Researchers find secret ties and vulnerabilities in popular VPN apps

VPN apps with more than 700 million users combined were revealed to be a part of the same overlapping ownership groups.
 By 
Chance Townsend
 on 
A VPN logo
Credit: Jaap Arriens/NurPhoto via Getty Images

A new study has uncovered that more than 20 VPN apps on the Google Play Store share the same codebases and infrastructure, despite presenting themselves as independent services. Together, these apps account for 20 of the 100 most-downloaded VPNs on the platform, with a staggering 700 million users.

The findings raise serious questions about trust and transparency in an industry built on privacy — and highlight how poorly app stores may vet VPN providers.

The research, conducted by The Citizen Lab at the University of Toronto, traced these apps back to just three VPN families, some with ties to Russia and China. Investigators used business filings and forensic analysis of Android APKs to uncover the hidden connections.


You May Also Like

Recommended deals for you

Apple AirPods Pro 3 Noise Cancelling Heart Rate Wireless Earbuds $219.99 (List Price $249.00)

Apple iPad 11" 128GB Wi-Fi Retina Tablet (Blue, 2025 Release) $274.00 (List Price $349.00)

Amazon Fire HD 10 32GB Tablet (2023 Release, Black) $69.99 (List Price $139.99)

Sony WH-1000XM5 Wireless Noise Canceling Headphones $248.00 (List Price $399.99)

Blink Outdoor 4 1080p Security Camera (5-Pack) $159.99 (List Price $399.99)

Fire TV Stick 4K Streaming Device With Remote (2023 Model) $24.99 (List Price $49.99)

Shark AV2511AE AI Robot Vacuum With XL Self-Empty Base $249.99 (List Price $599.00)

Apple Watch Series 11 (GPS, 42mm, S/M Black Sport Band) $339.00 (List Price $399.00)

WD 6TB My Passport USB 3.0 Portable External Hard Drive $138.65 (List Price $179.99)

Dell 14 Premium Intel Ultra 7 512GB SSD 16GB RAM 2K Laptop $999.99 (List Price $1549.99)

Products available for purchase through affiliate links. If you buy something through links on our site, Mashable may earn an affiliate commission.

Family A was tied to Innovative Connecting, Autumn Breeze, and Lemon Clove, and included major players like Turbo VPN, VPN Proxy Master, and Snap VPN — all of which shared identical code and assets. Family B, linked to Matrix Mobile, ForeRaya Technology, and Wildlook Tech, operated XY VPN, 3X VPN, and Melon VPN, which used the same VPN addresses. Family C, made up of Fast Potato and Free Connected Limited, controlled Fast Potato VPN and X-VPN.

Beyond a lack of transparency, the study also found serious security flaws. Some apps reused login credentials for ShadowSocks, a tool for bypassing firewalls. Others relied on outdated encryption algorithms, leaving users more exposed. Most concerning of all, all three VPN families were vulnerable to blind on-path attacks — meaning hackers on the same network, such as public Wi-Fi, could intercept traffic without either party realizing it.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

The researchers noted that app stores have limited ability to verify who operates a VPN or how it’s built, since their review systems are largely focused on malware detection and privacy violations. As a remedy, they suggested introducing a security audit badge for VPNs — a certification that could give users more confidence in the apps they choose.

The specifics of Google’s app review process remain unclear. According to a support page, developers must provide a privacy policy, disclose whether the app contains ads, obtain a content rating, and share the app’s privacy and security practices with Google in order to pass review.

In a statement to Mashable through email, a Google spokesperson said that the company is committed to "compliance with applicable sanctions and trade compliance laws."

"When we locate accounts that may violate these laws, our related policies or Terms of Service, we take appropriate action."

UPDATE: Sep. 2, 2025, 3:17 p.m. EDT This article has been updated to include a statement from Google.

Headshot of a Black man
Chance Townsend
Assistant Editor, General Assignments

Chance Townsend is the General Assignments Editor at Mashable, covering tech, video games, dating apps, digital culture, and whatever else comes his way. He has a Master's in Journalism from the University of North Texas and is a proud orange cat father. His writing has also appeared in PC Mag and Mother Jones.

In his free time, he cooks, loves to sleep, and greatly enjoys Detroit sports. If you have any tips or want to talk shop about the Lions, you can reach out to him on Bluesky @offbrandchance.bsky.social or by email at [email protected].

Mashable Potato

Recommended For You
Black Friday streaming steal: Score 12 months of this streaming-friendly VPN for under £25
Phone in hand


Grokipedia sourcing info from the internet's biggest neo-Nazi forum, researchers say
The Grokipedia logo reflected off a phone screen.

Why artists are leaving Spotify — and how you can, too
Spotify logo is pictured at the 77th Frankfurt book fair, the world's biggest trade fair for books, in Frankfurt am Main, western Germany on October 17, 2025. The 77th Frankfurt book fair runs from October 15 to 19, 2025 with the Philippines as guest of honour.

Ditch your VPN subscription for this plug-and-play privacy box
Deeper Connect Air Portable Decentralized VPN Travel Router

Trending on Mashable
Streaming just got cheaper: Black Friday deals still live on Hulu, HBO Max, Apple TV, Disney+, and more
Disney+, Hulu, HBO Max, Peacock, and Prime Video logos with colorful background and black friday icon

NYT Connections hints today: Clues, answers for November 29, 2025
Connections game on a smartphone

Wordle today: Answer, hints for November 29, 2025
Wordle game on a smartphone

The 23 best Black Friday PlayStation game deals still live (updated)
helldivers II, clair obscur, and silent hill f on pink background

Home Depot is still giving away free cordless tools for Black Friday — See BOGO offers on DeWalt, Ryobi, Milwaukee,
Dewalt and Ryobi power tools arranged on pink and brown backdrop
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!