Four separate stories broke in the VPN world over the past three months. Read alone, each looks like a niche update. Read together, they describe an industry getting squeezed from two directions at once: governments tightening the net on where and how VPNs can be used, while the tools themselves turn out to be less trustworthy than their marketing suggests.
Here is what happened in each case, why it matters, and what it actually changes about picking a VPN right now.
Russia stops fighting the network, starts fighting the app
For years, Russia’s approach to VPN blocking happened at the infrastructure level: throttling protocols, blacklisting server IPs, ordering ISPs to interfere with encrypted traffic. Getting around that was mostly a cat-and-mouse game between VPN providers and the state, and providers usually found a way, at least for a while.
That changed on April 15, 2026. Ozon, Russia’s largest e-commerce platform, and Kinopoisk, a major streaming service, started detecting VPN users directly and refusing to serve them. No network-level blocking required, the site itself now does the checking. Banking apps and ride-hailing services saw similar disruptions around the same date, though not every platform joined in: VKontakte and Wildberries reportedly kept working fine with a VPN active.
The order behind this reportedly comes from Russia’s Ministry of Digital Development, which has set a compliance deadline covering more than 20 platforms. The pressure on the VPN industry itself has been building in parallel: more than 100 VPN apps were pulled from Russian app stores across 2025, and Apple cut off mobile billing for apps in Russia in April 2026, which makes paying for a VPN subscription there considerably harder even before any blocking happens.
The shift matters because it closes a loophole that used to work reliably: even when the network was hostile, the destination site rarely cared how you got there. Now the application layer itself checks, and there is no server switch that fixes an app-side detection the way there was for network-level throttling. We covered the mechanics, the platforms involved, and what still works in detail in our full report on Russia’s VPN crackdown.
A university study just tested 281 Android VPNs, and most failed
While governments were busy blocking VPNs, researchers were checking whether the VPNs people do manage to use are actually doing their job. The University of Michigan built a testing framework called MVPNalyzer and presented it at the NDSS 2026 Symposium on July 7. It is the largest independent audit the mobile VPN market has ever gotten, and it inspected apps across several layers at once: the traffic actually leaving the device, the DNS requests being made, the configuration files controlling encryption, and the identifiers handed to outside servers.
The results are rough. Out of 281 popular Android VPN apps tested, 29 leaked DNS or browser traffic outside the encrypted tunnel, meaning the app’s core promise, hide what you’re browsing, simply didn’t hold up under testing. Seventy-six apps sent the device’s Advertising ID to third parties, which is precisely the tracking identifier a VPN is supposed to shield you from, not hand out to ad networks and analytics firms. More than 60% of the apps failed basic security hardening checks entirely, things like proper certificate validation and safe default configurations.
None of this touches the small handful of audited, no-logs providers this site tracks closely. It is a story about the much larger pile of free and low-profile apps sitting one search away from them on the Play Store, wearing the same three letters on the icon and offering none of the same guarantees. We break down the full methodology and numbers in our dedicated piece on the MVPNalyzer study.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Post-quantum encryption: one leader, everyone else still talking
Quantum computers do not exist yet at the scale needed to break today’s VPN key exchanges. But the threat model is not “wait until they exist.” It is “harvest now, decrypt later”: an adversary can record encrypted traffic today and unlock it years from now, once the hardware catches up. For anyone with long-horizon secrets, journalists, lawyers, researchers, medical or financial records, that clock is already running, regardless of when a working quantum computer actually shows up.
At mid-2026, NordVPN is the only mainstream consumer VPN that has actually finished the migration across its whole platform lineup. Its post-quantum NordLynx, built on ML-KEM layered on top of the existing WireGuard key exchange, shipped first on Linux in September 2024 and reached every remaining platform, Windows, macOS, iOS, Android, Android TV, and tvOS, by May 2025. It runs by default on every supported app, with no setting to dig for and no expert toggle required.
ExpressVPN, Surfshark, and Proton VPN have all signaled roadmap intentions in the same direction, but none has shipped a complete post-quantum implementation in production as of this writing. That gap is not a rounding error. It is the difference between a threat already mitigated for every user and one still sitting on a slide deck somewhere in a product roadmap. We go deeper on who ships what, and why the gap matters more for some users than others, in our post-quantum VPN encryption breakdown.
Age verification laws keep spreading, and VPNs keep being the workaround
The fourth thread is regulatory, and it has been building all year. Twenty-five US states now have active age verification laws, with Utah’s SB 73 the most aggressive of the bunch: it directly targets VPN users, holding websites liable if a Utah resident bypasses age checks using one, and even bans covered sites from publishing instructions on how to do it. The UK, Australia, Brazil, and Turkey have all passed or enforced similar legislation over the past year. The EU is now drafting a unified age verification framework meant to apply across all 27 member states by the end of 2026.
Every one of these laws has produced the same side effect: a spike in VPN downloads. Ordinary people reach for a VPN to keep browsing content that was legal yesterday and is suddenly gated today, not to do anything nefarious. Utah’s law is currently the sharpest test case for whether a state can meaningfully regulate users whose physical location it cannot legally verify, and it is being challenged in federal court right now, with enforcement delayed while the case proceeds. We track the state-by-state and country-by-country detail in our age verification laws roundup.
What it all adds up to
Put the four threads side by side and a pattern shows up quickly. Regulators, in Russia and increasingly in democracies too, are done treating VPNs as a niche privacy tool nobody needs to legislate around. At the same time, an independent security audit just confirmed that a large chunk of the VPN market cannot deliver on the one promise that justifies its existence in the first place. And the providers actually investing in future-proof cryptography remain a short list, not the whole industry.
None of that means VPNs stopped being useful. I still use one every day. But the gap between a serious provider and a name that merely sounds like one just got wider, and picking badly now carries a real cost: leaked DNS queries, a sold advertising ID, or an app that goes dark the moment the destination site decides to check who’s really connecting.
How to pick a serious VPN in this climate
Three filters do most of the work, and none of them require technical expertise to apply. First, choose a provider with a completed, independent no-logs audit, not just a claim buried in a privacy policy. Second, check that the app actually uses a modern protocol, WireGuard, NordLynx, or Lightway, rather than something dated like PPTP or plain L2TP, and see whether post-quantum key exchange is already shipped or at least on a public roadmap. Third, be wary of free apps outside the small set of established, audited names: the MVPNalyzer numbers above are exactly what happens when a VPN’s business model depends on selling data rather than protecting it.
NordVPN currently checks every one of those boxes: an audited no-logs policy, WireGuard-based NordLynx running by default, and the only complete post-quantum rollout on the market today. Proton VPN is a solid alternative if you want a provider with a strong open-source and privacy-advocacy track record, even while its own post-quantum work is still in progress rather than finished.
Mid-2026 is not a moment to panic about VPNs, but it is a moment to stop picking one by price alone. Censorship pressure is rising, a meaningful chunk of the mobile market is quietly failing its basic job, and only a handful of providers have bothered to future-proof their encryption. Pick from the providers that have done the audits and shipped the hard cryptography, and none of this year's news changes anything for you.
Sources: The Moscow Times on Russia’s VPN site blocking | University of Michigan on the MVPNalyzer study