Choosing between VPNs to avoid and VPNs worth paying for is less about speed tests than about one uncomfortable question: what happens when a court asks your provider who you are? A VPN moves your trust from your internet provider to a company you have probably never heard of. Several well-known services have already answered that question badly, and the warning signs were visible beforehand.
Key takeaways
- A VPN does not make you anonymous. It shifts who can see your traffic — nothing more.
- Free unlimited VPNs are the single biggest red flag. Servers cost money, so if you are not paying, your data is usually the product.
- "No logs" is a marketing phrase until it is tested in court or by an independent audit. Several providers made that promise and then handed over identifying information anyway.
- Judge providers on published audits, protocol support, leak protection and ownership — not on the star rating in an app store.
- Run your own leak tests after connecting. Reliable providers pass; several documented failures did not.
- Jurisdiction and the parent company matter as much as the software.
Seven warning signs of a VPN you should not trust
1. It is free and unlimited
Bandwidth and server capacity are real costs. A provider giving away unmetered access has to earn revenue somewhere, and the usual answers are selling usage data to analytics brokers, injecting advertising, or renting out user connections. A free tier attached to a paid plan, with a clear data cap, is a different and far more honest proposition. Open-ended free service with no limits deserves suspicion.
2. The logging policy dissolves when you read it
Plenty of privacy pages headline "we keep no logs" and then describe, further down, the connection timestamps, source IP addresses, bandwidth totals or device identifiers they retain for "service quality". Any of those can link an account back to a person. Read the actual policy rather than the landing page, and ask support directly if the wording is vague.
One practical test: ask how the provider bans abusive accounts. If they enforce bans against specific users, some identifier is being retained. If they cannot enforce bans at all, the no-logs claim is more plausible. Providers who answer that question with marketing language are telling you something.
3. There is no independent audit
This is the clearest dividing line in the market today. Serious providers now commission outside security firms to inspect their infrastructure and no-logs claims, and publish the report. A provider making strong privacy promises with nothing external to support them is asking for faith. Several have also moved to RAM-only servers that cannot retain data across a reboot, which is a meaningful architectural commitment rather than a slogan.
4. It leans on obsolete protocols
PPTP has been considered broken for years and should not appear in any current product. L2TP/IPsec is dated. What you want to see is OpenVPN, which is open source and has been scrutinised for two decades, or WireGuard, a leaner modern protocol now used by most major providers, often wrapped in their own layer to handle its address-assignment quirks. A provider still pushing PPTP as a headline feature has not kept up.
5. It leaks
Even a connected tunnel can leak. DNS lookups may escape to your internet provider's resolver, WebRTC in the browser can expose your real address, and IPv6 traffic frequently bypasses tunnels built only for IPv4. Switching from Wi-Fi to Ethernet, or waking a laptop from sleep, can drop the tunnel while traffic keeps flowing.
Verify it yourself. Note your address at a site such as ipleak.net before connecting, connect, and check again. The IP address and the DNS servers listed should both change. A provider without a working kill switch — which blocks traffic entirely when the tunnel drops — is not built for privacy.
6. The jurisdiction and the owner are unclear
Providers based in countries with broad intelligence-sharing arrangements, including the Five Eyes group and its wider circles, can face legal pressure that a company elsewhere would not. Jurisdiction is not the whole story — a provider holding no data has little to surrender wherever it sits — but combined with weak transparency it is a genuine concern.
Ownership matters too. A wave of consolidation has left several familiar brands under shared corporate parents, sometimes alongside the review sites that rank them. Find out who actually operates the service before trusting it.
7. Payment options that pin you down
If your threat model extends beyond casual tracking, a provider accepting cryptocurrency or cash removes the billing record that ties a subscription to your identity. For most people this is a refinement rather than a necessity, but its absence tells you how the provider thinks about its users.
Specific VPNs to avoid: providers with documented failures
Speculation is one thing; a public record is another. Each service below has a specific, reported incident attached to it. Some have changed hands or revised their practices since, so treat these as case studies in how trust breaks rather than a permanent blacklist.
| Service | Year | What was reported |
|---|---|---|
| Hola | 2015 | Routed other people's traffic through users' own machines as exit nodes, and sold that bandwidth onward. |
| HideMyAss | 2011 | Supplied activity logs to the FBI that identified a user, despite the service's privacy positioning. |
| Hotspot Shield | 2016–2017 | Research and a privacy complaint alleged JavaScript injection and redirection of e-commerce traffic to partner domains. |
| Onavo (Facebook) | 2018 | Marketed inside Facebook's apps as "Protect" while collecting mobile usage data for the company's own analytics. |
| Opera free VPN | 2016 | Functionally a browser proxy rather than a full system VPN, with usage data collected. |
| PureVPN | 2017 | Retained enough information to help investigators identify a user, despite a no-logging promise. |
| VPNSecure | 2016 | Academic testing reported IP and DNS leaks plus residential egress points resembling Hola's model. |
| ZenMate | 2018 | Independent testing found IP leaks, and the response to the disclosure was slow. |
What these cases have in common
Three patterns repeat. First, the free services monetised users rather than serving them — Hola and Onavo both treated the user base as inventory. Second, the no-logs promise collapsed under legal pressure at HideMyAss and PureVPN, showing that a policy page is not a technical guarantee. Third, leaks at several providers meant the product failed at its one job while the connection indicator stayed green.
The takeaway is not that these eight names are uniquely bad. It is that none of the failures were detectable from the marketing, and all of them would have been caught by the checks in the previous section.
How to vet a VPN before you pay
- Name your actual threat. Hiding traffic from a café network, a landlord's router or an internet provider is an easy problem. Evading a state adversary is not, and a commercial VPN is the wrong tool for it — Tor is designed for that case.
- Find the audit. Look for a published report from a named security firm, with a date. An audit from five years ago covers a product that no longer exists.
- Read the privacy policy to the end. Search it for "IP", "timestamp" and "retain" and see what survives the no-logs headline.
- Check who owns it. Trace the parent company, then check whether it also owns the sites recommending it.
- Confirm the essentials: WireGuard or OpenVPN, a kill switch enabled by default, DNS handled by the provider's own resolvers, and IPv6 either tunnelled or blocked.
- Test it on day one. Run leak tests while connected and again after forcing a disconnection. Use the refund window if anything leaks.
Worth saying plainly: for many everyday purposes you may not need a VPN at all. Nearly all web traffic is now encrypted with HTTPS, so a public Wi-Fi network already cannot read the contents of your browsing. A VPN hides which sites you visit from the network and your internet provider — useful, but a narrower benefit than the advertising suggests. For more on the broader picture, see our cybersecurity coverage and internet guides.
Frequently Asked Questions
Which VPNs should I avoid completely?
Avoid any unlimited free VPN, anything with no independent audit behind a strong privacy claim, and providers with a documented history of logging or leaking — the table above lists eight with public incidents. Also avoid services that will not clearly state who owns and operates them.
Are free VPNs ever safe?
A capped free tier from a provider that also sells paid plans can be legitimate, because the paid customers fund the infrastructure. Unlimited free service with no obvious revenue source is the one to walk away from.
Does a no-logs policy actually protect me?
Only when it is enforced by architecture rather than intention. RAM-only servers that discard everything on reboot, plus an external audit or a court order the provider demonstrably could not satisfy, are the evidence worth looking for. A promise on a web page is not.
How do I test whether my VPN is leaking?
Record your public IP address and DNS resolvers with the VPN off, connect, and check the same page again. Both should change. Then kill the connection deliberately and confirm the kill switch stops traffic instead of quietly falling back to your normal connection.
Does the provider's country really matter?
It matters, but less than what the provider stores. A company in a surveillance-sharing jurisdiction that genuinely holds nothing has little to hand over, while a provider in a privacy-friendly country that logs connection times remains a risk. Look at retention first, jurisdiction second.
Is a VPN enough to stay private online?
No. It hides traffic from the network you are on, and does nothing about browser fingerprinting, tracking cookies, or the accounts you are logged into. Pair it with a browser that blocks trackers and sensible account hygiene.
Final thoughts
The VPNs to avoid are rarely the ones with bad reviews — they are the ones making promises nobody has checked. Before subscribing, find the audit, read the retention terms in full, identify the owner, and test for leaks in the first hour. If a provider fails any of those and its main selling point is that it costs nothing, you are not buying privacy; you are choosing which company gets to watch you.









Comments