A TechRadar investigation published in early August 2026 audited more than 4,000 VPN app listings across Apple’s App Store and Google Play and found hundreds putting users at real risk before they even connect to a server, through insecure links, hidden redirects and outright scareware tactics baked into the listing pages themselves. The findings are a useful reminder that downloading from an official app store is a starting point for safety, not a finish line.

What the investigation found

The audit identified 339 Android app links, roughly 5.3% of those checked, and 188 iOS app links, about 6.8%, still using plain, unencrypted HTTP instead of secure HTTPS. On the open internet, that distinction matters: an unencrypted link can be intercepted or tampered with in transit, which is a strange and ironic weakness for an app whose entire purpose is supposed to be protecting your connection. Beyond broken encryption on the listing links themselves, the investigation also documented hidden redirects designed to obscure where a download link actually leads, and scareware-style messaging designed to pressure users into installing or paying for an app quickly, before they’ve had a chance to check whether it’s legitimate. (TechRadar, August 2026)

Why this happens on official app stores

Both Apple and Google run review processes before apps go live, but neither store audits every external link, redirect chain or piece of marketing copy embedded in an app’s own listing or in-app pages with the same rigor they apply to the app’s core functionality. A VPN app can pass the initial technical review while still linking out to insecure or manipulative content once installed, which is exactly the gap this investigation exposed. It’s a reminder that “available on the App Store or Google Play” is a baseline of legitimacy, not a guarantee that every part of an app’s experience has been scrutinized.

This follows a pattern of similar findings in 2026

This is not an isolated report. Earlier TechRadar investigations in 2026 documented clone VPN apps gaming the Google Play Store with near-identical branding to legitimate providers, and thousands of iOS and Android VPN apps operating behind fake or nonexistent websites with no real support infrastructure behind them. Together, these findings paint a consistent picture: the sheer number of VPN apps available on both major app stores makes it easy for a small number of exploitative operators to blend in alongside well-run, trustworthy providers.

How to check a VPN app before you install it

Search for the provider’s name alongside independent audit reports before downloading, rather than relying on app store ratings alone, since ratings can be manipulated with fake reviews more easily than a published third-party audit can be faked. Check whether the provider has a real, working website independent of the app store listing, with clear contact information and a detailed privacy policy rather than a single vague paragraph. Be suspicious of any VPN app that pressures you to act quickly, warns of an immediate security threat to convince you to install or upgrade, or redirects you through multiple pages before reaching an actual download or payment screen.

VPNs with a clean, verifiable track record

NordVPN and ProtonVPN, the two highest-scoring providers in our overall ranking at 4.63/5 and 4.24/5, both maintain transparent, independently audited operations with clear ownership, published audit reports, and app store listings free of the kind of manipulative tactics this investigation flagged elsewhere. Neither appeared in TechRadar’s findings, and both are reasonable default choices if this story has you rethinking whichever VPN you currently use.

Get NordVPN

What “hidden redirects” actually means in practice

One of the more technical findings worth unpacking is the hidden redirect issue: rather than linking directly from an app’s store listing to its actual download or sign-up page, some listings route users through a chain of intermediate pages, sometimes on unrelated domains, before landing on the real destination. Each additional hop in that chain is a point where the link could be swapped for something malicious, or where tracking and ad networks unrelated to the VPN itself collect data on you before you’ve even installed anything. A legitimate provider has no real reason to route users through several unrelated domains just to reach its own sign-up page, which makes a long or unusual redirect chain a reasonable reason for suspicion on its own.

A simple checklist before downloading any VPN

Look up the company behind the app and confirm it has a real, findable corporate presence rather than an anonymous developer account. Check for at least one independent audit of its no-logs claims, published with a named auditor. Read the privacy policy for specifics rather than vague reassurances. And treat any app that uses urgency or fear-based language in its own marketing, warning of an active threat to your device, for example, as a red flag rather than a reason to act immediately.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

What Apple and Google should be doing differently

Security researchers who reviewed TechRadar’s findings have pointed out that both companies could meaningfully reduce this problem by extending their existing review processes to cover external links and in-app redirect chains more rigorously, not just the core app binary submitted for review. Until that changes, the responsibility for filtering out bad actors falls more heavily on individual users doing their own diligence before installing anything, which is a genuinely unfair burden but the practical reality as of 2026.

Why VPN apps specifically attract this problem

VPN apps sit in an unusual spot in the app store ecosystem: the entire pitch of the product is trust, protect your data, hide your identity, keep you safe online, which makes them an attractive category for operators looking to exploit that trust with minimal effort. Unlike a game or a productivity app, where a bad actor mostly risks a poor rating, a VPN app that behaves badly can actively expose the exact data it claimed to protect. That mismatch between what a VPN promises and what a small number of listings actually deliver is precisely why investigations like this one matter more here than in most other app categories, and why a few extra minutes of research before installing pays off disproportionately.

Does this mean you shouldn’t use app store VPN listings at all?

No. The vast majority of VPN apps on both stores are legitimate, and app stores remain the safest general channel for installing software compared to downloading an installer directly from a random website. The lesson here is narrower: within that generally safe channel, a meaningful minority of listings cut corners in ways that matter, and a few extra minutes of checking a provider’s audit history and corporate transparency before installing is a reasonable habit regardless of which store you’re using.

Our verdict

This investigation is a useful reminder that "available on the App Store or Google Play" isn't the same as "verified safe." Stick to providers with a real corporate presence and published, named audits, like NordVPN or Proton VPN, and treat any VPN listing using urgency or vague claims as a reason to look elsewhere.

Keep reading: Are VPNs Safe? The Real Risks in 2026 and How to Verify a VPN’s No-Logs Policy.