The VPNs people download during shutdowns are not reliably safe. When access is cut or filtered, people install whatever VPN they can find, and researchers have documented spyware disguised as VPN apps, government-tolerated domestic VPNs with access to user data, and free apps with weak or no encryption. Tools designed specifically for censorship circumvention, such as Psiphon, Tor and Lantern, kept more people online during Iran’s 2025 shutdown, but no app is safe if it comes from an unverified link.
Shutdowns and platform blocks keep rising
Access Now and the #KeepItOn coalition documented at least 313 internet shutdowns in 52 countries in 2025, the most since they began counting in 2016. They also recorded a record 94 platform blocks, cutting access to services such as WhatsApp, Telegram or TikTok, in 40 countries (Access Now, 2026).
| Country | Shutdowns recorded in 2025 | VPN-related measures noted | Source |
|---|---|---|---|
| Myanmar | 95 | VPN blocking; street phone checks; Jan 2025 law penalizing unauthorized VPN services | Access Now, 2026; RFA, 2025 |
| India | 65 | Two-month ban on unauthorized VPN use in Jammu and Kashmir from Dec 29, 2025; police reportedly penalized about 800 users | Access Now, 2026 |
| Pakistan | 20 | 2024 push for businesses and freelancers to register VPNs with the regulator | Access Now, 2026; Dawn, 2024 |
| Russia | 19 | 197 VPN services blocked by October 2024; ban on promoting VPNs | Access Now, 2026; Freedom House, 2024 |
| Iran | 11 | Unsanctioned VPN use prohibited since Feb 2024; protocol whitelisting during June 2025 war | Access Now, 2026; Freedom House, 2025 |
| Venezuela | 3 | At least 21 VPN services blocked in January 2025 | Access Now, 2026 |
Freedom House found that anti-censorship tools had been blocked in at least 21 of the 72 countries in its Freedom on the Net coverage over the past five years, all rated Not Free or Partly Free (Freedom House, 2025).
A VPN cannot fix a total blackout
When a government blocks specific platforms or throttles traffic, a VPN or proxy can route around the block. When it cuts connectivity entirely, there is nothing for a VPN to tunnel through. Many recent shutdowns sit in between: in June 2025 Iran used DNS poisoning, protocol whitelisting and deep packet inspection, and traffic to the global internet fell by about 90% (Filterwatch, 2025). In that environment, ordinary VPN protocols are easy to spot and block, and only tools built to disguise their traffic keep working.
Documented risks to people seeking VPNs
Spyware dressed as a VPN
The clearest danger is malware that pretends to be a VPN. In June 2025, a week after the Israel-Iran war began, security firm Lookout found four new samples of DCHSpy, Android spyware it attributes to MuddyWater, a group linked to Iran’s Ministry of Intelligence and Security. The samples posed as VPN apps including Earth VPN and Comodo VPN, were distributed through Telegram, and one used “Starlink” in its file name, apparently to exploit interest in satellite internet during the outage. The spyware can collect WhatsApp data, contacts, text messages, call logs, location, photos and audio (The Register, 2025). One distribution page claimed the app was used by activists and journalists.
State-tolerated and state-linked VPNs
Some governments ban unapproved VPNs while allowing others to flourish. Freedom House reports that Iran prohibited unsanctioned VPN use in February 2024, without attaching criminal penalties, and exempted people who obtained government approval. Domestic VPN businesses then grew, Iranian lawmakers among others speculated about government ties, and a former Iranian cybersecurity official said authorities have access to extensive data from VPN companies (Freedom House, 2025). The same report says Russia’s restrictions effectively push people toward low-quality or state-endorsed VPNs.
Free apps with weak security and hidden owners
The free apps that top store charts during a crisis are often the least scrutinized. An analysis of 283 Android VPN apps found that 18% used tunneling protocols without encryption, about 84% leaked IPv6 traffic and 66% leaked DNS traffic outside the tunnel, and over 38% had some malware presence according to VirusTotal (Ikram et al., 2016). More recently, researchers found hard-coded Shadowsocks passwords in families of popular free VPN apps with more than 700 million combined Google Play downloads, which would let an eavesdropper on the network decrypt their users’ traffic (Mixon-Baca et al., 2025). Several of those apps are among those the Tech Transparency Project traced to undisclosed Chinese ownership (TTP, 2025).
Legal exposure from simply having the app
In some places the app itself is evidence. Voice of America reported that around two dozen people in Myanmar were arrested and fined in early June 2024 after police found VPNs on their phones during random checks (VOA, 2024). Myanmar’s Cybersecurity Law, in force since January 1, 2025, sets prison terms of up to six months and fines for providing VPN services without permission (RFA, 2025).
What kept people connected
Iran’s June 2025 shutdown offers the best recent evidence of which tools work under heavy filtering. A multi-stakeholder analysis by Filterwatch and the Miaan Group concluded that more Iranians got online during this shutdown than in the near-total 2019 blackout, crediting a diverse mix of tools (Filterwatch, 2025).
| Tool | Type | Reported performance | Source |
|---|---|---|---|
| Psiphon | Circumvention app using multiple protocols | About 1.5 million users at the height of the June 2025 shutdown, roughly one-third of its normal Iranian base | Filterwatch, 2025 |
| Lantern | Circumvention app | Moderate success; its proxyless protocol carried about 40% of its traffic | Filterwatch, 2025 |
| Tor (bridges) | Anonymity network | Bridge connections surged during the blackout | Filterwatch, 2025 |
| Tor Snowflake | Volunteer-run bridge | Users quadrupled within days during Iran’s September 2022 crackdown | Tor Project, 2023 |
| Ceno Browser | Peer-to-peer browser | Active peers rose from 600 on June 13 to nearly 8,000 by July 11, 2025 | Filterwatch, 2025 |
| BeePass VPN | VPN | Over half a million daily users in Iran at the start of the war | Filterwatch, 2025 |
These tools are not immune. The Tor Project noted that Snowflake traffic from Iran in 2022 dropped sharply about two weeks after the surge because censors blocked a distinctive TLS fingerprint, which developers then had to fix (Tor Project, 2023). Censors keep adapting, so tools that worked last month may not work next month.
What this means for you
- Install before you need it. Download circumvention tools from official app stores or the developer’s own website while access is still normal. During a shutdown, those sources may be blocked and fake copies multiply.
- Never install a VPN from a forwarded link or APK. The DCHSpy campaign spread through Telegram. If you must sideload, get the file from the project’s official channel and verify it where possible.
- Prefer tools built for censorship. Psiphon, Tor with bridges or Snowflake, and Lantern are designed to disguise traffic. Many free commercial VPNs use protocols that deep packet inspection can identify.
- Keep more than one option. Blocking shifts quickly; a second tool is a practical backup.
- Check the developer. Hidden ownership, sibling apps with identical code, and requests for contacts or SMS access are warning signs.
- Weigh the legal risk. Where phones are searched, a VPN icon on the home screen can itself be a problem. Know local rules and your own risk level.
Methodology and limitations
The sources are human-rights and measurement organizations (Access Now, Freedom House, Filterwatch and the Miaan Group, the Tor Project), threat-intelligence findings reported by The Register (original research by Lookout), peer-reviewed security studies (ACM IMC 2016, FOCI 2025), and reporting by Voice of America, Radio Free Asia and Dawn. VPN-demand figures published by VPN vendors or review sites are not used because their methods are not transparent.
Shutdown counts are minimums, and Access Now notes its numbers can change as new information emerges. Usage figures for circumvention tools in the Filterwatch analysis appear to come from the tool operators themselves and are not independently audited. The 2016 Android study predates current app versions, so its percentages describe the ecosystem at that time. Malware campaigns are documented when security firms detect them; the true number of fake VPN apps distributed during shutdowns is unknown.