a new wave of aggressive government blockages has knocked numerous popular VPN services offline.

On August 4, users across the country reported severe connectivity issues, as reported by Meduza, a Russian independent news outlet. The restrictions appear to have affected more than 20 popular services, making it increasingly difficult for citizens to connect to an open internet.

If you rely on circumvention tools to access independent news, finding the best VPN apps that work in Russia is more crucial than ever. However, this latest blackout suggests the Russian state communications regulator, Roskomnadzor, is deploying more sophisticated methods to sever the country's digital lifelines.

These ongoing blockages are becoming a daily reality for citizens, proving that Russians need a VPN to access Google and Apple as unexplained nationwide outages hit core web infrastructure.

On his Telegram channel, Leonid Volkov, an executive at the Anti-Corruption Foundation (FBK), described the current offensive against independent services as "the largest in history," though the exact scale of the disruptions remains difficult to quantify.

A new era of internet censorship in Russia

The recent outages appear to involve broad, aggressive network restrictions.

According to Russian tech outlet SecurityLab, these new restrictions have targeted the IP addresses and entire subnets of major hosting providers, taking a blunt-force approach to network censorship.

Specifically, Volkov speculated on Telegram that Roskomnadzor’s enhanced blocking capabilities might stem from data harvesting. He suggested that domestic Russian applications, such as banking and marketplace apps, could be tracking users and feeding a massive database of IP addresses to state censors for targeted strikes.

This wave coincides with reports that Russia's Ministry of Digital Development (Mintsifry) is planning to tighten control over corporate VPNs.

Sources suggest the government wants to establish a continuous monitoring mechanism with hosting providers to quickly exclude disguised circumvention tools from a whitelist of permitted corporate IP addresses. This aligns with ongoing fears that Russia's solution to its VPN crackdown is a state-owned VPN.

Shape of Russia filled with Russian flag-colored internet codes on a black hacking background

(Image credit: Getty Images)

Paper VPN is among the services publicly acknowledging connectivity issues, with some users reporting completely broken connections while others simply experience slower speeds.

In a post published on Wednesday (August 5), the company confirms that "the connection has been restored for most users."

Amnezia VPN — which recently strengthened its apps to fight Russia's new approach to VPN blocking — was caught up in the government's wider summer crackdown. The provider previously restored its premium service in Russia following a devastating state-sponsored cyberattack that lasted a month and a half.

Regarding the August 4 wave, however, the provider stated on its channels that its service is "working reliably" in Russia.

"Friends, over the past two days we have seen many reports of massive blockages of other VPNs. Not long ago this happened to us, but the new wave did not affect us," wrote Amnezia VPN, adding that the team is also currently testing a new "Greenland" location for bypassing whitelists.

TechRadar has reached out to the provider for further comment on the current situation. We will update this story as we learn more.

Amnezia VPN now supports human rights defenders with free premium VPN subscriptions

  • Amnezia VPN and Civil Rights Defenders teamed up to protect free speech
  • Journalists, activists can ask for free access to Amnezia Premium VPN
  • NordVPN and Surfshark previously introduced similar initiatives

Amnezia VPN has partnered with independent non-profit organisation Civil Rights Defenders to provide free access to Amnezia Premium for journalists and activists.

It’s not the first time the anti-censorship VPN has helped the category. Indeed, Amenzia VPN previously partnered with NGOs to support more than 300 journalists and activists from countries with heavy censorship — including Venezuela, Turkey, Russia, and Myanmar.

We all love the best VPNs to hide our real location, prevent our internet provider and third-party marketing companies from tracking us, or to protect our data when we connect to public Wi-Fi networks.

However, as regulators and platforms tighten their grip on freedom of digital access and the freedom of online expression itself, professionals writing about censorship or human rights violations and digital rights require reliable digital tools more than ever — particularly when they are located in countries with heavy internet censorship.

"Through this program, we hope to reach even more people," Amnnezia said.

In the meantime, its free service Amnezia Free continues to serve 2.5 million monthly active users for free in heavily censored countries, as the VPN continues to strengthen its commitment to protecting digital freedom by recently unveiling new anti-censorship protocols.

How to apply for the Amnezia VPN and Civil Rights Defenders program

The program is open to independent professionals and media organisations covering topics including freedom of expression and digital security, or that live and work in countries subject to censorship, media restrictions or state surveillance.

It will provide annual subscriptions to Amnezia Premium service — which, during our testing, has delivered impressive unblocking and access to 20 global server locations — with the option to renew the subscription for longer periods. There is currently no deadline for applications, and the program is expected to remain in place for at least one year.

To apply, professionals can complete a form if they have an email address linked to a specific project. Alternatively, they can contact Civil Rights Defenders by sending a description of their work and some references to vpn@civilrightsdefenders.org. Signal contact is also available upon request. You can find all the information in this blog post.

📝 Are you a journalist or activist covering human rights, censorship, or cybersecurity? Amnezia VPN has teamed up with Civil Rights Defenders to offer sponsored Amnezia Premium subscriptions for secure connection & digital protection. Apply now: https://t.co/G8z10U6uEh…July 28, 2026

Mazay Banzaev, founder of Amnezia, emphasised that journalists and human rights defenders' work is vital to society. "Supporting them is part of what we consider our mission," he said.

In this context, the partnership with Civil Rights Defenders is ideal, as the organisation operates in over 50 countries and provides a range of digital support and security services, including legal assistance, temporary relocation and digital protection measures to enable human rights defenders to continue their work.

"Civil Rights Defenders partners with human rights defenders in some of the world's most repressive environments to ensure that those who work for democratic rights and freedom of expression have the right tools to minimize risks imposed by isolationism and censorship," said Sofia Walan, Executive Director of Civil Rights Defenders.

The partnership adds to previous collaborations between other VPN firms and non-profit organisations, reflecting a growing awareness and desire for new initiatives aimed at combating digital threats.

Earlier this year, NordVPN partnered with Internews to boost digital protections for journalists and activists by directly integrating NordVPN’s security tools and 'Changemakers' training sessions into Internews' global digital security programmes.

Surfshark had also previously collaborated with the same organisation to provide fully funded Surfshark One subscriptions to 100 media outlets and civil society organisations operating in nine high-risk countries.

Meet deGDID: Windscribe's answer to the Windows tracker that VPNs cannot mask

  • Windscribe has released deGDID, a free tool that targets a hidden Windows identifier that VPNs cannot mask
  • The identifier surfaced in a US court case where it helped trace a suspect's PC across VPNs and three countries
  • Blocking the identifier can break Microsoft account features like Xbox, Outlook, and the Store

Windscribe has built a new tool that takes aim at a form of Windows tracking that even the best VPN cannot switch off.

The tool, called deGDID, targets a little-known Microsoft identifier called the Global Device Identifier, or GDID. It is a server-assigned code tied to a Windows installation.

The GDID burst into public view in July after it appeared in a US federal complaint against an alleged member of the Scattered Spider hacking group, where Microsoft gave investigators logs that correlated a Windows GDID with IP activity. Investigators traced the machine through VPN obfuscation across multiple countries over roughly eight months.

Windscribe: a feature-packed VPN
Windscribe is fast, capable, and stacked with features. While the provider offers one of the best free VPNs around, Windscribe Premium gives you access to the full server network across 115 locations and extra features, including threat protection and port forwarding. If you find that you're unhappy with the product, you can get your money back within a week of signing up. View Deal

What Microsoft's GDID is, and why a VPN won't help

A Microsoft representative described the GDID in the complaint as a persistent, device-level identifier designed to uniquely identify an installation of Windows on a device.

It survives Windows updates but not a clean reinstall, which generates a fresh one. The privacy risk appears when that stable ID is tied to telemetry, Edge browsing data, Microsoft Store records, and IP addresses, letting Microsoft reconnect the same machine across sessions and services.

A virtual private network (VPN) protects your traffic by masking your IP address and encrypting your data. The GDID sits outside that tunnel, at the layer where Windows talks to Microsoft's cloud, so it ties every session together no matter which IP the traffic came from.

Switching to a local Windows account doesn't fix it either. Windscribe found its test machine still created a GDID even as a local account, and after manually deleting the value from the registry, it reappeared after a reboot.

How Windscribe's deGDID works, and how to use it

Windscribe's deGDID uses hosts file modifications and firewall rules to block the registration paths Windows uses to fetch a GDID, and wipes known local identity artifacts.

To run it, download the degdid.ps1 script from GitHub and run it in PowerShell with administrator rights. Use the -Status flag for a read-only check, or -Protect for the full block, verify, and wipe routine, with an -Unprotect option to reverse the changes.

The tool deliberately refuses to run on managed, domain-joined, or corporate machines.

Windows is spying on you. By design.Microsoft's GDID is a unique, server-assigned identifier for your Windows install. A recent court filing showed Microsoft was able to connect a GDID to IP activity.VPNs don't help. Local accounts don't fix it.So we built deGDID.July 27, 2026

This is not a clean opt-out. In hands-on testing, the script ran without errors, but then broke logins to Xbox, Outlook, and the Microsoft Store because the firewall rules also cut off the connectivity those services depend on.

Windscribe warns it may also affect OneDrive, passkeys, and Windows Hello, cannot guarantee it catches every GDID pathway, and does not erase records Microsoft already holds server-side.

For most people, this is just another reminder of what it means to be a Windows user, but if you want to inspect or reduce the identifier, deGDID is currently one of the only tools that tries. And if you want a more comprehensive solution, Windscribe suggests giving Linux a go.

Millions of downloads, zero security: how clone VPNs are gaming the Google Play Store

When browsing the Google Play Store for a mobile VPN, downloads in the tens of millions is usually the ultimate stamp of approval. If 10 million people use an app, it must be well-maintained, technically secure, and backed by a legitimate business, right?

Unfortunately, our latest audit of Android VPNs shows that high download metrics and large app catalogs don't equal operational support, technical maintenance, or store compliance.

Primarily, our data suggests that Google Play's automated submission checks are allowing multi-million-download apps and commercial app networks to circumvent certain developer website requirements.

Instead of real support portals, these developers are using blank domain placeholders, error pages, and ad monetization text files to game the system.

Broken infrastructure in 10M+ download "Super-Apps"

When you pay for one of the best VPNs, you get a dedicated corporate infrastructure, 24/7 support channels, and transparent legal documentation. But on Google Play, some of the top-ranking apps we audited are operating as ghost towns.

Our audit identified 14 separate Android VPN apps with over 10 million downloads each that maintain non-existent, broken, or dummy website links. For example, both USA VPN - Get USA IP and VPN Indonesia - Indonesian IP direct users to tap2free.net, which is a completely blank page.

Other high-volume apps redirect to active server errors. AnonyTun directs users to an HTTP '403 forbidden' error. The link for v2RayTun simply times out, and examples like Fast VPN lead to "Invalid URL" messages.

Even when the sites load, they are often devoid of information. VPN 365 is one of several examples that display generic single-line welcome banners like "Welcome to facefaster.com!" with no other content. MTM Tunnel Lite links to an empty free Blogspot page containing a single post stating "there’s nothing here."

Most embarrassing of all is Armada VPN, which points to a blank white page that actually misspells the app’s own product name as "Aramda VPN".

Other major listings were also found to omit a website URL entirely on their official store pages.

More risk of hijacking

These missing and broken links indicate abandoned or completely unmaintained web assets, heightening the risk of quiet service degradation or future domain hijacking.

More importantly, it leaves millions of active users with no obvious or easy channels to seek technical support, report severe security vulnerabilities, or legally request account and data deletion.

It also prevents users from verifying company registration details or reading binding terms of service outside the application client.

The problem of multi-app developer rings

The broken links on individual apps are bad enough, but the audit also exposed massive "developer rings", single entities spinning up dozens of clone apps to flood the search results and trick Google's automated systems.

One of the most common ways these developer networks game the rules is through the "app-ads.txt" exploit.

App-ads.txt is a standard format websites use to manage their Google ads, and many sites host these files for free. Developers need only paste these raw monetization file links into their app store submission forms to satisfy Google's website requirement without having to build a real site.

This exploit is happening on an industrial scale. The developer account Karastm operates 39 VPN apps, and 35 of them link back to Google Play via a generic app-ads text file.

Another developer, helalik, operates 19 VPN apps, including seven with over 1 million downloads, that all point to a single adzonemax.site file. Similar ad-file exploits were found across several other networks of similar size.

When developer rings aren't using ad files, they use dummy blogs. The developer BanglaTach operates 26 VPN apps (including two with over 1 million downloads) that all point to naruto24.com, a generic, dummy WordPress template that contains no information about VPN services.

Networks like BD IT POINT (8 apps) point their store listings to empty blog feeds, removed accounts, or placeholder domains.

So what?

These multi-app networks create a dangerous illusion of software variety. They trick users into believing they are choosing between distinct, competing privacy providers, when they are actually downloading reskinned clone apps.

These white-label fleets share identical infrastructure, identical bugs, and identical data logging practices, all while successfully evading Google's operational transparency and support obligations.

Consumer advice & actionable insights

Because of the ways Google Play permits apps into its store, and the weaknesses in this, users must become their own security auditors to navigate the storefront safely.

Start by completely disregarding download metrics. You should treat high download totals merely as indicators of past distribution popularity, rather than proof of current security, technical maintenance, or legitimacy.

Before downloading, always click the developer's name on the app store listing to audit their portfolio. If you see them operating dozens of identical clone apps sharing generic names, avoid their software entirely.

Finally, pay close attention to the provided URLs. Do not download an app if its official store website link ends in an "/app-ads.txt" extension or points to a free blogging domain like Blogspot. Ultimately, legitimate privacy companies invest in and own their own web domains.

The bottom line

Our data shows that, currently, Google Play's app verification methods offer enough maneuverability for apps to use dead links, blank pages, and ad monetization files to register their apps in place of truly helpful information hubs for users.

Until automated store submission checks are replaced with genuine corporate verification, consumers should evaluate independent security audits and clear corporate domain ownership rather than assuming app store popularity reflects developer reliability.

When contacted about our findings, Google responded, saying: "We are looking into this. When made aware of an app that violates our policies, we will review the apps in question and take appropriate action."

We also contacted all the VPNs mentioned in this article for comment on the issues found. As of publishing, none have responded thus far though we will update with any responses as they arrive.

Apple and Google are hosting hundreds of dangerous VPN links — here is why your device is at risk

When you download an app from the Apple App Store or Google Play Store, you assume the environment is heavily moderated and entirely safe. Unfortunately, we recently completed an audit of mobile VPNs that reveals significant privacy and security risks.

Our evaluation identified apps on both app stores that put visitors at risk of unencrypted traffic, hidden redirects, and active scareware.

The best VPNs will invest heavily in bug bounties and secure, authenticated web infrastructure. But there are a significant number of mobile VPN apps that leave you exposed to phishing and malware before you even install the app.

Insecure protocols and obscured links

The biggest concern we found surrounds encryption enforcement. We found that 339 Android links (5.3%) and 188 iOS links (6.8%) use plain, unencrypted HTTP instead of secure HTTPS. This includes massively popular apps like Oryx VPN (which boasts over 1 million downloads) and Stealth Shield VPN.

So what?

Clicking a plain HTTP link allows network eavesdroppers or man-in-the-middle (MitM) attackers to intercept, manipulate, or inject malicious content into the traffic between you and the developer's site.

But the security holes don't stop at missing encryption. The audit uncovered several other severely obscured URL formats being approved, such as:

  • URL Shorteners: Multiple store listings rely on shorteners like shorturl.at and the Yandex-based clck.ru. This deliberately conceals the final destination domain, making it impossible for users or automated URL security scanners to evaluate link safety prior to clicking.
  • Raw IP Addresses: Some listings use raw numerical IP addresses instead of domain names. This bypasses domain-based web filtering, SSL certificate validation, and public DNS reputation systems, effectively making connection security impossible to verify.
  • Direct PDF Links: We found privacy policies pointing directly to downloadable PDF files (13 on iOS, 1 on Android). PDF documents can execute embedded JavaScript, trigger automated local file downloads, or easily exploit PDF reader vulnerabilities on your device.

Active threats: scareware and malicious redirects

The most alarming discovery is that clicking a link on an official Apple or Google store page can lead to active cyber threats.

When developers abandon their apps, their official web domains often expire. It seems that actors are actively purchasing these expired domains specifically to exploit the existing app store traffic. In fact, our audit verified multiple active store listings containing domains that now host fake antivirus popups and ad redirects.

Users who trust these official app store links are tricked into viewing fake security warnings. These scareware popups are explicitly designed to coerce panicked users into downloading genuine malware to "fix" a fabricated virus.

In other instances, store links point to totally irrelevant and unvetted environments. Official links were found pointing to deleted Twitter handles, empty Facebook and Instagram pages, payment portals like Cashpay Iraq, and even Chinese opera sites.

Directing users to external messaging platforms like Telegram or abandoned social accounts bypasses web security standards entirely, exposing users to unmoderated third-party chat environments and severe impersonation risks.

How to protect yourself

Its important that, regardless of inbuilt measures, consumers take matters into their own hands to some extent to navigate these listings safely. Always inspect link targets closely before blindly tapping on a developer website.

You should verify that the destination uses a secure HTTPS connection, and remain on high alert for obscured formats like raw numerical IP addresses or randomized link shorteners that conceal the true domain.

Furthermore, you should actively decline unexpected PDF downloads. Avoid opening direct PDF links from store pages, as these files may contain embedded JavaScript or exploit reader vulnerabilities. If tapping a privacy policy suddenly prompts an automatic file execution or download, block it immediately.

Finally, if an official app store link leads to a virus warning or requests system scanning permissions, recognize that it is a fabricated scareware scam designed to coerce you into downloading malware. Do not click anything on the page; close your browser tabs immediately to protect your device.

The bottom line

Gaps in outbound link verification across the App Store and Google Play Store mean active security threats and unencrypted traffic can still slip onto mobile VPN product pages.

When we approached Apple and Google on our findings, Apple declined to comment on the record. Instead, we were pointed towards its safety guidelines and app review processes. A Google Spokesperson did comment, saying, "We are looking into this. When made aware of an app that violates our policies, we will review the apps in question and take appropriate action."

We also reached out to both Oryx VPN and Stealth Shield VPN, neither of which has returned to us with a response at the time of publication.

Ultimately, the lesson is that you must apply the same strict web security precautions inside official app stores as you would when navigating the open web.

First your age, next your identity: Inside the 'hack' that broke the EU age verification app's privacy promises

When Paul Moore heard the European Commission President saying that the EU age verification app will “give children a safer start online,” he was unconvinced.

"Bypassing the latest EU age verification app (2026.07-1) with a Chrome extension," he later posted on X. And it wasn’t the first time.

With over 20 years of experience under his belt, Moore managed to bypass the app back in April, right after the Commission first launched it. Combined, his experiences have led him to a straightforward conclusion: "anonymous age verification doesn't work."

While the process he used to bypass the verification system doesn’t undermine people’s privacy, Moore believes the long-term impact of its ineffectiveness will.

"All it is an escalation path being drip-fed, bit by bit under the guise of child safety," Moore told TechRadar. It won’t just be about proving your age. "The next step will be proving who you are," he said.

The EU’s 'privacy-preserving' approach

EU

(Image credit: Pixabay)

Most of the current age verification methods, which require scanning national ID documents or biometrics, put people's sensitive data at risk. (Think, for example, of the data breach that affected Discord’s age verification provider and exposed 70,000 people's government IDs and personal data last year.)

For that reason, there's a growing sense of urgency to find a solution that helps people prove their age without collecting sensitive information. And the European Commission argues that it has found it.

Drawing on the framework of the COVID-19 certificate app, the Commission came up with a template for a privacy-first, open-source tool that EU member states can use to build their own national apps.

The process — which is part of the bigger European Digital Identity Wallet (EUDI) project — leverages zero-knowledge proofs (ZKPs) and verifiable credentials (VCs) to verify someone's age without sharing sensitive information.

In other words, your phone scans your ID and stores that data locally. Websites will then ask users to scan a QR code via the app to prove they are old enough to access certain content.

A European Commission spokesperson told TechRadar that online services won't receive any personal information about the users, saying: "The age proof simply confirms whether the user meets the age requirement."

Moore doesn’t dispute the privacy credentials of the process. Perhaps worse, he just doesn’t think it will work.

Why the EU age verification doesn't work

While the EU age verification blueprint sounds like a welcome improvement compared to the current approach, the advantages don't hold up.

That's because Moore says age checks have to be tied to a person’s identity to be trustworthy. "The second you strip the identity away from how old somebody is, a person can't answer that question," he said.

Since the April launch, the tool's security credentials have even been improved, but Moore says the issue isn’t a bug but the entire process, criticising the latest efforts as mere "security theater."

How Moore bypassed the app

Bypassing the app wasn't difficult. In fact, Moore says he built two Chrome extensions on Claude in minutes.

The first extension he built replicated the Android app, but with the ID checks removed. This meant he could skip the need for a user to scan a document entirely.

"It detects the QR code automatically (when presented by a website) and passes verification," Moore explains, adding that the process is entirely automated with no need to interact with the Chrome extension once installed."

This week, Moore went further and built a Chrome extension that can capture the QR code from a website and automatically forward it to a remote, automated phone to get a genuine signature in seconds.

#EU #AgeVerification unfixable bypass:✅ Automate the device✅ Detect and relay the QR code⏱️ Push to GitHubOnce an age verification QR code appears, it will detect & automatically relay to a legitimate device that completes the verification remotely.If a "technically… https://t.co/O0Z0BpCOs8July 31, 2026

Known as an 'automated relay bypass,' these attacks mean nothing in the process is faked, making prevention almost impossible.

"Even after they enable all other protection mechanisms, both will continue to work," Moore said.

The EU’s response

When asked whether any steps were taken to prevent circumvention, a European Commission spokesperson said: "We of course rely also on parents and caretakers to check what children are doing online," adding that the app's goal is "avoiding the unintended exposure of kids to inappropriate content."

Yet, according to Moore, lawmakers' focus is misdirected. He said: "What [lawmakers] are missing is that the threat actor isn't a third party; the threat actor is the user.

"They don't want age verification in the first place, so they are going to look for ways to bypass the system. And if the system can be bypassed by design, they will do it."

Deciding not to impose a new law or technology simply because it could be bypassed is unlikely to convince lawmakers. But the problem may extend beyond an ineffective system.

In fact, Moore fears that the app's inevitable ineffectiveness could push lawmakers to turn to more invasive checks and an erosion of people's privacy.

Next step? Our identity

Portrait of woman with shadow of barcode on her face

(Image credit: Francesco Carta fotografo/via Getty Images)

When Moore says the concept is broken, he is calling out what he sees as a fundamental flaw in the EU age verification framework's design: client-side trust.

The app is more privacy-preserving than passports and face scans because the data won’t leave the user’s device. But this may be exactly why its implementation is bound to fail. If nothing leaves the device, Moore explains, there is no way to trust or verify what has been obtained.

This creates a problematic catch-22 for European lawmakers. When this ‘anonymous’ app fails to keep kids off restricted sites, Moore contends that Brussels is unlikely to simply give up on its flagship safety initiative and drop privacy-preserving practices altogether.

"For them to push ahead with it under the guise of child safety is an escalation path to say we've tried this; the natural route is now you've got to prove your identity," Moore told TechRadar.

It’s clear that age verification is here to stay, despite continuous outcry coming from privacy advocates, technologists, and data scientists who warn it may do more harm than good.

For Moore, the danger is that what’s marketed as a privacy-first breakthrough today may ultimately be used to undermine privacy tomorrow.

‘I just got hacked’ — What Play Store reviews reveal about people's VPN expectations

A VPN isn't a silver bullet. It can’t guarantee total security or anonymity online. Instead, it is a tool that allows you to hide your browsing data from your internet service provider (ISP), adopt a virtual IP address, and access geo-restricted content.

However, there are still a lot of misconceptions about what a VPN can and cannot do — a problem made worse by the exaggerated marketing claims pushed by some VPN companies.

Given that, it’s unsurprising that when we analyzed nearly 30,000 Google Play Store reviews of our four top-rated VPNs, a clear trend emerged: a lot of people aren’t getting the privacy and security protection they thought they were paying for.

In part, this stems from users misunderstanding what a VPN does. But it also shows that the industry needs to do a better job of setting realistic expectations.

On the whole, people are satisfied with their VPNs. Across our full dataset, just 35% of overall comments were negative. However, when we isolated feedback related to privacy and security, the proportion of negative comments rose to 41%.

This article is the second in a series investigating the real-world experience of using major VPN services, driven by our exclusive analysis of Android VPN reviews. The first article examined billing and pricing issues.

Lab-tested security vs Play Store reality

Proton VPN received the highest proportion of positive comments regarding privacy and security, with 68% of its feedback on the topic being positive.

That's significantly higher than Surfshark, which recorded a positive sentiment rate of just 31%. ExpressVPN (54%) and NordVPN (34%) sat in between.

It's worth noting, however, that all four services offer essentially equivalent protection and are among the most secure VPNs available. They all feature advanced encryption and proprietary protocols, and have been audited by third parties to confirm their security credentials.

So what’s causing the disconnect between our lab tests and real-world user experience? It seems that for many, it stems from several myths about what a VPN can actually protect you from.

Myth #1: A VPN stops every 'hacker'

When analyzing the Play Store reviews, we noticed that a significant number of people were concerned about the threat of hackers. And for obvious reasons — people lose money, privacy, and their health to malicious actors online every day.

Unfortunately, a VPN can't help in every scenario, and that seems to have left many disappointed.

One Proton VPN reviewer, for example, alleges it is the “worst app ever” because they had “been hacked by someone else while using this VPN.” Meanwhile, a NordVPN comment says that “hackers” had “managed to set up a way of getting passed [sic] the VPN on all my devices.” Another simply says: “got hacked the second day, don’t trust.”

However, others proudly claim that their VPN “protects my identity from hackers.”

Like most things, the reality is somewhere in the middle. While a VPN protects your data in transit (encrypting the data between your device and the server you’re connecting to), it does nothing to protect data you’ve already handed over to a third party — like an email address or password stored on an external database.

A standard VPN also won't stop you from falling victim to phishing scams, where an attacker tricks you into voluntarily entering your credentials on a fake website. However, VPN companies are increasingly releasing products to help prevent this.

If you're looking for more details on what a VPN can and can't do, check out the cheat sheet at the end of this article.

Myth #2: A VPN offers bulletproof protection

In our tests, these VPNs have never leaked an IP address. That would be a big deal. Yet across Play Store reviews, a surprising number of people report that their VPN appeared to fail.

One NordVPN reviewer said the app “did not hide my IP address from being tracked,” while a comment about Surfshark claimed it “failed to hide my IP address at least twice in the first 3 weeks.” Another noted that their VPN “leaks IP after some time [...] giving you a wrong sense of privacy and security.”

It’s impossible to diagnose the specific issues at play without more context. However, true encryption failures are extremely rare, particularly among well-regarded providers.

In reality, most reported leaks stem from configuration errors (like not having the kill switch enabled), browser tracking or basic steup errors. To make sure your connection isn't dropping data, always enable your app's kill switch and verify your real IP address is hidden using a diagnostic tool like Cloudflare's trace page.

If you’ve checked your settings and still suspect your VPN is genuinely leaking your IP address, leave a comment below and our team will see if we can help troubleshoot it.

Myth #3: A VPN equals total anonymity

Exaggerated marketing claims around online privacy seem to have influenced reviewers throughout the data. Some accuse providers of betraying them, writing reviews like "do not trust this app for privacy," while others complain about the amount of telemetry data collected by the apps themselves.

However, these reviews highlight an uncomfortable truth: masking your IP address only goes so far. Cookies, browser fingerprints, device information, language settings, and SIM card regions are all routinely logged, analyzed, and leveraged by advertisers and platforms to track your identity regardless of your IP.

A VPN is an important first step in improving your privacy, but if you continue to use services that monitor your every move, it’s not enough on its own. Check your browser, the services you use and you might find that there are other factors at play revealing your identity.

‘Not a catch-all’ — VPN providers' defense

We reached out to each of the VPN companies mentioned in this report for comment.

Proton VPN, NordVPN, and Surfshark all acknowledged that a VPN is not a catch-all solution for every digital threat. Instead, they highlighted additional security features they offer and noted that many reported issues stem from configuration errors and non-IP tracking rather than a failure of the VPN.

ExpressVPN did not respond to our request for comment.

Proton VPN highlighted its NetShield feature, which blocks ads, trackers, and malware domains. Addressing leak complaints, the company explained that genuine tunnel traffic does not leak, and that reported issues typically occur when split tunneling, connection dropouts, or browser extensions leave specific traffic outside the encrypted connection.

Surfshark pointed to its Web Content Blocker — which it says blocked nearly 1.2 million phishing and malware sites in the past month — and its Alternative ID tool, which generates email aliases to protect contact details.

Meanwhile, NordVPN, which said that it "does not advertise complete immunity," highlighted its next-gen antivirus and credential leak monitoring tools. It added that perceived IP leaks are frequently down to device configuration rather than an IP exposure.

Combined, it's clear that leading VPN companies are developing more comprehensive and effective cybersecurity products to accompany the core VPN technology. However, if the limitations — as well as the benefits — of these additional tools aren't communicated clearly, the industry risks creating the same expectation gap it appears to face with its core technology.

What a VPN can and can't do — A cheat sheet

A VPN can:

  • Encrypt your browsing traffic: Shield your internet activity from your Internet Service Provider (ISP), network manager, or public Wi-Fi admin.
  • Spoof your location: Replace your real IP address with one in another location, making it harder for sites to track your physical whereabouts and help you access geo-restricted content.
  • Bypass local network blocks: Circumvent restrictions imposed by Wi-Fi administrators, government censors, and geo-fenced content.
  • Prevent bandwidth throttling: Stop ISPs from slowing down your speeds when they detect specific activities like streaming or torrenting.
  • Secure DNS requests: Direct web address lookups through private, encrypted DNS servers to prevent ISP-level logging and DNS leaks.
  • Protect your IP address against DDoS attacks and IP tracking by hiding your actual home IP address during gaming or P2P connections.

A VPN can't:

  • Protect the data you share: It can't stop companies from collecting data you submit directly or protect that data if those companies suffer a breach.
  • Prevent phishing: It can't stop you from falling for phishing, text, or phone scams, although many providers now offer tools that help on top of the VPN.
  • Make you completely anonymous: Web cookies, browser fingerprinting, and account logins can still track your identity online regardless of your IP address.
  • Block hardware-delivered malware: It offers no protection against threats introduced directly to your device via physical hardware (like infected USB drives).
  • Protect against digital forensics: It cannot shield files or logs stored directly on your physical device if it is accessed with forensic tools.
  • Remove existing infections: It cannot retroactively clean malware or spyware already installed on your system.
  • Stop OS-level zero-day attacks: It can't stop sophisticated, nation-state spyware that exploits underlying vulnerabilities in your device's operating system.

Methodology

We collected almost 30,000 user reviews published on Google Play Store since the beginning of the year for the four VPN providers featured in this report using the google_play_scraper library.

As individual reviews often address multiple topics (e.g. streaming and security), we broke reviews down into sentence-level units. This expanded our analysis to over 47,000 entries, with individual entries permitted to sit across multiple categories when suitable.

Each sentence was assigned to specific categories using regex keyword filtering, and analyzed for sentiment using a pre-trained BERT model that took into account the user’s star rating.

While all machine learning sentiment pipelines carry a minor margin of error, every VPN provider was subjected to the exact same pipeline to ensure consistency and fair comparison. Human review was also conducted throughout.

Data processing scripts were developed in Python with AI assistance, and all final outputs were manually reviewed.

Thousands of iOS and Android VPNs are hiding behind fake websites and useless privacy policies — here's how to spot them

If you think downloading a VPN directly from an official app store guarantees your digital privacy, it’s time to think again.

We recently undertook a huge audit of storefront verification standards, which has exposed a severe lack of quality control across both the iOS App Store and Google Play.

We evaluated developer transparency and store verification standards, analyzing 3,392 Android VPN apps (with more than 1,000 downloads) and 1,387 iOS VPN apps (with at least one review).

It appears that Google Play looks significantly worse than Apple's App Store across almost every transparency and validity metric. In fact, a mere 61.4% (851) of iOS apps passed all main validity checks, while Android trailed far behind with just 40.8% (1,210) passing the same tests.

Just because a VPN is available on an official App Store doesn’t mean it’s legitimate. Here is what the data tells us about the safety of mobile VPNs.

Storefront Enforcement & Quality Control Data

Google Play Store

(Image credit: Google)

When you hand over your web traffic to a VPN, you expect the developer to be a real, registered business. However, storefront enforcement data proves that thousands of these apps lack even the most basic corporate infrastructure.

When it comes to maintaining a valid developer website, Apple leads the pack. Our data shows that 82.7% (1,147) of iOS apps maintain a valid developer website. In contrast, only 52.2% (1,774) of total Android apps manage to do the same (which equals 59.8% of the Android apps that actually bothered to list a URL).

But the problem goes deeper than broken links. 46.9% of valid Android websites (832) and 47.5% of total Android privacy policies (1,612) rely entirely on free third-party domains like Google Sites, GitHub, and Blogger.

In total, more than 1,200 Android developer website or privacy policy links pointed directly to free Google pages. Apple performs better here, but isn't immune; 15.6% of iOS websites (179) and 18.3% of iOS privacy policies (217) still rely on these free hosts.

So What?

Relying on free platforms like Blogger or Google Sites signals a complete lack of dedicated corporate infrastructure and financial investment. If a developer isn't willing to spend a few dollars on a custom domain, how can you trust them to invest in secure AES-256 encryption or server maintenance?

Worse, if that free third-party account is suspended or abandoned by the host, developer support and privacy documentation vanish instantly.

The platform differences are equally stark when it comes to developer contact requirements. Google Play mandates that developers display an email address, but 65.1% of Android apps (2,208) use free, public domain services like @gmail.com or @yahoo.com.

Meanwhile, iOS does not require developers to display an email address at all, and it is present on only 16.2% of iOS VPNs (225 apps).

Allowing developers to omit contact emails lets operators remain entirely anonymous. This prevents users from exercising fundamental privacy rights, such as GDPR data access or deletion requests.

It strongly indicates that the "company" is an individual or transient entity rather than a registered business, making legal accountability and data privacy enforcement virtually impossible.

Privacy Policy Misrepresentation & Boilerplate Networks

Privacy policy on a smartphone

(Image credit: Shutterstock)

A VPN is only as trustworthy as its privacy policy. Premium providers like ExpressVPN and NordVPN undergo regular independent audits to verify their no-logs claims. By contrast, our audit revealed that hundreds of mobile VPNs use completely meaningless, generic, or copied text to masquerade as legitimate services.

In one example, we found 13 iOS apps sharing identical boilerplate text containing unedited template placeholders. Because the developers didn't even bother to read their own legal documents, the text still reads: "If you have questions about this Privacy Policy, contact us at support@example.com." You can view one of these identical unedited policies here.

These unedited templates contain zero binding commitments regarding VPN-specific practices, such as traffic logging, IP tracking, or bandwidth monitoring. Users are misled into assuming they are protected when, in reality, no legal policy actually exists.

Furthermore, a massive portion of these apps rely on automated "policy generator farms", sites that bulk-host generic privacy documents. The audit discovered:

  • 48 Android apps hosting policies on projeto10.top
  • 40 apps using freeprivacypolicy.com
  • 19 apps using termsfeed.com

Automated policy generators often attach legal disclaimers stating they do not guarantee accuracy. Furthermore, the host platform can alter or remove the page without the developer's knowledge, leaving users without valid privacy terms.

Perhaps the most absurd discovery belongs to Sigma VPN, an Android app with over 100,000 downloads. Its listed privacy policy isn't a policy at all. Instead, it links directly to a copied Wix support article on how to create a privacy policy.

Even when policies are unique, they are often too short to mean anything. The audit found that 2.3% of valid Android policies (72) and 6.6% of valid iOS policies (78) contain 250 words or fewer. Highly truncated policies like these lack necessary legal disclosures regarding logging, third-party data sharing, jurisdiction, and data retention windows.

Consumer Advice & Actionable Insights

So, how do you navigate app stores safely without downloading a dud, or worse, a data-harvesting nightmare? Here is our actionable checklist to protect yourself before hitting 'Download'.

  • Domain Verification: Always check that the provider operates an independent, custom web domain matching the product name, rather than a free sub-domain on Blogger or Google Sites. If they don't own their own website, they shouldn't own your web traffic.
  • Policy Audit Checklist: Don't just trust the word "Privacy Policy." Open the link and search the text for generic email placeholders (like support@example.com), generator footers, or broad non-VPN terms. Confirm that the policy explicitly commits to no connection or activity logging.
  • Contact Testing: Test the developer's contact channels before subscribing. Send a quick email to verify that support responsiveness and account deletion mechanisms actually exist.

The Bottom Line

Google Play's link verification method lets hundreds of apps operate using temporary blogs, blank pages, and automated generator sites. While Apple does a better job of enforcing valid web links, its main flaw is that it permits total anonymity for developers, leaving users with no way to hold iOS developers accountable legally.

In response to our investigation, Apple declined to comment on the record, pointing instead to its safety guidelines and app review processes. Meanwhile, a Google spokesperson said: “We are looking into this. When made aware of an app that violates our policies, we will review the apps in question and take appropriate action."

The final takeaway is a crucial lesson in modern cybersecurity: store listing approval reflects compliance with basic submission forms, not operational legitimacy or privacy protection. Always do your own research before trusting a mobile VPN with your personal data.

'They will renew your subscription even if you turn off the auto-renewal' — Which VPN has the most price complaints on the Play Store?

The VPN industry has a problem. For a significant number of people, their VPN subscription has quietly auto-renewed, jumped in price, or cost more than they initially bargained for.

The issue is so bad that multiple VPN providers — including ExpressVPN, NordVPN and Surfshark — have faced legal scrutiny over their auto-renewal practices.

This creates a dilemma for us at TechRadar when it comes to recommending VPNs. We are confident these are the best VPNs available — they are the fastest, most secure, and best at streaming — but it's clear that more needs to be done to ensure fair and transparent billing.

To get a better understanding of people's real-world experience using our top-rated VPNs, we analyzed almost 30,000 Android VPN reviews across the 'Big 4' — NordVPN, ExpressVPN, Surfshark & Proton VPN — published on the Play Store since the beginning of the year.

The results are stark. Across the entire Play Store dataset, people are mostly happy with the apps — just 35% of overall written comments are negative. But when we looked at billing and pricing specifically, that figure rose to almost 60%.

Read on to find out which provider performed the best, which you might want to be wary of, and the key practical steps to avoid common VPN issues.

This article is the first in a series investigating real-world customer experience of using major VPN services, inspired by our exclusive analysis of user-generated Android VPN reviews.

Which VPN has the most positive reviews?

The vast majority of written Android reviews offer little insight into how people really feel. There are thousands of generic entries like "top app," "good," "ok," or "bad."

However, once we filtered out the noise, billing and pricing issues emerged as a significant area of frustration, accounting for almost 30% of all categorized feedback.

Because total review counts varied widely between brands, we compared percentages rather than raw numbers. Attitudes were scored using a machine-learning model supported by manual human checks.

Read more about our methodology here.

When it comes to billing and price satisfaction, Proton VPN is the clear winner. Just 35% of billing-related comments were negative. However, that’s in large part because of the free tier it offers.

In fact, if you remove references to the product being 'free,' the rate of negative comments rises to 57%. While that points to significant underlying friction for paid accounts, it’s still better than the rest.

By contrast, the remaining market leaders face significant dissatisfaction:

  • NordVPN: 83% negative billing sentiment
  • ExpressVPN: 79% negative billing sentiment
  • Surfshark: 71% negative billing sentiment

It wasn’t all bad news, though. There was some positive feedback, with one user praising Surfshark for its "outstanding value for money" and another calling NordVPN the "best affordable" VPN. But for the majority of reviewers, issues around free trials, auto-renewals and price hikes dominated.

Of course, all written reviews skew towards negative emotions as consumers seek to fix or change something. However, taken together they demonstrate a comprehensive picture with clear issues at play.

Free trials, auto-renewals, and price hikes

Across all of the reviews analyzed, three distinct issues appeared.

Firstly, it’s clear many people are experiencing issues with free trials. Specifically, people are signing up only to find themselves charged automatically.

As one Surfshark user wrote: “Wanted to try using the free trial, [it] didn’t work and still charged me for a month.” Meanwhile, a NordVPN user reported not being able to “cancel my free trial just days in.”

Another source of friction occurs when automatic renewals are triggered. And it impacts all of the providers mentioned. As one Proton VPN reviewer wrote: "A lot of users would appreciate more transparency before renewals happen.”

Closely related to the automated renewals are the price hikes that are associated with them. Even if you sign up for a certain price for a year, VPN providers often use more expensive rates at the point of renewing a user’s subscription.

One ExpressVPN user wrote: "Of course every time they renewed my subscription they used old prices and never told me about it.” Meanwhile, a Surfshark reviewer put it even more succinctly for others: “Beware of subscription auto renewal.”

VPN auto-renewal costs

Comparing the prices of 1-year VPN plans across the 'big four' initially and after renewal

NordVPN
Initial cost
53.88
Renewal cost
139.08
Surfshark
Initial cost
50.85
Renewal cost
79
ExpressVPN
Initial cost
74.85
Renewal cost
99.95
Proton VPN
Initial cost
47.88
Renewal cost
83.88
037.575112.5150
USD
Group 1 Data
ProductInitial cost (USD)Renewal cost (USD)
NordVPN53.88139.08
Surfshark50.8579
ExpressVPN74.8599.95
Proton VPN47.8883.88
TechRadar Logo

How to avoid VPN auto-renewal traps and surprise charges

It's clear that major VPN providers need to do more to ensure fair and transparent pricing and billing. Thankfully, there are also a number of steps you can take to make sure you're not unnecessarily impacted.

To avoid the billing and pricing issues referenced here:

  • Turn off auto-renewal immediately after signing up: Navigate straight to your account dashboard after subscribing and turn off auto-renew.
  • Prepare for the ‘early billing’ window: Many VPN providers trigger automatic renewal charges 7 to 14 days before your subscription technically expires. Set calendar reminders two weeks before your renewal date so you aren't caught off guard.
  • Keep an eye on your inbox: VPN providers will contact you to warn you about the auto-renewal and are likely to send you an email about extending your discounted rate around 60 days ahead of your contract expiring.
  • Always request an official cancellation first: Submit an explicit cancellation request through the provider's official account portal or support chat.
  • Check refund terms: Many ‘free trials’ require upfront payment details and automatically convert into full recurring plans. Read the fine print before providing billing information, and remember that 30-day money-back guarantees often only apply to first-time purchases and are void during certain promotional offers.

What did the VPN companies say?

We contacted each VPN provider for comment on our findings.

Representatives from NordVPN, Surfshark and ExpressVPN highlighted their strong overall Google Play ratings and stressed that user feedback informs ongoing app development.

ExpressVPN added that subscriptions bought via Google Play are subject to Google’s payment and refund policies, but noted its focus is on making the experience "easier to understand, manage, and resolve when customers need help."

A NordVPN spokesperson argued that its premium pricing reflects ongoing infrastructure investment, but pointed out that because the app is free to download, "some users expect the service itself to be free as well," which can drive down review scores when users discover it is a paid product.

A Surfshark spokesperson acknowledged that "public reviews naturally tend to overrepresent moments of friction" but said its current approach is "resonating positively with users" overall.

Meanwhile, Proton VPN emphasized that its paid subscriptions fund an unlimited, ad-free tier for all users, adding that it "clearly states its pricing structure, upfront costs, and terms of renewal" without using tiered feature paywalls or surprise price increases.

Methodology

We collected almost 30,000 user reviews published on Google Play Store since the beginning of the year for the four VPN providers featured in this report using the google_play_scraper library.

As individual reviews often address multiple topics (e.g. streaming and security), we broke reviews down into sentence-level units. This expanded our analysis to over 47,000 entries, with reviews permitted to sit across multiple categories when required.

Each sentence was assigned to specific categories using regex keyword filtering, and analyzed for sentiment using a pre-trained BERT model that took into account the user’s star rating.

While all machine learning sentiment pipelines carry a margin of error, every VPN provider was subjected to the exact same pipeline to ensure consistency and fair comparison. Human review was also conducted throughout.

Data processing scripts were developed in Python with assistance from an LLM, and all outputs were manually reviewed.

Iran-linked group caught hiding surveillance tools in fake apps

  • Recorded Future found an Iran-linked group spreading spyware
  • The malware is delivered through fake VPN and media player apps
  • Researchers assess that most targets are Iranian users

A new report from Recorded Future's Insikt Group describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.

Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, the report says.

It's a blunt reminder that choosing one of the best VPN services is a lot more secure than downloading free, unvetted tools.

Fake apps, real surveillance

Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store.

Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.

According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else.

A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99rJuly 2, 2026

Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.

It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.

MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group Kaspersky documented conducting years of covert surveillance against activists inside Iran.

Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.

Why a fake VPN makes such an effective lure

Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the country's prolonged internet shutdown, which ended with partial restoration of access on 26 May 2026.

The people most desperate for a virtual private network (VPN) in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach.

Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered previous Iran-linked fake VPN campaigns, and this one seems to follow the same pattern with better infrastructure.

How to stay safe

Most readers will never be targeted by a state actor, but the underlying lesson travels.

Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing.

Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks.

Star ratings are a weak signal, since fake reviews are cheap.

'No changes to our logging or privacy policies' — Windscribe reassures users on Canada's Bill C-22 fallout

  • Windscribe said Bill C-22 won't change its privacy policies
  • The bill would require service providers to retain user metadata
  • Canada's Senate is set to discuss Bill C-22 in September

A Reddit user recently put a blunt question to Windscribe: is paying for a Canada-based VPN a privacy problem, given the surveillance bill working its way through Parliament?

The company's official support account answered without hedging. Windscribe will keep operating exactly as it has, the account said, with "no changes to our logging or privacy policies".

Canada is bringing in laws that genuinely complicate things for the company, Windscribe added, but that is internal work to sort out rather than something subscribers should expect to feel.

It's a calmer message than the one Windscribe was broadcasting in May, when it said it would sooner relocate its headquarters than start logging users. That put it alongside Signal and NordVPN, and made it one of the sharpest voices among the best VPN providers fighting the bill.

Bill C-22, formally the Lawful Access Act, cleared the House of Commons on June 18 and now sits with the Senate, which won't begin its study until Parliament returns in September.

Windscribe and Bill C-22: what the VPN provider said

Is paying for Windscribe a problem to privacy given they’re based in Canada and the likely upcoming Bill C-22? Would love to subscribe if not for this. from r/Windscribe

Pressed further in the thread, Windscribe drew a line between where the company is registered and where its infrastructure lives.

The incoming laws could see it served with a court order requiring it to start logging users, the support account acknowledged. Its answer is jurisdictional: a virtual private network (VPN) operating outside Canada doesn't have to comply with Canadian law.

That echoes the route the company has been signalling since May, when CEO Yegor Sak told the Globe and Mail he was actively exploring moving Windscribe out of the country.

Windscribe was also careful to separate provider obligations from user liability. No law currently stops Canadians from using a VPN, it pointed out, and the risk it describes only reaches customers if a provider stays put and starts logging traffic.

For anyone uneasy about the paper trail, Windscribe's suggestion was simple: pay in crypto, so neither the government nor a card issuer sees the purchase.

What's next for Canada Bill C-22

Introduced in March by Public Safety Minister Gary Anandasangaree, Canada Bill C-22 would let the government compel electronic service providers to retain user metadata and build technical capabilities for law enforcement access.

The House passed it at third reading on June 18 after the government moved to limit debate, and the Senate is set to pick it up on September 21, according to Parliament's own LEGISinfo tracker.

Late amendments cut the maximum metadata retention period from twelve months to six and added a clause stating the act can't be read as compelling decryption, unless the provider already holds the keys.

Still, law professor Robert Diab argues that doesn't go far enough, since ministerial orders could still sweep up the metadata of people under no suspicion whatsoever.

The government has consistently rejected the surveillance framing, insisting the bill builds no backdoors and that authorities still need judicial authorisation to obtain data.

A new dawn for digital rights? What Burnham’s 'do better' promise could mean for your privacy

A circuit breaker, bring back hope, do better – that’s what Andy Burnham promised Britain on Monday when he was sworn in as the new UK Prime Minister. And the digital rights community was watching closely as the seventh to stand in front of Downing Street in 10 years made his big, first-day promises. What will Burnham have planned for his predecessor’s divisive digital privacy policing?

It turned out that the tech world didn't have to wait long for the answer. In fact, on the previous Saturday, Burnham had already made almost three million Britons happy with the news that he would scrap the controversial national digital ID plan.

The new PM then sent shockwaves across the political benches on his first day in charge, when he dismantled the Department for Science, Innovation and Technology (DSIT) after only three years of service and merged it with the Business Department.

The question now is whether Burnham’s impetus for change will address the issues at the heart of the digital privacy debate.

According to the Policy and Campaigns Officer at Liberty, Anna Cardoso, the newly-formed cabinet now has the opportunity to set out a positive vision for tech.

"We hope to see a human-centred approach to digital policy that puts people, privacy and fundamental rights at its core," Cardoso told TechRadar.

But what changes do digital privacy experts exactly hope for? What might a "human-centred approach" really look like? And how likely is the new government to live up to the expectation?

Does Andy Burnham mean an end to Digital ID cards?

Demonstrators protest against the Labour Government's plans to introduce a Digital ID, outside of the Labour Party's conference in Liverpool, north-west England, on September 28, 2025.

(Image credit: Photo by OLI SCARFF/AFP via Getty Images)

Keir Starmer’s BritCard was an unpopular policy among privacy-conscious citizens. Opponents to the programme then welcomed with excitement Burnham's decision to finally send the UK digital ID to the grave.

"We’ve done it," wrote Big Brother Watch's Director, Silkie Carlo, in a celebratory post on X, while Akiko Hart, Director at Liberty, called the move "a victory for civil liberties in the UK."

But Burnham's motivations to kill the proposal don't exactly come from privacy concerns. His decision was one of economics. Axing the BritCard means freeing up an estimated £600 million a year — from a policy no one wants — and using it for something citizens desperately desire, such as more support with the cost-of-living crisis.

In fact, Burnham told the Financial Times that he's not "arguing against the principle”. After all, he was a supporter of Tony Blair’s Identity Cards Act back in 2006.

"I think there’s a risk of an opportunity-cost situation here where something can consume a huge amount of time and actually doesn’t come through," he told the newspaper.

Does this mean that another form of BritCard be brought back when the time is right? Possibly.

Some commentators are already speculating that online ID checks may find a way to stick around.

Speaking with Al Jazeera, Alan Miller, co-founder of the campaign group Together, argues that other online government systems could evolve into a "de facto digital ID through creeping expansion".

Cardoso from Liberty agrees that killing one proposal isn't enough to sweep away all the concerns about digital forms of identification. Yet, she still considers it a huge step in the right direction. She told TechRadar:

"Whether or not digital ID returns in another form, any future proposal would need to demonstrate a clear public benefit, strong privacy protections, meaningful safeguards and robust democratic scrutiny. Those principles should apply regardless of who is in government."

Will Burnham really scrap Palantir's NHS deal?

The government's £330 million contract with Palantir to build the NHS's new Federated Data Platform (FDP) has also been a concern for Britain’s privacy-conscious citizens. Whether the wave of division on the subject has been one of geopolitics, morality or technical usability, data protection is at its core.

Some reports suggest that Burnham is already considering scrapping Palantir’s NHS contract. Something that, according to Palantir UK CEO Louis Mosley, "would be a terrible mistake".

While nothing is as yet confirmed, the Head of Tech and Data at Good Law Project, Duncan McCann, sees the political reshuffle as the best chance for the group’s campaign to remove Palantir from the UK's healthcare system to succeed, commenting to TechRadar that Burnham now represents "a beacon of at least an opportunity".

Health Workers for a Free Palestine, many of them striking Junior Doctors, picket military intelligence company Palantir in Soho square on December 21, 2023 in London, England.

(Image credit: Photo by Guy Smallman/Getty Images)

Burnham's track record in this area looks hopeful, too. During his almost decade as Mayor of Greater Manchester, municipal or public health departments did not award any contracts to the US surveillance tech giant.

And while McCann explains that Burnham may not necessarily be the one to credit for the decisions the city's public sector took on Palantir, it is an opportunity for hope of change at a national level.

As reported by Al Jazeera, Manchester’s NHS leaders spent six years building their own analytics infrastructure instead of adopting Palantir's FDP system, something that for Palantir critics became proof that effective NHS data management can be achieved without the help of the American company.

"It offers some real opportunity to show Manchester as an innovation hub," explained McCann, saying that the Good Law Project remains hopeful that this could fit well on Burnham's political agenda.

"It proves that we can do it ourselves and save money by doing that, while creating new jobs."

The Prime Minister's press office has already confirmed to reporters the guiding principle remains "getting value for money for the taxpayer" alongside the "need to be safeguarding people’s data and British interests", both of which fit neatly into McCann’s hopes.

As with the BritCard, then, it could be the financial angle that leads the digital rights community to have their concerns on Palantir and patients' privacy finally addressed.

Don’t expect much change to the UK’s approach to children's online safety

Keir Starmer dropped a digital rights bombshell in his last days of governance — an upcoming under-16s social media ban that privacy experts have already dubbed "a cybersecurity disaster waiting to happen".

But don’t expect Andy Burnham’s rise to power to change much here.

In an interview with The Times in April 2025, Burnham talked about the urgency to regulate social media platforms for teens. A concept he reiterated more recently, when he backed the Tories' call for a ban on under-16s from social media last January — as reported by The Guardian.

According to Policy Manager at the Open Rights Group, James Baker, that’s a clear sign that policies on social media will most likely remain unchanged.

"However, I'm not convinced it's going to work because it doesn't tackle the underlying root cause of what makes these platforms harmful," Baker told TechRadar, adding that evidence coming from Australia shows that young people can easily circumvent restrictions.

Baker argues that to really reassure British parents over their children’s online safety, we need a complete shift in policy.

"We need to tackle structural causes for harm instead, like the advertising business model causing platforms to come up with harmful loops that keep people online as long as possible," Baker told TechRadar.

That said, it also looks unlikely that Burnham will address privacy advocates’ concerns on mandatory age verification.

Back in 2016 — during the discussions around the controversial Investigatory Powers Act — Burnham took a strong stance against what he defined as "simplistic loyalties to the security or privacy lobbies", arguing that "such debates are pitched as a clash between two absolutes of privacy and security, where there can be no compromise and only one winner".

Baker agrees that the new Prime Minister probably isn't going to be a huge supporter of privacy causes. But he remains hopeful.

"So much time and energy has been spent trying to solve online safety with policies that haven't actually worked. Perhaps he will take a more pragmatic look and consider other, more cost-effective measures."

Again, economics may prove to be the deciding factor, shifting the conversation away from policies that experts fear will threaten digital freedoms.

So, what can we expect for Burnham on digital privacy?

By binning the digital ID proposal and the entire tech ministry within his first 36 hours of leadership, Andy Burnham proved he isn't afraid to move fast and break things. But as digital rights experts have made clear, a true 'circuit breaker' requires more than just stopping bad policy.

"Liberty wants policymakers to move away from a ‘technology first, questions later’ approach and instead place human rights at the heart of decision-making," Policy and Campaigns Officer Anna Cardoso told TechRadar.

She said that the real tests are yet to come on whether the government will be "willing to grapple seriously with the risks posed by surveillance technologies, AI and large-scale data collection."

Whether it comes from genuine concerns for digital privacy or a pragmatic way for closing the gap between politics and the public, it doesn’t much matter at this stage. If Burnham’s administration can weave privacy protections into his broader economic agenda, he might just deliver the positive vision for tech that advocates are desperate to see.

Until then, the digital rights community remains cautiously optimistic — holding its breath for the next move. As Baker from Open Rights Group puts it:

"We’ll try to give him a chance. Maybe he can do things a bit better."

Suspicious content? NordVPN's new AI bot will check it for you on WhatsApp, X, and Instagram

  • NordVPN releases a free-to-use AI tool that evaluates suspicious content
  • NordBot aims to stop users from falling victim to social media scams
  • It integrates directly with WhatsApp, Telegram, X, Instagram, Messenger

We all know the feeling of receiving a text about a missed delivery fee or a bizarre link from a friend's hacked Instagram account. As phishing tactics grow increasingly sophisticated, the maker of TechRadar's top-rated best VPN has launched a new tool to give you a much-needed second opinion before you click.

Today, NordVPN announced the launch of NordBot, an AI-powered agent designed to detect suspicious content across social media and messaging apps.

Developed by NordLabs, the company's experimental innovation hub, the tool allows users to quickly verify messages, URLs, and images directly within their favorite platforms.

Attackers constantly impersonate brands, support teams, recruiters, and even friends, often relying on urgency to push victims into sending money or clicking malicious links. The goal is to intercept scams where they are most prevalent.

"Scams follow you everywhere now, and they blend right into places you already trust. They show up in your DMs, your group chats, and the comments under a post you were just scrolling past," says Domininkas Virbickas, Product Director at NordVPN.

By evaluating content on the fly, NordBot aims to stop users from falling victim to fake giveaways and AI-generated imagery.

NordVPN – the best anti-scam VPN
NordVPN is the VPN service best equipped to protect you against the rise of online scams. Starting at the equivalent of only $3.49 per month, you'll get its top-rated VPN, alongside protection against phishing, invasive ads, web trackers, malware, scam calls, and malicious messages.

Try it out before committing by using the 30-day money-back guarantee.View Deal

How NordBot works

Unlike standalone security apps that require you to copy and paste the suspicious content into a separate browser window, NordBot is designed to live where the conversations happen.

It currently supports Instagram, Facebook Messenger, Telegram, X, and WhatsApp (via the number +1 940-616-6302), with Reddit integration reportedly coming soon.

Using the tool is straightforward. Whenever you spot a suspicious delivery notice or an unfamiliar link, you simply share the content with NordBot via a direct message or tag it under a public post — depending on the platform.

NordBot chatbot promo image

(Image credit: NordVPN)

NordBot only checks the specific content you send it — analyzing the data before replying with a quick safety verdict — to return one of four clear signals.

Safe if the content shows no clear signs of danger. Suspicious means it contains elements that deserve caution. Dangerous when it appears likely to be harmful or deceptive. AI-generated is reserved for content that looks created or heavily altered by AI.

However, the company warns that the bot isn't foolproof.

Because any AI tool can occasionally miss risky content or flag harmless messages, NordBot should act as an extra safety signal rather than a total replacement for good digital hygiene or NordVPN’s built-in next-gen antivirus.

Users are still urged to never share sensitive information, such as passwords, payment details, or one-time codes, with unknown senders.

NordLabs' trackrecord in fighting scams

NordBot is the latest project to emerge from the NordLabs initiative. Other releases include experimental tools like an AI voice checker to spot audio deepfakes and a dedicated link-checking tool.

Virbickas confirmed to TechRadar that NordBot is built on the same scam-detection technology and link-checking engines that power its existing NordLabs tools. What's new is NordBot's capability of detecting AI-generated images, which works by extracting and analyzing any text found in images.

"So, it's a combination of proven, battle-tested detection technology and new capabilities, delivered where people need it most," added Virbickas.

As with any other NordLabs release, NordBot is also completely free for anyone to use and does not require an active NordVPN subscription.

'$3.7B lost to deepfakes' — Why social media is the perfect launchpad for AI fraud

  • Surfshark's study puts total recorded deepfake fraud losses at $3.7 billion
  • Social media is the leading origin point, accounting for 47% of losses
  • 2025 and 2026 alone are responsible for 89% of the damage

Deepfakes have graduated from an internet curiosity into a serious financial threat.

New research from Surfshark finds that people have now lost at least $3.7 billion to deepfake fraud, and the pace of that damage is accelerating sharply.

The study also traced where these scams tend to begin, and one channel stands out above all others. Social media is the single largest origin point, accounting for 47% of all recorded losses.

Running the best VPN will encrypt your traffic and hide your IP address, but it cannot stop a convincing fake video of a celebrity or a cloned voice on the phone from talking you out of your savings.

Social media is the biggest source of deepfake fraud

Surfshark's graph showing the amount of deekfake frauds and where they come from (July 2026)

(Image credit: Surfshark)

The scale of the problem has changed almost overnight.

According to Surfshark's data, losses totalled just $83 million between 2020 and 2023, then climbed to $335 million in 2024, surged to $2.5 billion in 2025, and had already reached $764 million in the first half of 2026. Together, 2025 and 2026 account for 89% of all recorded losses.

Most of these losses come from criminals using deepfakes of celebrities and public figures to push fraudulent investment schemes on social media.

"A single deepfake video can go viral in hours, reaching millions of potential victims before it's detected or removed. No other channel offers that kind of reach at zero cost," explains Luís Costa, Research Lead at Surfshark.

Not every viral fake causes harm, though. Costa points out that an innocent deepfake of a footballer during the World Cup might rack up millions of views without costing anyone a penny, while a fake government post promoting a dubious investment scheme can drain thousands of dollars from a single victim.

The threat is spreading beyond your feed

Social media is only part of the picture. Impersonation fraud, where criminals use deepfakes to pose as real people or bypass identity checks, is the second-largest category at $911 million — or 25% of losses.

Fake job candidate schemes, in which AI-generated interviews are used to infiltrate hiring processes, added a further $100 million. These scams are expected to rise, too. As TechRadar previously reported, a 39% spike in "deepfake-as-a-service" chatter on the dark web could end up fueling the next wave of "fake boss" scams.

Everyday communication channels are increasingly in the firing line as well, contributing $174 million between them: phone calls ($71 million), video platforms ($62 million), and messaging apps ($41 million).

The FBI's latest Internet Crime Report also logged $893 million in AI-related losses for 2025, with AI-assisted investment fraud alone accounting for $632 million.

A separate Surfshark experiment found that nearly half of people cannot reliably tell a bot from a human online.

How to stay safe

As Costa puts it, "awareness is the only effective defense when a familiar voice or face can no longer be trusted implicitly".

For personal calls and messages, he suggests setting up a family "safe word" you can use with loved ones to confirm identity when a request feels urgent or out of character.

On video calls, a "glitch test" can help too. Ask the other person to wave a hand in front of their face, as deepfakes often blur or distort when facial features are obscured.

TechRadar has more advice on catching convincing AI images and deepfakes if you want to sharpen your eye.

'VPNs are lawful technical tools,' says EU Court in landmark Anne Frank copyright ruling

  • VPN providers aren't liable for copyright infringement, said the EU Court
  • The Court explicitly recognized VPNs as "lawful technical tools"
  • The case centered on the copyright battle involving Anne Frank's diary

In a major victory for digital rights and common sense, the Court of Justice of the European Union (CJEU) has officially categorized Virtual Private Networks (VPNs) as "lawful technical tools" while establishing new boundaries for online copyright disputes.

The landmark judgment — handed down in July 2026 — stems from a complex legal battle over the online publication of Anne Frank's historical manuscripts. At its core, the case forced Europe's top judges to answer a highly technical question: if a publisher actively tries to block visitors from a specific country, are they still breaking the law if a user sneaks past the digital border using circumvention software?

According to the CJEU, the answer is no. As long as a website employs "state-of-the-art" geo-blocking technology, the publisher cannot be held liable for copyright infringement simply because a determined reader decides to fire up the best VPN to bypass the restrictions.

The ruling sets a massive precedent. It confirms that copyright holders cannot point to the mere existence of VPNs to claim a website's security measures are completely ineffective.

More importantly for privacy advocates, the court firmly pushed back against the demonization of privacy software, cementing the legitimate status of VPN providers across the European Union.

The Anne Frank dispute explained

The EU's top court just confirmed: Geo-blocking is the copyright holder's problem, not the VPN's. Providers are not liable for users bypassing restrictions ⚖️ @torrentfreak https://t.co/fLwb5kYAy1July 17, 2026

The legal tug-of-war began when a coalition of Dutch and Belgian academic institutions published a free, scholarly online edition of Anne Frank's manuscripts.

Because copyright laws are not fully harmonized across Europe, the legal status of the famous diary varies by territory. In Belgium and roughly 60 other countries, the writings entered the public domain years ago. However, in the Netherlands, parts of the text remain protected by copyright until 2037.

To respect this territorial divide, the publishers hosted the site in Belgium and used geo-blocking to prevent access from Dutch IP addresses. Visitors from the Netherlands were met with a notice explaining why they couldn't enter the site.

The Anne Frank Fonds, which holds the Dutch copyright, sued. They argued that because standard VPNs easily allow users to mask their true IP address and spoof a Belgian location, the scholarly website was effectively communicating the protected work to the Dutch public.

The CJEU ultimately rejected this argument. In its judgment, the court noted that while geo-blocking measures can inevitably be circumvented, "the possibility of such circumvention cannot, in itself and in all circumstances, be a decisive factor in finding those measures to be inadequate and, therefore, ineffective."

Why this matters for the internet and VPN users

For everyday internet users, the "So What?" of this ruling is deeply reassuring. It validates that using a VPN to encrypt your online traffic, hide your IP address, or bypass digital borders is a legitimate use of consumer technology.

The judges explicitly shielded VPN companies from collateral damage in piracy lawsuits, a topic that has sparked intense debate among European ISPs and rightsholders. The court specifically argued that the provider of a VPN or similar services is not liable for users bypassing restrictions.

By placing the legal burden on publishers to maintain "state-of-the-art" digital fences, rather than demanding absolute, impossible perfection, the EU has drawn a pragmatic line in the sand.

Publishers aren't expected to build unhackable walls, and VPN providers aren't responsible for the actions of users who climb over them. Ultimately, this ruling proves that the borderless internet can still coexist with territorial copyright laws, provided everyone uses the right technical safeguards.

'It’s time to punch more holes in the closed Internet' — This free VPN now promises to be even better at evading censorship

  • A digital rights group unveils a new version of its free, open-source VPN
  • FreeSocks v2 adds Xray-based pluggable proxy to evade VPN blocks
  • Post-quantum encryption has also been added for maximum security

With state-sponsored internet blocks growing more sophisticated worldwide, ordinary citizens are finding it increasingly difficult to stay connected. Now, one privacy-focused non-profit is fighting back by completely rebuilding its popular censorship circumvention tool.

Unredacted, a US-based non-profit dedicated to internet freedom, has launched the second generation of its free VPN service, FreeSocks. First released in 2023, the original service successfully issued over 60,000 access keys to users trapped behind digital firewalls.

However, as Unredacted noted in a blog post, censors have refined their blocking skills and become more efficient in blocking VPN and proxy protocols designed to circumvent Internet censorship. "We realized we needed to build FreeSocks from the ground up via a highly flexible system," the group explains.

Today (July 20), Unredeacted announced the new version of the app, adding that "It's now time to punch more holes in the closed Internet."

FreeSocks v2 is now live and promises to provide an incredibly powerful, fully anonymous alternative designed specifically for high-risk environments.

Unredacted’s mission against a closing web

Why the urgent need for a censorship-resistant VPN? 2025 was the worst year on record for internet shutdowns, and state censors are deploying increasingly advanced deep packet inspection (DPI) to identify and block traditional proxy traffic.

Unredacted’s stated mission is to "Operate with absolute transparency, morality, and empathy to directly benefit users and citizens globally." As governments crack down, everyday users, like Iranians overcoming unprecedented internet censorship, are forced into a daily struggle to access outside information.

Censors got better at blocking VPNs, so we rebuilt ours from the ground up.FreeSocks v2 is out today, with harder-to-block protocols, accounts that collect no personal data, and no IP logging anywhere.It's free forever. Share it with a friend behind the censored Internet.July 20, 2026

This mirrors global trends where VPN providers have radically adapted how they dodge blocking technology. Rather than relying on easily identifiable connections, modern circumvention demands dynamic VPN obfuscation technology.

Unredacted embraces this approach by shifting away from the easily blocked Outline (Shadowsocks) protocols to a new primary backend running Xray.

By supporting pluggable proxy backends, FreeSocks v2 can instantly pivot if censors catch on. This ongoing cat-and-mouse game continues to pose a broader question to the industry: is the future of censorship-resistant VPNs no VPNs at all?

Upgraded privacy, hardware, and post-quantum encryption

Diagram on how Unredacted's FreeSock works

(Image credit: Unredacted)

Beyond evading blocks, FreeSocks v2 offers aggressive privacy guarantees. Users don't need an email or password to sign up. Instead, solving a proof-of-work challenge generates a random 32-digit account number. Furthermore, Unredacted explicitly confirms: "The application never stores a client IP address anywhere – not even hashed."

Security is also heavily bolstered by hybrid post-quantum encryption. FreeSocks v2 adds X-Wing, a hybrid protocol that combines classical X25519 and post-quantum ML-KEM-768 algorithms. In simple terms, it ensures that your data remains secure even against hypothetical future quantum computers designed to break modern encryption.

Crucially, Unredacted is cutting ties with third-party hosting, too. "FreeSocks v2 is launching fully on hardware that we own, colocated in Kansas City, MO," the team confirmed. This hardware ownership prevents upstream providers from interfering with user traffic or handing over server logs.

While the core service remains free, users can purchase an optional $5 monthly membership to remove traffic limits. Unredacted also accepts cryptocurrency and fiat donations.

In a unique philanthropic twist, every donation made to the platform directly funds a shared bandwidth bonus that is automatically split across all free users on the network every month.

US sanctions on rogue VPN accidentally break Telegram's short links worldwide

  • The US Treasury sanctioned First VPN Service for aiding ransomware gangs
  • Complying with the sanctions, the .ME registry wrongly suspended Telegram's entire t.me domain
  • The domain was restored roughly 19 hours later after Telegram CEO Pavel Durov flagged the issue online

If you clicked a Telegram link on Monday and stared at a blank screen, you weren't alone. Every shortlink starting with 't.me' suddenly vanished from the global internet, breaking group invites, profile shares, and channel links for roughly a billion users worldwide.

But the outage wasn't caused by a technical glitch or a targeted cyberattack. Instead, it was the unintended collateral damage of a US government crackdown on a cybercriminal proxy network.

On July 13, the US Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned the administrators of a rogue proxy network called First VPN Service (1VPNS), aiming to cut off infrastructure used by ransomware operators.

While anyone shopping for the best VPN expects privacy, First VPN actively courted cybercriminals with promises of total anonymity, leading European law enforcement to pull the plug on the service earlier in May.

As part of the new sanctions, the US Treasury published a list of web addresses associated with the VPN. Buried in that list was a link to First VPN's public Telegram support channel: t.me/FirstVPNService.

A sledgehammer to crack a nut

This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading,

(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)

Because top-level domains operate under strict international compliance rules, domain registrars must act quickly when sanctioned entities use their infrastructure.

Identity Digital, the company managing the technical backend for the .me domain, confirmed that the t.me domain had been blocked at the request of OFAC.

However, because a domain registry cannot selectively disable a specific webpage or channel path — like a single Telegram group — the Montenegro-based registry Domain.Me applied a "serverHold" status to Telegram's entire t.me domain.

This sweeping action effectively erased the domain from the global Domain Name System (DNS). The core Telegram app continued to function, and the older telegram.me domain remained active, but the shortlinks the messaging platform is built upon went entirely dark.

The swift resolution

The sudden shutdown prompted immediate action from Telegram's leadership.

Unaware of the backend domain hold, Telegram CEO Pavel Durov took to X to publicly ask the registrar for an explanation: "Hey @domainME, t.me links stopped working. Can you look into it?"

Hey @domainME, https://t.co/9z6UC2o37U links stopped working. Can you look into it? 🙏July 14, 2026

Once the sanctions issue was identified, Telegram scrubbed the offending channels from its platform. The registry operator subsequently verified the compliance and brought the domain back online.

"On 13 July, 1VPNS was included as a sanctioned entity by the US Department of the Treasury. A Telegram channel using the t.me domain was among 1VPNS identified infrastructure. Accordingly, the t.me domain was suspended," domain.Me confirmed in a statement following the outage.

The registrar clarified that normal service resumed roughly a day later, after Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. "We appreciate Telegram's prompt cooperation in resolving this matter," domain.Me added.

While the outage is now resolved, the incident highlights a glaring vulnerability in the modern web, where a single URL swept up in a government sanctions list can inadvertently silence an essential communication channel for millions.

❌
❌