Increasingly, researchers and government agencies say that it operates in direct contradiction to the privacy it claims to provide. The exodus toward paid services is no longer anecdotal, it is now measurable, and the reasons behind it are serious.
The Shift Is Measurable
A 2025 survey by NordVPN found that in the United States, the share of VPN users choosing paid services jumped from 42% to 52% in a single year. While free VPN usage held flat, a significant shift in preference within an overall user base that has remained relatively stable.
This isn’t a matter of brand loyalty or marketing. The migration is being driven by a growing body of documented harm that is difficult to ignore.
The Breach That Changed the Conversation
In 2023, cybersecurity researcher Jeremiah Fowler discovered a publicly exposed, non-password-protected database containing over 360 million records. It is linked to SuperVPN, a free app with more than 100 million downloads worldwide. The exposed data included email addresses, original IP addresses, geolocation records, references to visited websites, and unique device identifiers.
Fowler reported the exposure to VPNMentor, calling it a wake-up call for anyone who assumes a free VPN actually protects them. The breach also contradicted SuperVPN’s own no-logs policy, exposing the gap between what free providers claim and what they actually collect.
From Data Leaks to Botnets
The SuperVPN case was not an isolated incident. In May 2024, U.S. law enforcement dismantled one of the largest botnets ever discovered, comprising 19 million hijacked IP addresses across more than 190 countries. At least 18 fake free VPN apps have been identified as the primary infection vector.
Users who installed these free VPNs had their devices secretly converted into proxy servers. Their bandwidth is sold to cybercriminals for fraud, money laundering, and launching attacks on others.
The Business Model Is the Problem
The structural economics of free VPNs leave little room for genuine privacy. Industry analysts project that as many as eight in ten free VPN services embed tracking features. Over half may sell user data to third parties, a monetization model that inverts the product’s core value proposition.
Kaspersky reported that in Q3 2024, user encounters with malicious applications pretending to be free VPNs rose 2.5-fold quarter over quarter. The acceleration suggests the problem is not stabilizing; it is scaling.
Federal Agencies Issue a Direct Warning
Government bodies have now moved from implicit concern to explicit public guidance. CISA’s December 2024 mobile communications advisory stated directly: “Personal VPNs do not eliminate online risks. Instead, they transfer trust from internet service providers to VPN companies, which can introduce additional security and privacy concerns if the provider is not trustworthy.”
The guidance was issued in the context of PRC-affiliated espionage targeting telecommunications infrastructure. Its implications extend across the entire consumer VPN market, particularly the free tier, where provider accountability is hardest to verify.
What Users Are Concluding
Users who have made the switch describe the free model as one where costs materialize in other ways. The ways may include security risks, speed degradation, and lost productivity, rather than disappearing entirely. The perception of savings, in other words, rarely survives contact with reality.

