Cheap VPNs to Avoid: When the Deal Is the Product
Cheap is not the problem. Legitimate budget VPNs exist and are genuinely good value — several are recommended elsewhere on this site. The problem is a specific category of "deal" where the low price is not a discount on the product; the product's real business is something else entirely, and the VPN is the bait. This article names the documented, factual patterns worth avoiding — sourced from independent research, not speculation — and points to budget options that are actually just VPNs.
Pattern 1: Free VPN apps that monetize your traffic
This is the best-documented category, with multiple independent incidents on the public record:
- Hola VPN was confirmed, by its own admission, to route users' bandwidth and IP addresses through a sister commercial service (originally branded Luminati, now Bright Data), effectively turning free users into exit nodes sold to paying clients — including, in one widely reported case, use in a coordinated attack traced back to an unwitting Hola user's connection.
- SuperVPN, GeckoVPN, and ChatVPN — combined tens of millions of downloads — were the source of a 2021 breach exposing around 21 million user records, traced to unsecured backend databases.
- Betternet was identified by CSIRO research as carrying the highest number of third-party tracking libraries among studied free VPN apps.
- Onavo Protect, Facebook's free VPN, was removed from both major app stores after it emerged the app was being used to harvest competitive usage data on users' other apps.
The mechanism is consistent across all of them: running a VPN costs real money in servers and bandwidth, a free app has to fund that somehow, and "selling access to user data or user bandwidth" is the business model that pays for "free."
Pattern 2: Android VPN apps carrying malware
Independent academic research (the CSIRO study analyzing 283 Android VPN apps) found that a substantial share contained malware components — adware, trojan functionality, or spyware — bundled inside apps explicitly marketed as privacy and security tools. This is not a fringe result; it is peer-reviewed analysis of apps that were live on major app stores. The takeaway is not "avoid all free VPNs blindly" but "avoid free VPN apps from unfamiliar developers with no independent audit history," which is most of them.
Pattern 3: The lifetime-deal vendor that disappears
Covered in depth in our lifetime-deal guide: budget VPN vendors selling one-time "lifetime" access have a documented failure pattern — roughly 40% of lifetime software deals across marketplaces fail to survive three years, through shutdown, acquisition, or unilateral downgrade. One VPN's new owners publicly stated they had not known about thousands of outstanding lifetime subscriptions when they acquired the company, and chose not to honor them. That case is worth sitting with for a moment: the buyers did nothing wrong at the point of purchase, followed every reasonable precaution available to them at the time, and still ended up with a worthless subscription years later purely because ownership changed hands. It illustrates why "lifetime" pricing carries a structural risk that a low sticker price cannot offset, no matter how carefully the original deal was vetted.
What does NOT belong on this list
It matters to be precise, because "cheap VPN" gets unfairly lumped with "sketchy VPN" constantly. Legitimate budget-tier paid providers — the kind charging a low monthly-equivalent on a long-term plan, not zero — run real infrastructure, publish real privacy policies, and in several cases have passed independent no-logs audits. Low price alone is not the signal; the business model behind the price is.
The actual red flags, distilled
| Red flag | Why it matters |
|---|---|
| Permanently free, unfamiliar developer, no paid tier | No visible revenue model other than your data |
| "Lifetime" access from a small or new vendor | ~40% documented 3-year failure rate; store-credit-only refunds |
| No published privacy policy, or one that permits broad data sharing | The terms often disclose the monetization plainly, if you read them |
| Android app with excessive permissions (contacts, files) for a VPN | Correlates with the malware-bundling pattern CSIRO documented |
| No independent audit, no company transparency (physical address, ownership) | No accountability if something goes wrong |
Why "you get what you pay for" isn't quite right either
It would be tidy to conclude that price simply correlates with trustworthiness, but that overstates the case. Several respected, independently audited providers sell budget-tier long-term plans at prices not far above the "too good to be true" range this article warns about — the differentiator is not the price point itself but the business model behind it. A subscription-funded provider charging a low monthly-equivalent on a 2-year term is economically ordinary: acquire customers cheaply, retain them, monetize through the subscription itself. A permanently-free app with no paid tier at all has no equivalent explanation available, which is precisely why "free" is a sharper warning signal than "cheap."
Budget picks that are just VPNs
Skip the traffic-selling free apps entirely and put a couple of dollars a month toward a provider whose business model is subscriptions, not your data:
- Surfshark — unlimited devices, budget-tier long-term pricing, and a subscription-funded business model with no ad-injection or traffic-selling.
- PrivateVPN — straightforward budget long-term plans with a conventional money-back guarantee.
- VeePN — low-cost multi-year pricing for basic, no-frills protection.
All three cost a small fraction of what "free" apps quietly extract from you — the difference is you can see exactly what you're paying, instead of discovering it later.
How to vet any VPN before you trust it, cheap or not
The patterns above are specific documented cases, but the underlying evaluation method generalizes to any provider, budget or premium, familiar or new. Five checks catch the overwhelming majority of problems before you ever install an app:
- Find the business model in plain language. A legitimate provider's own site should say, without needing to be inferred, that it makes money from subscriptions. If a "free forever" service cannot explain in its own FAQ how it pays for servers, that silence is itself the answer.
- Look for an independent no-logs audit. Several major providers have commissioned third-party security firms to verify their no-logging claims, with published results. A provider that has never been independently audited is not automatically untrustworthy, but it is asking you to take its privacy claims entirely on faith.
- Check company transparency. A real registered business address, named leadership or at least a verifiable corporate entity, and a history that predates last month are all basic signals a provider is not a fly-by-night operation designed to collect a few months of subscription revenue and vanish.
- Read the actual privacy policy, not just the marketing page. Free and cheap providers alike sometimes disclose data-sharing practices plainly in the legal text even while marketing "100% private" on the homepage. The terms document is where the real answer usually lives.
- Search the provider's name alongside terms like "breach," "lawsuit," or "data sold" before committing. This single search surfaces the majority of documented problems in minutes, as demonstrated by every incident cited earlier in this article — all of which are a search away from anyone who thought to look.
None of these checks take more than a few minutes combined, and running them before signing up — rather than after something goes wrong — is the entire difference between the documented failures above and a genuinely good budget choice. Bookmark this five-point list and reuse it every time a new "amazing free VPN" or rock-bottom budget deal crosses your feed — the specific incidents named in this article will eventually age out of relevance, but the evaluation method will not.
Ready to grab a better deal?
Every provider below backs new sign-ups with a real money-back window, so you can test your replacement before your old plan even expires.
Frequently Asked Questions
Are free VPN apps actually dangerous, or is that overstated?
It's well documented, not overstated. Independent incidents include Hola VPN's confirmed use of user bandwidth as a commercial exit-node network, a 2021 breach exposing roughly 21 million SuperVPN/GeckoVPN/ChatVPN user records, and academic research finding malware components in a substantial share of studied Android VPN apps.
Is every cheap VPN a scam?
No — legitimate budget-tier paid providers run real infrastructure and, in several cases, have passed independent no-logs audits. The risk pattern is specifically permanently-free apps with no visible revenue model and small unaudited vendors selling one-time 'lifetime' access.
What happened with Hola VPN specifically?
Hola confirmed that free users' bandwidth and IP addresses were routed through a commercial sister service (Luminati/Bright Data) and sold to paying clients, effectively making free users unwitting exit nodes — in one widely reported case, linked to a cyberattack traced back to an uninvolved user's connection.
What's a trustworthy cheap alternative to a free VPN?
A budget-tier paid provider on a long-term promotional plan — Surfshark, PrivateVPN, or VeePN all deliver real subscription-funded service in the low single-dollar monthly range, with none of the documented data-selling or malware patterns tied to permanently-free apps.