What a VPN Does Not Protect You From in 2026

Disclosure: this article may contain affiliate links. If you buy through them, merkart may earn a commission, at no extra cost to you. Recommendations are independent.

A friend called me from a rented flat in Lisbon, fairly upset, because someone had got into her email despite the VPN she had been paying for since January. Nothing about the VPN had failed. She had typed her password into a page reached from a message about a parcel, three weeks earlier, on her home connection. The tunnel was in perfect working order the entire time. It was simply never the thing standing between her and that page.

That gap between what a VPN does and what people believe it does is where most of the disappointment lives. So here is the edge of the protection, drawn honestly, by someone who still recommends one.

What it actually changes

A VPN takes the connection between your device and the internet and wraps it, so the network you are sitting on cannot see where you are going, and the sites you visit see the provider address rather than yours. That is a real and narrow benefit. On a shared network it removes the local observer. Across borders it changes which country you appear to be in. For anything involving a network you did not set up, that is genuinely worth paying for.

Everything below is outside that wrapper, either because it happens before your traffic enters it, or after it leaves.

It does not stop you handing over your own keys

Phishing is a conversation, not an interception. The message arrives, it looks like a delivery notice or a tax refund or a colleague in a hurry, and you type your credentials into a page that captures them. Every byte of that exchange can travel through an encrypted tunnel and arrive perfectly intact at the wrong destination. The tunnel does its job flawlessly. That is the point people miss: a secure delivery of your password to a thief is still a delivery.

The same is true for anything you consent to. Granting an app permission to your contacts, approving a login prompt you did not initiate, reusing a password across accounts. None of these are network problems, so none of them have a network solution.

It does not clean a device that is already compromised

If something is running on your laptop that reads what you type, encrypting the connection changes nothing at all. The data is collected before it enters the tunnel, in plain form, where it was typed. The same goes for a browser extension with wide permissions, which sees pages as you see them, after decryption.

This is worth saying plainly because the two products are often sold in the same bundle. Antivirus and a VPN are not two grades of the same protection. One watches the device, the other watches the wire, and buying a second wire guard does not cover the device.

It does not make you anonymous once you sign in

The moment you log into an account, you have introduced yourself. The service now knows exactly who is on the other end of the tunnel, whatever the address says. Your session cookies, your logged in profile and the browser fingerprint that comes from your fonts, screen size and settings all persist across a change of address.

There is a common travel version of this mistake. People switch to a foreign server, keep their normal browser session, and then wonder why the results and the prices did not move. The address changed. The identity did not.

It does not fix what an app leaks on its own

Applications talk constantly, and a VPN moves that traffic without inspecting it. Telemetry still leaves. Location permissions still report where you are, from the device sensors rather than the connection. A photo still carries whatever the camera wrote into it. If an app sends more than it should, it will send exactly as much through a tunnel, and the destination will receive it correctly.

Mobile has its own quiet exception. Your telephone number and the network your phone is registered on are not affected by any of this, because that traffic never enters the tunnel in the first place.

It moves the observer rather than removing one

This is the one that deserves a clear head. Without a VPN, the network you sit on can see the shape of what you do. With one, that view moves to the provider. You have not eliminated an observer. You have chosen a different one, which is a good trade only if the new one is better than the old.

That is why the boring questions are the real ones. Is there an independently audited no-logs policy rather than a claim on the homepage. Is there a kill switch that fails closed when the tunnel drops. Where is the company registered and what can be demanded of it. Those are the criteria on which a service like NordVPN (Europe) or NordVPN (US/Canada) (which link works best depends on the region you are in) is worth checking, and they are the same criteria you should apply to any provider, including a free one, where the observer question answers itself in an unflattering way.

What the honest picture looks like

A VPN is one control among several, and it covers exactly one segment of the path. The rest of the work is unglamorous and mostly outside the network: a password manager so credentials are neither reused nor typed into look-alike pages, two factor authentication so a stolen password is not enough, prompt updates on the device, and a slow suspicious reflex about any message that creates urgency.

Sold that way, a VPN keeps its value instead of losing it. It protects the wire, which is genuinely worth protecting when you are on networks you do not own. It has never protected the person at the keyboard, and no software sold on that promise has ever delivered it.

Marko Jambrek

Marko Jambrek

Licensed architect in Zagreb, 30 years of practice (sustainable design). Reviews and approves every article on this site before publication. Writes about AI tools through a lens of order and long-term value, tests before recommending.

How I vet what I recommend

The 12-point checklist behind every review on this site. Run any “best of” article through it, including mine. Twelve checks, sent once, yours to keep.

This article may contain affiliate links. We may earn a commission if you click through and make a purchase, at no extra cost to you.