A recent audit of 281 free VPN applications has uncovered widespread data leakage and tracking behaviors... Researchers from the University of Michigan, the University of New Mexico, and IIT Delhi found that the majority of these apps prioritize data collection over user anonymity.

Advertisement

246 of 281 free VPN apps are communicating with trakcers

The fundamental issue driving these privacy breaches is the economic reality of the VPN industry.. Because free VPN apps must pay for expensive server infrastructure, many turn to data harvesting to remain profitable. As the report suggests, when a standalone app has no paid product behind it, the user's data often becomes the primary commodity used to fund operations.

According to the report, 246 of the 281 free VPN apps tested were found to be communicating directly with advertising or tracking domains.. This suggests that instead of creating a secure tunnel for your internet traffic, these apps may be acting as a bridge for third-party advertisers to monitor your online activity.

2.4 billion installs are exposed to data leakage

The scale of the privacy risk is massive, as the audited apps represent more than 2.4 billion total installs globally. This means billions of devices may be operating under a false sense of security while their data is being harvested.

The technical failures identified in the study are significant.. Researchers found that 61 of the audited apps sent data in plain text, and 29 apps leaked DNS and browser traffic outside of the protected tunnel. Such leaks allow internet service providers or malicious actors to see exactly which websites a user is visiting, effectively nullifying the core purpose of using a VPN.

Deloitte’s six audits of NordVPN provide a privacy benchmark

Paid services like NordVPN offer a different security profile compared to the unverified free alternatives analyzed in the study. While free apps often lack transparency, NordVPN utilizes third-party verification to validate its privacy claims. As the report notes, Deloitte has audited NordVPN's no-logs policy six times, with the most recent audit completed in February 2026.

Beyond privacy, the study highlights a significant performance gap between free and paid models. In testing on a 190 Mbps connection, NordVPN showed minimal speed degradation, dropping only 3-7 percent in the United States and 10-20 percent for international connections. This stands in stark contrast to the unpredictable performance and high-risk profiles of the free apps identified by the researchers.

Which 17 popular apps are hiding trackers?

While the audit provides a stark warning, several specific details regarding the most common apps remain unverified. The report mentions a separate study of 18 popular free apps where 17 were found to contain trackers—averaging five per app—but the report does not name which specific applications were compromised . This leaves consumers in a difficult position, unable to identify which household names might be part of the problem.

Additionally, the distinction between how "standalone" free apps sell data versus how "freemium" companies might use their free tiers remains a gray area. It is still unclear to what extent companies that offer both free and paid versions use their free tiers to gather intelligence on users for their broader business models.