South Africa recorded over 32 million malware incidents in 2024, the highest on the continent, according to research by NordVPN published in February 2025. A large share of that came through apps people downloaded deliberately, believing they were getting protection. Free VPN apps are one of the primary delivery vehicles, and most people who have one installed have no idea what it is actually doing in the background.
What a VPN is supposed to do, and what free ones often do instead
A VPN, or Virtual Private Network, encrypts the traffic leaving your device and routes it through a server elsewhere, so that websites and networks cannot read your data or trace it back to your IP address. It is a legitimate and widely used privacy tool. The problem is not VPNs as a category. The problem is that running VPN infrastructure costs real money: servers, bandwidth, staff, security audits. A provider who charges nothing for that service has to recover the cost somewhere, and the somewhere is almost always you.
Research by VPNRanks, cited by Tom's Guide, found that 60% of popular free VPNs had suspicious links to China, and predicted that by 2025 up to 80% of free VPNs would embed tracking features, with data sales to third parties reaching 60%. That means the app you downloaded to stop people reading your browsing history may be selling your browsing history to advertisers, data brokers, or anyone else willing to pay for it. The encryption is real. The privacy is not.
At the worse end of the spectrum, the app is not just selling your data. It is renting out your device.
The botnet problem: when your phone joins the attack
In May 2024, US law enforcement dismantled what investigators described as the largest botnet ever recorded, counting 19 million unique IP addresses across more than 190 countries. The infrastructure was built almost entirely through free VPN apps: at least 18 of them, including MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN, and ShineVPN, all available on app stores at the time of download (Kaspersky, 2024, reported by TechRadar). Every person who installed one of those apps had their device silently enrolled as a proxy server. Other people's traffic routed through their connection. The infected servers were later sold to other threat actors for ransomware staging, money laundering, and large-scale fraud.
This is not a new pattern. Hola VPN, which reached nearly 50 million users worldwide, was exposed in 2015 for doing exactly this. The service routed paid customers' traffic through its free users' connections without telling them. Security firm Trend Micro later confirmed that the traffic was not encrypted at all; free Hola users were running an unencrypted proxy, not a VPN, and their home IP addresses were being sold through a sister company called Luminati to businesses and criminals alike. The administrator of the message board 8chan went public after a botnet using Hola's network attacked his site. That is how it came to light. Most people who had Hola installed never found out.
The First VPN service dismantled this week in Operation Saffron (19-20 May 2026) was a different category: a criminal-only anonymisation service marketed on Russian-language forums, used by at least 25 ransomware groups including Avaddon to hide reconnaissance, intrusions, and command infrastructure from investigators. Europol described it as deeply embedded in the cybercrime ecosystem. That is a tool built for criminals. The more relevant question for most people in KZN is the one sitting in their app drawer: the free VPN they downloaded to watch something geo-blocked, or because a friend recommended it, or because a YouTube ad made it look like a good idea.
Why this hits differently for South African businesses
If you run a small to medium business in South Africa, there is a reasonable chance that someone on your team has a free VPN installed on their phone or laptop, and that device connects to your business email, your accounting software, or your shared drives. Under POPIA (the Protection of Personal Information Act), if you process your clients' personal information on a device that is routing that data through a third-party provider you have not vetted, you may already have a compliance gap. POPIA requires that you apply reasonable safeguards to the personal information you hold and that any operator you use to process that information meets the same standard. A free VPN running on a staff device that is harvesting session data does not meet that standard, and the obligation to know about it sits with you, not the app developer.
The POPIA angle aside, the operational risk is simpler: a device enrolled in a botnet without the owner's knowledge is a device that threat actors can use to probe your network, log your traffic, and test credentials against your accounts, all from an IP address that looks like it belongs to your own staff.
What to do this week
- Check what VPN apps are installed across your team's devices. Ask, or look. If anyone is running a free VPN with no verifiable privacy policy, a name you cannot find on a reputable review site, or one of the named apps above, treat it as a compromised endpoint until it is removed and the device is cleaned.
- Remove free VPN apps from any device that touches business data. This includes personal phones used for work email, WhatsApp, or any business platform. The device security perimeter is wherever your data goes, not just your office network.
- If your team needs a VPN, choose one with an independently audited no-logs policy. Reputable paid options publish the results of external audits. The audit is the evidence that they are not keeping records of your sessions. No audit, no trust.
- Run a device audit. Check which apps on staff devices have permissions to read contacts, access the microphone, or run in the background. Free VPN apps frequently request permissions they have no legitimate reason to need. If an app asked for something it should not have and you approved it at install, revoke it.
- Document your POPIA operator chain. Every app, platform, and service that processes personal information on your behalf is an operator under POPIA. List them. Check whether each one has a privacy policy that meets a reasonable standard. The ones that do not need to come out.
Where Ubuntu Guard fits
If you are not sure which devices in your business are running software you have not properly vetted, or you want to understand your actual exposure across devices, accounts, and POPIA controls, that is what our cybersecurity assessment covers. We go through your setup methodically, tell you exactly where the gaps are, and give you a plain-language report you can act on. No jargon, no alarmism. You can read how it works at our cybersecurity assessment page.
Not sure your setup is secure? WhatsApp us and we will walk you through the next step. Or reach us at [email protected].
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za