Google issues security alert about malicious VPNs stealing user data
The holidays are almost upon us, and Google is giving us some security advice as a gift.
In a wide-ranging fraud and scam advisory blog post on its website, Google warned users of a number things, including malicious VPNs. According to Google, there are bad-faith actors disguising their software as legitimate VPNs for users who feel they might need such a thing. Anyone who downloads one of these might be subject to data theft (or worse). Google did not name any specific examples of VPNs you shouldn't mess with, however.
While it was light on specifics, Google did offer some advice that should help keep you safe.
You May Also Like
Apple AirPods Pro 3 Noise Cancelling Heart Rate Wireless Earbuds — $219.99 (List Price $249.00)
Apple iPad 11" 128GB Wi-Fi Retina Tablet (Blue, 2025 Release) — $274.00 (List Price $349.00)
Amazon Fire HD 10 32GB Tablet (2023 Release, Black) — $69.99 (List Price $139.99)
Sony WH-1000XM5 Wireless Noise Canceling Headphones — $248.00 (List Price $399.99)
Blink Outdoor 4 1080p Security Camera (5-Pack) — $159.99 (List Price $399.99)
Fire TV Stick 4K Streaming Device With Remote (2023 Model) — $24.99 (List Price $49.99)
Shark AV2511AE AI Robot Vacuum With XL Self-Empty Base — $249.99 (List Price $599.00)
Apple Watch Series 11 (GPS, 42mm, S/M Black Sport Band) — $339.00 (List Price $399.00)
WD 6TB My Passport USB 3.0 Portable External Hard Drive — $138.65 (List Price $179.99)
Dell 14 Premium Intel Ultra 7 512GB SSD 16GB RAM 2K Laptop — $999.99 (List Price $1549.99)
"Only download VPN apps from official sources, and check for apps with the VPN badge in Google Play. Be skeptical of free offers and avoid sideloading unknown apps," Google wrote. "Users should look carefully at the app's requested permissions — a VPN should not need access to things like your contacts or private messages. Always pay attention to browser download warnings and keep your antivirus software enabled."
In other words, don't sideload strange apps onto your Android device if you don't know where it's coming from. If you're getting something from the Play Store, there should be a verification badge letting you know it's OK to use. Follow this advice and you should have an easier time avoiding serious problems this holiday season.
Topics Android Cybersecurity Google
Alex Perry is a tech reporter at Mashable who primarily covers video games and consumer tech. Alex has spent most of the last decade reviewing games, smartphones, headphones, and laptops, and he doesn’t plan on stopping anytime soon. He is also a Pisces, a cat lover, and a Kansas City sports fan. Alex can be found on Bluesky at yelix.bsky.social.