The VPN business: what they cost, what they promise, and what they actually do Transcript of the narrated version (25 min). Narrated with a synthetic voice (Larry). The writing is Esteban Rey's — kilowatto.com. --- The VPN business: what they cost, what they promise, and what they actually do. A few weeks ago, I checked my credit card statement and found a charge I didn't recognize: $107 from a VPN I had signed up for two years ago for $2.19 a month. At first, I thought it was a billing error. It wasn't. It was the auto-renewal price, the one the same company that sold me traffic privacy never put in big letters. I wasn't the only one surprised. An analysis of almost 30,000 Android reviews of the four largest providers, NordVPN, ExpressVPN, Surfshark, and Proton VPN, found that complaints about auto-renewals and price hikes dominate the negative reviews, according to TechRadar in 2026. And NordVPN is already facing four lawsuits in US federal courts over renewal practices that the plaintiffs call deceptive, also reported by TechRadar in 2026. That was the hook that made me open the whole box: how true is everything else that this $70 to $80 billion a year industry promises, as reported by VPNpro in 2026. I spent several weeks reviewing audits, lawsuits, academic papers, and even the source code of free apps. This is what I found. The owner of your VPN also owns the site that tells you which one to buy. Let's start with what almost nobody looks at: who really owns the brand you see sponsored on YouTube. ExpressVPN, CyberGhost, Private Internet Access, and ZenMate all belong to the same group: Kape Technologies, a company listed in London and controlled by Israeli-British businessman Teddy Sagi, according to Wikipedia and corporate records as of 2026. Kape was called Crossrider until 2018, when it was renamed after years of operating as an adware distributor, as reported by CyberInsider in 2024. Kape's own CEO has acknowledged in interviews that the name change was meant to distance itself from past activities, also reported by CyberInsider in 2024. That would already be an uncomfortable footnote. What makes it relevant to you as a consumer is the second part: several investigations by specialized media have documented that Kape also controls independent VPN review sites that systematically rank its own brands first, as found by PrivacyProof and VPN Testing Research Lab in 2026. It's not illegal, as no law requires a review site to disclose its owner, but it's the reason why, when a YouTuber says I compared all the VPNs and this one won, it's worth asking who funded the comparison. NordVPN and Surfshark have a different transparency issue, although it's less severe: since their 2022 merger, they belong to the same group, Nord Security, with operational headquarters in Lithuania and a corporate structure that includes entities in Panama, as reported by Jazod in 2026. Nord Security reports annual recurring revenue of around 357 million dollars and a valuation close to 3 billion dollars, according to Latka in 2025, and its founders, unlike Kape, are public and verifiable: Tomas Okmanas and Eimantas Sabaliauskas, who built the company without external capital for a decade before receiving their first investment rounds in 2022, as reported by Sifted in 2024. On the other end of the spectrum are Proton VPN, linked to the Swiss foundation behind Proton Mail, and Mullvad, a Swedish company whose founders are public and deliberately refuse to ask for an email address to sign up, as reported by Shielded Browsing in 2026. The details of the ownership structure of these companies are noteworthy, with Kape Technologies owning several VPN brands and review sites, while Nord Security and other companies have different ownership structures and levels of transparency. How much a VPN pays a YouTuber (and why some no longer accept the check). Before diving into the technical aspects, it's worth understanding why you see so many VPN ads in the same video: the tech niche pays between $30 and $60 CPM, one of the highest on the platform after finance, according to SponsorRadar in 2026. A mid-sized channel with 200,000 views per video can charge between $6,000 and $12,000 for a single sponsored VPN integration; large channels negotiate five-figure sums per video, also according to SponsorRadar in 2026. The cost per thousand views for the tech niche is one of the highest, with details available from SponsorRadar in 2026. This money has generated an uncomfortable debate within the tech community itself. British tech personality Tom Scott posted a video, now a reference point, debunking the typical claims made in VPN sponsorship scripts, starting with the most repeated one: that without a VPN, an attacker can steal your password on any public network, something that HTTPS encryption has made unnecessary on most sites for years, as noted by Tom Scott in 2019, and cited on the Linus Tech Tips forum. Linus Tech Tips, the largest tech channel in its category, stopped accepting VPN sponsorships for years due to the same reasons before announcing in 2024 that it would reconsider on a case-by-case basis, as recorded in an episode of LTT in 2024. This is a telling sign: if the creators who get paid to promote VPNs doubt the scripts they're given, the end consumer has plenty of reasons to review the fine print. "No-logs" audits: what has changed (and what still can't be proven). This is where the industry has genuinely improved. Ten years ago, "we don't keep logs" was a marketing phrase with no substance behind it. Today, NordVPN, ExpressVPN, Surfshark, Proton VPN, Mullvad, and PIA have all undergone repeated audits by serious firms: PwC, Deloitte, KPMG, and the German penetration testing firm Cure53 VPN Vertex, 2026. ExpressVPN, for example, published its third consecutive KPMG audit on its TrustedServer architecture in 2025, which runs entirely in RAM and is wiped on each restart. Proton VPN, being open-source, adds to its annual Securitum audits a continuous public review of its code by the community, according to VPN Vertex, 2026. But "audited" doesn't mean "infalible," and this is where the reader's skepticism is justified. These audits certify an architecture and a point in time, not an eternal promise. The textbook example is PureVPN: in 2017, its privacy policy stated that it didn't keep any logs. When the FBI investigated a cyberstalking case, PureVPN provided connection timestamps that, when cross-referenced with other data, helped identify the suspect, as documented by the FBI and cited by CyberInsider, 2026. They didn't provide browsing history – technically, it was true they didn't keep that – but they did keep more than their policy promised. Similar cases have been documented with HideMyAss, according to CyberInsider, 2026. NordVPN had its own moment of truth in 2018, when an attacker compromised one of its over 3,000 servers in a Finnish data center, exploiting a remote management system that the data center provider had left insecure, as stated in NordVPN's official statement, 2019. The company took over a year to publicly disclose the incident after discovering it, which generated legitimate criticism about transparency, although external investigators agreed that there was no evidence of user activity being leaked, as reported by IT Pro, 2019. Following the incident, NordVPN migrated its entire infrastructure to servers operating exclusively in RAM and increased its annual audits, according to NordVPN, 2019. The honest lesson here is not "don't trust any audited VPN." It's that an audit reduces the risk of deliberate dishonesty but doesn't eliminate the risk of a failed technical implementation or a leak due to a poorly secured third party. 2026 audits are a reasonable minimum baseline for choosing a provider – not a guarantee of invulnerability. Details of scandals, settlements, and lawsuits are available, showing the timeline of these events. The free ones: the business where you are the inventory. If paying $2 a month for an audited VPN already has fine print, free ones are a whole different story. An academic study presented at the NDSS 2026 symposium by researchers from the University of Michigan, the University of New Mexico, and IIT Delhi analyzed 281 free Android VPN apps and found traffic leaks, unencrypted configurations, and active tracking libraries in a significant portion of them. The study was cited by The Hacker News, referencing the NDSS paper from 2026. A separate investigation by Top10VPN into 100 free Android apps found that half of them sent data to third parties like ByteDance and Yandex, and that a majority requested permissions, such as scanning what other apps you have installed or accessing your location, that have no legitimate function within a VPN. This was cited by Axis Intelligence in 2026, referencing Top10VPN's investigation. The most cited case of an "inverted business model" is Hola VPN, whose free version turned each user's device into an exit node for a commercial residential proxy network called Luminati, now known as Bright Data, which the same company sold to third parties. This was reported by Newsweek, citing research from Trend Micro in 2018. In practice, your internet connection could be used by a Luminati client anywhere in the world, including, as documented by Trend Micro's research, actors who abused the network to try to access stolen email accounts, as cited by Cyware in 2020. Hola's founder, when asked if users knew how their bandwidth was being used, replied that most "don't care", according to CISO Mag in 2019. Not even Facebook was immune to this pattern. Its Onavo Protect app was marketed as a VPN to protect personal data, but in reality, it fed Facebook with metrics on which apps you used, how long, and what sites you visited, information the company used, among other things, to detect WhatsApp's growth before acquiring it, as reported by TechCrunch in 2019. Apple expelled Onavo's "research" version from its store for violating enterprise certificate rules, and Facebook eventually shut down the service altogether in 2019, also reported by TechCrunch. Then there's Hotspot Shield, whose case illustrates the regulatory mechanism that does exist, albeit slowly. In 2017, the Center for Democracy and Technology filed a formal complaint with the US Federal Trade Commission, documenting that Hotspot Shield's free version redirected e-commerce traffic to partner domains and shared device identifiers with ad networks, despite advertising "guaranteed privacy". Not all free VPNs are a scam. Proton VPN Free, with no data limit, although with fewer servers, and Windscribe Free operate under the same audited infrastructure as their paid versions and are the documented exception within a market that, as a whole, remains a minefield, according to TrustMyIP in 2026. Opera: the "free VPN" that's actually a browser proxy. If you use Opera or Opera GX, you're likely affected by a myth that their built-in free VPN isn't, technically, a VPN. What Opera calls Free VPN is a proxy that only encrypts traffic passing through the Opera browser, using the standard HTTPS/TLS protocol, the same one used by any secure website, instead of a real VPN tunnel protocol like OpenVPN or WireGuard, as noted by Top10VPN in 2026. This means your email client, desktop apps, torrent client, or even another browser you have open simultaneously receive no protection, only what happens within the Opera window, according to PrivacySavvy in 2026. Multiple technical reviewers agree that it's literally a VPN in name only, as stated by Cybernews in 2024. Opera itself is transparent in its technical description, if you read the fine print, but the problem is that the Free VPN label in the interface isn't, as stated on Opera's official page in 2026. It's worth noting that Opera has been owned by a consortium led by Chinese companies Kunlun Tech and Qihoo 360 since 2016. In 2020, the research firm Hindenburg Research accused Opera of operating short-term loan apps in Kenya, Nigeria, and India with effective annual interest rates of between 365% and 876%, far above what they publicly advertised, as reported by The Register in 2020. Opera called the report error-ridden and publicly rejected it, also reported by The Register in 2020, and the case essentially remained an unresolved dispute between the two parties, with no subsequent judicial resolution. Neither of these issues, the proxy nature of the free VPN or the dispute over loan apps, has a direct technical connection to the security of your browsing, but they are relevant if your reason for using Opera is privacy. Myths to debunk: invisibility, Google, and the free antivirus. Does it make you invisible? No. A VPN hides your real IP address and encrypts traffic between your device and the provider's server, which is real and valuable. However, it doesn't make you anonymous. Browser fingerprinting, a combination of screen resolution, installed fonts, time zone, browser version, and dozens of other variables, can identify your device with near-unique precision among hundreds of users. This method survives changing VPN servers, clearing cookies, or using incognito mode, as noted by Hackaday in 2025. Furthermore, if you log in to your Google, Facebook, or Netflix account while using the VPN, that company knows exactly who you are, regardless of what IP you're using that day, a limitation acknowledged by NordVPN in their blog in 2026. Does Google can't track you anymore? Only partially. A VPN hides your network location from Google, but not from Google-the-service if you're using an active Google account, nor from the cookies and tracking pixels that most sites still use regardless of your IP, according to Ghostery in 2026. Is the included antivirus useful or just marketing fluff? The answer is more nuanced than expected. NordVPN's threat blocking engine, Threat Protection Pro, was certified by AV-TEST, an independent German lab, with a malicious link detection rate of 83.4 percent, compared to 47 percent for the second-best competitor evaluated in the same test, as reported by TechRadar citing results from AV-TEST in 2025. In 2026, AV-Comparatives tests showed that it blocked up to 96 percent of active phishing URLs without false positives, according to NordVPN citing AV-Comparatives in 2026. However, it's essential to understand what it really is: a malicious domain and link blocker at the network level, not a traditional antivirus that scans files already downloaded to your disk for malicious behavior. It's a useful layer with real independent evidence behind it, but not a complete substitute for a dedicated antivirus. So, there are no logs, right? As we covered earlier, it entirely depends on the provider, whether they've been recently audited, and whether that audit covered what matters to you, not just marketing. Do you really need a VPN at Starbucks or the airport?. The claim that you should never connect to public Wi-Fi without a VPN, or they'll steal everything, is probably the most repeated sales claim in any sponsorship. However, reality is more boring and more reassuring than the marketing script suggests. The US Federal Trade Commission updated its public stance to acknowledge that the widespread adoption of HTTPS, the lock you see in the address bar, has made public Wi-Fi considerably safer than it was a decade ago, because it encrypts the connection content regardless of whether you use a VPN or not, as noted by the FTC, cited by TravlFi in 2025. According to a MakeUseOf analysis in 2026, you can be safe on coffee shop Wi-Fi without paying for a VPN, as long as you verify the site uses HTTPS before entering sensitive data. That doesn't mean the risk is zero. The US cybersecurity agency, CISA, still recommends using a VPN on networks you don't control when available, and so-called evil twin attacks, a fake access point that mimics the name of a legitimate network, are still real and can't be stopped by HTTPS alone, as noted by Le VPN in 2026. After reviewing both sides, it's clear that if you're going to do banking or enter sensitive info on a public network, a VPN is a reasonable extra layer; however, if you're just checking social media or reading news, the actual risk today is much lower than what VPN marketing wants you to believe. Netflix, Disney+, HBO Max: the silent war against VPNs. The mechanics at play here are purely business, not security. Netflix and other streaming platforms license content by country or region. A studio can sell the rights to a series to a different distributor in each market, and the contract requires the platform to block access from outside that region. When you use a VPN to appear in another country, you're not technically committing a crime in most jurisdictions, but you are violating the platform's terms of service, which can result in warnings or, in repeated cases, account suspension, depending on the service's policy. In practice, some premium VPNs, such as NordVPN, ExpressVPN, and Surfshark, are still winning the technical race against IP detection from these platforms, documenting active compatibility with Netflix, Disney+, Amazon Prime Video, and HBO Max in recent third-party tests. Free VPNs almost never achieve this consistently, except for limited exceptions like Proton VPN Free or Windscribe on a handful of servers. These sources come mostly from review sites with affiliate models, which presents the same incentive problem, so they should be treated as a general guide, not a guarantee. In practice, the worst usual scenario for using a VPN is an error message or a proxy detected screen that forces you to switch servers. Permanent account suspensions for this specific reason are extremely rare. However, there are real legal consequences in a handful of countries, including China, Russia, Iran, and the United Arab Emirates, which restrict or ban the use of unauthorized VPNs, with fines that in the Emirati case can reach two million dirhams. For the rest of the world, including Mexico and virtually all of Latin America, using a VPN is completely legal. What's still illegal is what you do with it, whether you use a VPN or not. Cheaper plane tickets with VPN? The myth that turned out to be half a myth. This is, of all the promises investigated, the one with the most contradictory evidence, and that's why it's worth explaining carefully instead of giving a false yes or no. On the skeptical side, Business Insider tested booking flights with five different VPNs on multiple routes and found no difference in price, as cited by The Traveler in 2025. A Yale economist who studied airline pricing algorithms concluded that prices respond to demand, seat availability, and time until departure, not cookies or your IP address, according to research cited by DevRunners in 2026. Consumer Reports found in their own analysis that 88 percent of flights showed the same price in incognito mode as in normal mode, as cited by DevRunners in 2026. On the other side, there is a real phenomenon that's distinct and has nothing to do with tracking, but rather with price discrimination by point of sale. Some airlines and booking platforms set different prices based on the country where the purchase is made, due to local purchasing power and regional competition, and in some cases, a VPN can show a different rate, as reported by Dollar Flight Club in 2025. An independent test found real but inconsistent savings when comparing prices from different countries, with Mexico and Vietnam among the cheapest origins in that specific experiment, although the authors themselves warn that results vary by route and moment, as shown in a travel blog in a specific instance in December, which was not repeated over time. Additionally, several airlines already detect and block attempts to book via VPN, and there are reports of bookings being canceled by anti-fraud systems when they detect a discrepancy between the country of the card and the point of sale, as reported by The Traveler in 2025. The myth that Google raises the price because it saw you search for the flight twice is pretty well debunked. The phenomenon of different prices by country does exist, but it's inconsistent, depends on the route, and comes with a real risk of having your booking canceled. It's not the goldmine that marketing promises, but it's not pure fantasy either. The real price: what you pay first and what you pay later. The pattern of a super low entry price for a two-year plan, then silent renewal at list price, is not exclusive to one brand, it's practically the standard model for the industry. NordVPN, for example, offers promotional plans from $2.19 to $3.09 per month for two-year commitments, but its regular monthly rate without a discount is around $11.95, according to TomsGuide's historical price data from 2026. If you leave auto-renewal on, you pay the full list price, not the promotional one, a difference of up to four times, as documented by TechRadar in its coverage of the lawsuits against NordVPN in 2026. The details of the advertised price versus the actual renewal price on a monthly basis show that there is a significant difference. For readers in Mexico, this matters twice, as most of these prices are quoted and charged in dollars, so the exchange rate variation adds to the renewal blow. Additionally, almost no Spanish-language price comparator, such as VPNExperto and ClavesLADA, is independent, as they work with affiliate links that only generate commissions if you buy, which presents the same underlying conflict of interest already seen with English reviews, as noted in VPNExperto's own transparency note from 2026. Mullvad is the notable exception to this pattern, as it charges a flat rate of 5 euros per month, with no promotional tiers, no renewal trap, and without even asking for an email, instead giving you a randomly generated account number and accepting cash payment by postal mail for those who want maximum anonymity, as reported by Shattered.io in 2026, making it literally the most honest pricing model in the entire sector that has been documented. So, which ones are worth it?. If you want a balance between ease of use, streaming unblocking, and audited security, NordVPN, ExpressVPN, Surfshark, and Proton VPN reasonably deliver what they promise on the technical side, but it is advisable to cancel auto-renewal the day you subscribe and set an alarm to decide manually each year. If your priority is real anonymity above all else and you don't mind sacrificing streaming, Mullvad is today the most honest option in the market, with a fixed price and truly anonymous registration, as noted by iFeelTech in a technical comparison in 2026. If your budget is zero, Proton VPN Free or Windscribe Free are the only free ones that run on the same audited infrastructure as their paid versions, according to TrustMyIP in 2026, and it is recommended to avoid any other free VPN without public auditing, without exception. Additionally, if you use Opera expecting real privacy, it is essential to understand that its free VPN only protects the browser, not your entire device. It is also important to note that any free VPN without a recognizable name, clear privacy policy, and publicly verifiable audit should be treated as suspicious by definition. These are often the kind that shows up on the first page of an app store promising unlimited free speed forever without explaining how they pay for their servers. If they're not charging you money, someone else is paying to access something of yours, and in this industry, that something is almost always your traffic, metadata, or bandwidth. No VPN makes you invisible, no VPN replaces common sense on public networks, and no VPN will consistently get you cheaper flights. But chosen well, a VPN does encrypt your traffic from your internet provider, gives you real control over your apparent location, and is worth its price, the list price, not the welcome offer price.