80% of VPNs Make False Claims About Anonymity, Tracking and Security
VPN software started as Israeli spyware. The industry hasn't shaken its roots.
“A huge number of VPN companies are not real companies. They’re shell corporations, adware firms, offshore fronts, and former spyware vendors rebranded as privacy tools.”
—Addie LaMarr, here
Earlier this year we started to look at VPNs, what they are, what they do, and how the government treats them. The first part of that examination is here:
Bottom line: The government, in the interest of “keeping you safe,” always spies on VPNs. Always. Because, what are you hiding?
(For those who care, there’s never been a clearer example of the unbreakable government rule — “Surveillance for you, secrets for us and our friends” — than what’s shown in Ken Klippenstein’ recent piece, “Is Mitch McConnell Dead?”. The “ingrained secrecy of officialdom” is the mildest way to describe it. The rule is absolute.)
In that earlier piece, I promised more about VPNs. Here is that more. It’s a lot.
VPNs Were Created As Spyware
The heading above is correct. The VPN industry as we know it has a dark history. VPNs apps were initially created as spyware (“full spectrum traffic surveillance”), first by the Israeli government’s sinister Unit 8200, their equivalent of our NSA, and then so that Facebook, to gain competitive advantage, could hack through Snapchat’s encryption and spy on their teenage users.
From the video above (at 1:41):
By 2016, Snapchat had basically taken over as a go-to app for Gen Z. Teenagers were leaving Facebook and Instagram in huge numbers, and Facebook needed to know fast just how quickly that shift was happening.
Then Snapchat encrypted its traffic, and Onavo [Israeli-developed spyware that Facebook was using] was now blind. So Zuckerberg sent his team a clear directive. We need reliable analytics about Snapchat. You should figure out how to do this.
Facebook engineers launched something called Project Ghostbusters. It was a plan to bypass HTTPS encryption and restore visibility into Snapchat, YouTube, House Party, and other apps.
Facebook was eventually found out and, though it took a while, was forced to stop. That’s where the VPN industry as we know it was born, out of this spyware app (4:15 in the video).
[Facebook] opened the door, and others started copying the business model. Companies with histories in adware, spyware, and data harvesting began acquiring VPN services. Trust was not their goal. They just needed users to stop asking questions. Some of the most popular VPNs today are built on that exact same structure. They have the same incentives and playbook. And unless you’re looking deep under the surface, it’s nearly impossible to tell.
This is where it goes from sketchy to straight up sinister. Because a huge number of VPN companies are not real companies. They’re shell corporations, adware firms, offshore fronts, and former spyware vendors rebranded as privacy tools.
And maybe you’ve seen those independent VPN review sites, the ones that always seem to rank ExpressVPN and Ghost in the top three. Surprise, those sites are owned by the same company that owns the VPNs. And that company’s got one hell of a backstory.
Trust: A Thing to Be Sold
The industry, frankly, is rotten to the core. VPN companies — not all, but most — are exploitive by nature. The simplest way is neglect, selling you something you want that they never deliver. One of their pitches is privacy. Yet incidents like this seem regularly to occur (7:51):
In 2020, seven no-log VPNs, including UFO VPN and SuperVPN, were caught with 1.2 terabytes of exposed user log names, IPs, session timestamps, all wide open.
A “no-log VPN” is a VPN company that promises never to keep user metadata logs. These companies obviously lied.
Keep in mind, every free VPN — every free VPN — is getting its money from somewhere, and selling something to get it. If they’re not too unscrupulous, they give users the least they can in product-value, in order to keep their costs capitalist-low.
And if they are unscrupulous, well … they have all this data, and data is valuable.
VPNs Can Be The Right Tool
VPNs can be a good tool — the right VPN, that is — but not in all circumstances. Use VPNs when you want to:
Access a public Wi-Fi
Bypass a firewall
Access blocked regional content
Reduce (but not eliminate) your tracking surface
VPNs are definitely not right, when used alone, for investigators and reporters. Computer fingerprinting is still a thing, and VPNs don’t solve that problem. You can still be easily identified in other ways.
The ‘Good’ VPNs
LaMarr’s list of ‘good’ VPNs isn’t long, and may not be comprehensive. So I’m just passing it on. VPNs that she recommends are these:
Mullvad (Sweden)
IVPN (Gibraltar)
ProtonVPN (Switzerland)
See the video or transcript (below) for more explanation. I personally use ProtonVPN and I’m very pleased.
Transcript
This is a lightly editied version of YouTube’s generated transcript. Though it’s good, it’s clearly not perfect. Inserted headings and emphasis are mine.
What if the privacy tool you trusted was designed to exploit you? You were told a VPN would keep you safe online, that it would protect your privacy. But what if the tool you just downloaded for safety was actually built to watch you? What if the tool you installed for privacy quietly recorded your behavior, your app usage, your habits, your online patterns, and sold access to that data?
In this video, you’ll learn how the most dangerous VPN ever created went undetected for years, how a major tech giant used it to spy on teens and crush competitors, and why today’s trusted VPNs are still using the same blueprint.
I spent months combing through leaked emails, court documents, and buried privacy policies that were never supposed to be read. What I found wasn’t illegal, but it was disturbing because the system was built to allow it.
This story isn’t about one bad company. It’s about how the entire VPN industry got away with it. how trust became a business model and why the next time someone promises you privacy, you’ll know what to look for.
[VPN Origins: Facebook, Israel and Snapchat]
Back in 2013, Facebook bought this small Israeli app called Onavo. It was built by cyber intelligence veterans from unit 8200 [the Israeli NSA]. The specialty in that unit was traffic interception, behavioral analytics, and deep packet inspection.
On the surface, Onavo was marketed as a data saving app, but in reality, it became one of the most powerful surveillance tools ever deployed on consumers. From the moment you installed it, every packet of data on your phone, including every app you opened, every background process, and every tap, was routed through servers owned by Facebook. That gave them full visibility into which apps you used, how often, how long you stayed, and what kept you hooked, and in some cases, even the content itself.
It was full spectrum traffic surveillance, and Facebook used it to spy on competitors, especially Snapchat.
By 2016, Snapchat had basically taken over as a go-to app for Gen Z. Teenagers were leaving Facebook and Instagram in huge numbers, and Facebook needed to know fast just how quickly that shift was happening.
Then Snapchat encrypted its traffic, and Onavo was now blind. So Zuckerberg sent his team a clear directive. We need reliable analytics about Snapchat. You should figure out how to do this.
Facebook engineers launched something called Project Ghostbusters. It was a plan to bypass HTTPS encryption and restore visibility into Snapchat, YouTube, House Party, and other apps.
Here’s how they did it. They created a fake root certificate to impersonate apps. They installed it through a VPN profile. It intercepted encrypted traffic. It decrypted that traffic and logged it and then re-encrypted it before sending it along.
From the user side, everything looked normal. But in reality, Facebook had just carried out a man-in-the-middle attack. the exact kind of tactic you’d expect from spyware or state surveillance programs.
And the people they tested on were teenagers aged 13 to 17. They were offered 20 bucks in gift cards to give Facebook full root level access to their phones. Even Facebook’s own VP of security warned, “No security person is ever comfortable with this.”
Eventually, in 2018, Apple banned Onavo for violating its privacy rules, so Facebook just rebranded it. They called it Facebook Research, code-named it Project Atlas, and used Apple’s enterprise distribution system to sneak it onto iPhones, bypassing the App Store entirely.
And their target was still teenagers. They paid kids, again, aged 13 to 17, $20 a month in gift cards to install the app and hand over complete root access. And it only stopped when TechCrunch broke the story in 2019. Apple responded by revoking Facebook’s enterprise certificates, which instantly killed every internal app Facebook employees were using at the time.
But did they actually stop? No. They kept the project alive on Android. They kept collecting data. They kept making billion-dollar decisions based on surveillance. This was a long-term business model designed with intent backed by technical expertise and strategically targeted at minors.
And yeah, this is the part where I have to be careful and censor what I say. YouTube is advertiser friendly, especially with VPN companies. So I can’t always show you everything here. That’s why I put the full breakdown, the documents, receipts, and my real docs inside the Cyber Resistance Club. If you want the uncensored version, it’s all waiting for you in the link below.
[The Industry Grows]
So here’s what matters now. Facebook was the first to do it this way. They used a VPN to collect user data under the label of privacy, and it worked. That opened the door, and others started copying the business model. Companies with histories in adware, spyware, and data harvesting began acquiring VPN services.
Trust was not their goal. They just needed users to stop asking questions. Some of the most popular VPNs today are built on that exact same structure. They have the same incentives and playbook. And unless you’re looking deep under the surface, it’s nearly impossible to tell.
This is where it goes from sketchy to straight up sinister. Because a huge number of VPN companies are not real companies. They’re shell corporations, adware firms, offshore fronts, and former spyware vendors rebranded as privacy tools.
And maybe you’ve seen those independent VPN review sites, the ones that always seem to rank ExpressVPN and Ghost in the top three. Surprise, those sites are owned by the same company that owns the VPNs. And that company’s got one hell of a backstory.
[Kape Technologies]
Ever heard of Kape Technologies? Didn’t think so, but that’s on purpose. Kape, formerly known as Crossridder, used to make browser hijackers and ad injection malware. In 2018, they changed their name because obviously malware wasn’t a great look. They then quietly started buying up the VPN industry.
Here’s what they own now. CyberGhost since 2017, ZenMate in 2018, Private Internet Access or PIA in 2019, and ExpressVPN, which was bought in 2021 for $936 million.
And that’s not all. Kape also owns the independent review sites VPN Mentor and Safety Directives, which consistently rank Kape’s own products at the very top of every best VPN list.
You’re not supposed to catch that. The same company that used to inject ads into your browser now controls multiple major VPN brands and the review sites that recommend them.
They built an entire surveillance ecosystem, monetized both ends of it, and slapped a privacy sticker on the front. One industry analyst put it like this. Kape’s network was explicitly designed to go after your data and your wallet.
Do you still feel safe with your VPN?
[Most VPN Companies Aren’t Honest]
Kape isn’t the only one playing this game. The VPN industry is littered with fake names, offshore shells, and state level entanglements.
Here’s just one example. Back in 2025, investigators found out that more than 20 of the top 100 VPNs in the app store were quietly owned by Chinese companies. That list included TurboVPN, VPN Proxy Master, and ThunderVPN, all tied to a parent firm connected to Jiu 360, a company blacklisted by the US government for national security risks.
Their ownership was masked through Cayman Islands and Singapore registered shells, but the traffic was routed through some very questionable infrastructure and users had no idea. These apps had millions of downloads.
Meanwhile, ExpressVPN, yes, the one owned by Kape, employed a former mercenary hacker from the UAE’s Project Raven. That’s a surveillance unit known for using zero days [a type of cyber attack] against journalists and activists. That executive stayed on staff even after the US fined him.
That’s the kind of decision that tells you exactly what kind of company you’re dealing with. And it gets worse when you look at all the claims these companies make, the ones plastered all over their websites, their ads, and their influencer deals.
Because one of the biggest ones is “no logs” [a promise to keep no logs]. Here’s the dirty secret of VPN marketing. “No logs” means absolutely nothing without proof. And most VPNs either don’t get audited, get fake audits from shady shell companies, or just outright lie.
Even when there is an audit, it’s usually a one-time thing, outdated, or only done on one server, or maybe a limited configuration.
When logs do exist, they leak. In 2020, seven no-log VPNs, including UFO VPN and SuperVPN, were caught with 1.2 terabytes of exposed user log names, IPs, session timestamps, all wide open.
All of them were running on the same white label infrastructure. All used fake company names, and all made the same hollow privacy promises.
[VPN Companies Sell Trust]
By the mid-2010s, VPNs had a problem. Nobody outside of niche tech forums cared about them. So the companies behind them pivoted and they started paying creators. And it worked. People who didn’t understand how VPNs actually function were suddenly promoting military-grade encryption and 100% anonymous browsing like it was toothpaste.
Audiences listened because trust scales a lot faster than truth.
And here’s the part no one talks about. For most creators, 60 to 70% of their income comes from sponsorships. And VPN companies pay really well. It’s $5,000 for a mid-tier channel, and up to $25,000 per integration for bigger ones, plus lifetime commissions on every sign-up. That’s 30 to 50% of every subscription for years going to creators.
In 2023, researchers reviewed 243 VPN ads on YouTube. 80% of them made false claims about anonymity, tracking protection, and security.
And the vast majority of creators? They never checked what was actually under the hood. There’s no incentive to verify a product when the pitch pays better than the truth.
But this isn’t about blaming creators. It’s about the system. Because under capitalism, trust becomes a product. And once it’s up for sale, privacy doesn’t stand a chance.
This is also why I have never accepted a sponsored post. If you are wondering what the hell you’re actually supposed to use to stay safe online, buckle up. We’re about to break down exactly what makes a VPN worth trusting, which ones actually pass the test, and what to use instead if you really want to protect yourself.
[What VPNs Do and Don’t Do]
Let’s clear something up real quick because most people don’t actually understand what a VPN even does and what it doesn’t.
At its core, a VPN is just a private tunnel. It encrypts your traffic between your device and the VPN server, and it hides your IP address from your internet service provider or ISP and local network. That’s it.
Here’s what that tunnel actually gives you. Your traffic is encrypted between you and the VPN. Your IP address is masked from the sites you visit. You get protection on sketchy public Wi-Fi. And yeah, it can help you get around geoblocks or [region-based] censorship.
But here’s what it doesn’t do. It doesn’t make you anonymous. It doesn’t block trackers, fingerprinting, or device IDs. It doesn’t stop DNS leaks unless you’ve configured it to. It doesn’t stop apps from phoning home. It doesn’t delete your history or clean up your metadata. And it definitely doesn’t protect you from fishing, malware, or shady browser extensions.
So bottom line, a VPN is just one layer or tool. If you’re not combining it with hardened browsers, encrypted DNS, sandbox apps, and solid data hygiene, you’re not getting privacy.
[Is a VPN Right for You?]
Now, let’s take it one step further because sometimes using a VPN isn’t just ineffective, it might actually be the wrong move. If you care about true anonymity, if you’re a journalist, an activist, a dissident, under threat, you should not be relying on a VPN.
Here’s why. VPNs are centralized. That means logs can be subpoenaed. Even no-log providers might still collect connection metadata. The VPN endpoint knows your IP and maybe even your payment info. And you’re still wide open to fingerprinting and behavior-based tracking.
So if you’re trying to dodge surveillance capitalism, a VPN won’t save you. It won’t block Google or Facebook or the thousands of analytics libraries buried in your app. What you need is browser hardening, and a serious rethink of your entire device setup.
That said, VPNs can still be the right tool. It just depends on your situation. They’re genuinely useful when you’re on public Wi-Fi and want protection from man-in-the-middle attacks. If you’re trying to bypass school, work, or government firewalls, if you want access to blocked content like different Netflix regions or censored news, you don’t trust your ISP or your country’s network infrastructure, or you’re trying to reduce your tracking surface by masking your IP.
Yes, VPNs still have a place, but you’ve also got to know when to use them and which ones you can actually trust. So what should you demand from a VPN before you even consider it?
Here’s a checklist. If they don’t pass every single point, walk away.
• Full-scope third party audit, not just a no logs claim. I mean, the whole infrastructure, the clients, the servers, the logging policies. No audit means no trust.
• Transparent ownership. Can you trace who owns the company, where they’re based, who’s on the team? If not, assume they’re hiding something.
• Open-source [software] clients. If you can’t see what the software is doing on your machine, you can’t verify a single claim they’re making.
• Anonymous payment options. If they require a credit card or PayPal, they’re tying your identity to your usage. Cash, Monero, crypto, or nothing.
• No connection metadata. No logs should mean no logs at all. that includes timestamps, bandwidth, and session IDs. If they keep any of it, it’s a red flag.
• Privacy first features like kill switches, DNS leak protections, WireGuard support, Tor bridge or multihop routing, and custom DNS resolver support.
• And finally, it must be paid. No exceptions. If you’re not paying for the product, you are the product. And if any of that is missing, that’s not a privacy tool. That is spyware.
[Some ‘Good’ VPN Companies]
Which VPNs have actually earned the security community’s trust? These are the few providers that meet the bar, just what the security community actually respects.
First, we have Mullvad. It’s based in Sweden, no email required, and accepts cash by mail. It’s fully audited and has open- source clients. It offers Tor bridge support, and it is best for privacy-maxed users who don’t want to hand over any identity whatsoever.
Next up, we have IVPN. It’s based in Gibraltar. They have transparent audits and team disclosures and they block ads and trackers at the network level. It has anonymous sign-up and crypto payments. This one is best for users who want privacy by default and strong ethics under the hood.
And third, we have ProtonVPN. It is based in Switzerland. They have transparent ownership, which is by the Proton Mail team. It’s audited and open source, and they have a generous free tier with no data caps.
But Switzerland may soon force VPNs to log metadata. However, Proton has said that they’ll relocate if the law passes, and they’ve started moving their infrastructure. It is best for beginners who want a trustworthy, non-predatory VPN that they can grow with.
These aren’t perfect tools, but they are trustable and in a space where most others are built to extract, mislead, and exploit.
[Security Beyond VPNs]
So what should you use instead or alongside a VPN? Most people treat VPNs like the holy grail of privacy, but in 2025, they’re often the least important part of your setup. Because what actually makes you trackable usually has nothing to do with your IP address. It’s your browser, your behavior, your DNS traffic, your apps, your device ID. A VPN doesn’t touch any of that.
If you actually want to reduce your exposure, you need layers. And these tools do more for your privacy than any sponsored VPN ever will.
• First, we have DNS over HTTPS or DOH. Let’s start with what almost nobody configures, DNS. Every time you visit a website, your computer makes a DNS request asking where is the site located. By default, those requests are plain text. Meaning, your internet service provider or ISP and anyone else on the network can see everything you try and visit, even with HTTPS. Even with a VPN, unless your VPN encrypts DNS too.
DNS over HTTPS fixes that. It encrypts your DNS lookups and sends them through a trusted resolver like NextDNS, Cloudflare, or Controlled. You can even self-host if you’re advanced.
If your goal is to stop your ISP from tracking your browsing, DoH handles it cleanly without rerouting all of your traffic through a VPN provider that you don’t even know.
• Next, we have Tor browser. Tor reroutes your traffic through three relays, so no single point sees both who you are and where you’re going. It’s a powerful tool, but it’s not a magic cloak. It’s not true anonymity, and using it wrong breaks it fast. If you log into a personal account on Tor, you’ve linked your identity. If you act like it’s a normal browser by opening tabs, resizing windows, watching YouTube with your account logged in, you fingerprint yourself.
Tor is best when used carefully with no personal login, and a tight understanding of threat modeling. For high-risk situations where you need to reduce visibility, it works. But if you don’t need that level of obfuscation, skip it. You’ll just slow things down and expose yourself anyway.
• Next we have hardened Firefox. Most privacy leaks happen in the browser, not in the network. So start with using Firefox. Install uBlock Origin, disable Web RTC, kill telemetry, use container tabs, and now your browser isn’t leaking fingerprints, system info, or third party cookies every time you load a page. You’re already miles ahead of most people using a VPN alone.
• Browser isolation. If you’re using one browser for everything from banking, crypto, work, and research, then you’re fully linkable even with a VPN.
So, split your activity. Put crypto in one browser, personal accounts in another, work in a container tab or a virtual machine, and research in a hardened setup. Compartmentalization breaks the cross connections that adtech depends on. Even if one part gets exposed, the rest of your identity stays sealed.
• And self-hosted VPN. If all you want is encrypted traffic on public Wi-Fi, you don’t need to rent that tunnel from a shady provider. Spin up your own WireGuard VPN on a $5 virtual private server and now you control the endpoint without any mystery logs or surveillance as a service or middlemen. It won’t make you anonymous, but it will protect you from sketchy routers, firewalls, and lazy ISPs.
The bottom line is that a VPN is just one layer, and for most people, it’s not even the most important one. HTTPS encrypts your actual web traffic. DNS over HTTPS hides your DNS lookups. uBlock and hardened Firefox destroys trackers. And Tor, when used correctly, offers obfuscation, not invisibility. Browser isolation breaks profiling. And self-hosted VPNs let you route traffic without selling yourself out.
[Summary]
So if you’re only asking, “Which VPN should I buy?” you’re asking the wrong question.
It’s not just that VPNs could watch you. Some were made for that. And the people who are paid to tell you they were safe rarely checked if that was true. Companies hid behind shell firms. Creators repeated talking points, and privacy became something you bought, not something you understood.
You weren’t protected. You were sold to. And if that works on you, that’s because it was designed to.



If the VPN uses the tor network get away. As the tor network was created by the u.s. navy. It's nodes operated by naval intelligence.
Look it up.
If the VPN uses the tor network get away. As the tor network was created by the u.s. navy. It's nodes operated by naval intelligence.
Look it up.