How a VPN protects you (and what it doesn't)

A VPN stops network-level snooping: it hides your traffic from your ISP, local Wi-Fi, and the sites you visit, which see its IP address instead of yours. It does nothing about threats above that layer — malware, phishing, browser fingerprinting, tracking through accounts you're logged into, or a legal request served on the VPN company itself.

Ask what a VPN protects you from and most explainers stop at the network: encrypt the traffic, hide the address, done. That part is real, but it’s one layer out of everything a person actually worries about online. The sharper question is narrower — for each specific fear, a hacker, a phishing email, your ISP, a subpoena, a data breach, does turning a VPN on change the outcome, or not?

What layer does a VPN actually work at?

A VPN operates at the network layer. It wraps the connection between your device and a server in encryption. That job stays the same no matter which app or site is on the other end — the mechanics behind it are covered in what a VPN is and how it works. The UK’s National Cyber Security Centre frames VPNs the same way in its infrastructure guidance: a tool for protecting data in transit, not the device or the accounts on it. A VPN can’t reach into a file after it lands on your device. It can’t reach into a page rendered inside your browser. It can’t reach into a database a company already filled with your information. If one of the threats below turns out to be a network-layer problem after all, our full VPN rankings cover which providers back their promises with evidence.

Threat by threat: what actually changes

Line up specific worries against what a VPN mechanically does, and the pattern holds: anything that depends on the network path changes; anything that depends on your accounts, your browser, or the device itself does not.

What a VPN stops, partly changes, or leaves untouched
ThreatDoes a VPN stop itWhat actually happens
Someone on your Wi-Fi reading your trafficYesTraffic is encrypted before it leaves the device, so a shared network sees only scrambled data
Your ISP logging every site you visitMostlyThe ISP sees one encrypted connection to the VPN server, not the destinations behind it
A website logging your IP address and rough locationYes, for that addressThe site sees the VPN server's IP instead of yours
Malware from an infected download or a malicious linkNoA VPN secures the connection; it does not scan or block file contents
A phishing page harvesting your passwordNoThe tunnel encrypts a fake login page exactly as well as a real one
Browser fingerprinting (device and browser signature tracking)NoFingerprinting runs inside the browser, above the layer a VPN encrypts
Tracking through an account you are signed intoNoThe platform identifies you by the login, not by your IP address
A company you already gave data to getting breachedNoA VPN protects data in transit; it has no reach into a database that already holds it
A court order or subpoena served on the VPN companyDependsThe company can only hand over what it actually logs — this is what audits are meant to verify
A stolen or unlocked deviceNoThe tunnel protects traffic on the network; it does nothing once someone holds the device itself

Why the marketing and the mechanics disagree

Independent reviewers keep landing on the same gap. PCMag’s rundown of VPN myths singles out claims of total anonymity and blanket security as two that don’t hold up, because a VPN’s job stops at the network connection. The Electronic Frontier Foundation draws the line just as plainly: a VPN is best understood as routing your connection through a different network, not as a source of blanket privacy or anonymity.

Fingerprinting is the clearest example of a threat sitting entirely outside a VPN’s reach. Brave’s own explainer of what a VPN protects draws that boundary directly. Your browser and device generate a signature from things like screen size, fonts, installed extensions, and timezone. A tracker can read that signature no matter which server you’re connecting through. Changing your IP address changes none of it.

What if the company you gave your data to gets breached?

A VPN’s protection ends the moment your data reaches its destination. Hand your email address to a retailer and that retailer’s database leaks, and no VPN setting from months earlier reaches back to stop it — the data was collected and stored outside the tunnel entirely. The same logic covers routine data collection: operating systems, apps, and websites gather usage data through the account or app itself, not by intercepting your connection, so there’s nothing in that path for a VPN to encrypt.

What happens if someone serves the VPN company a court order?

This is the honest edge case, because it flips who gets asked. Without a VPN, your ISP is the party a court or agency would approach for a record of where you went. With one, that party is the VPN company instead. What it can hand over depends entirely on what it actually logs, not on what its marketing page promises. Three providers point to real tests of that promise: Private Internet Access says a legal request for its records met a no-logs policy that produced nothing to hand over. Proton VPN’s audit announcement states its no-logs policy has held through more than 400 legal cases. Windscribe points to a Greek court case as evidence of what its logs do and don’t contain. None of that is a blanket guarantee — it’s evidence tied to one company’s specific record, which is exactly why how no-log VPN audits work matters more than the phrase “no logs” on its own.

Is the VPN app itself something to trust blindly?

A VPN is also just software, built by a company, and both can have their own problems. Consumer Reports tested 16 VPN services and found 12 made privacy or security claims that were inaccurate or broader than the evidence supported. Only one of the sixteen, Mullvad, used a signature to authenticate its Windows updates. Some had weak protections against repeated failed login attempts on the account itself. None of that is the tunnel failing. It’s the cost of trusting a claim without checking who verified it — the same discipline how to choose a VPN walks through in full.

Match the worry to the right tool

A VPN is one tool built for one job: securing the network path. Most of the threats above have their own dedicated fix, and stacking the wrong tool on a problem wastes money without closing the gap.

  • Snooping on shared or untrusted Wi-Fi — a VPN, switched on before you connect. Is public Wi-Fi safe without a VPN covers exactly when that applies.
  • Malware and infected downloads — antivirus or endpoint protection and caution with unknown attachments, not a VPN.
  • Phishing and credential theft — a password manager plus multi-factor authentication, not a VPN.
  • Fingerprinting and cross-site tracking — a privacy-hardened browser and blocked third-party trackers, not a VPN.
  • A provider’s own data-handling record — its audit history, checked before you trust its no-logs claim, not its marketing copy.

Treat a VPN as network-layer insurance: valuable exactly where the network is the risk, and silent everywhere else.

Frequently asked questions

Does a VPN protect you from hackers?

It stops one specific kind of attack: someone reading or altering your traffic on a shared network. It does nothing about malware, software exploits, or an attacker who already has your password — those live on the device or the account, not the connection.

Can a VPN stop someone from tracking you?

It stops IP-based tracking, the kind that ties your browsing to your network address. It has no effect on cookies, browser fingerprinting, or tracking tied to an account you are signed into, all of which identify you without needing your IP.

Does a VPN protect you from malware?

No. A VPN encrypts the connection a malicious file travels over just as reliably as it encrypts a legitimate one. Antivirus software and cautious downloading habits are the tools that actually screen for malware.

Does a VPN protect you from data theft?

It protects data while it moves between your device and the VPN server. It has no reach into a company’s database after you have already handed that data over, so it does nothing to stop a breach at a retailer, employer, or app you use.

Can a VPN protect you from government or police monitoring?

It moves what a court or agency could ask your ISP for and puts it in the VPN company's hands instead. Whether that company has anything to hand over depends on what it actually logs — a question its audit history answers better than its marketing page does.

Does a VPN protect your privacy?

Partly. It hides your IP address and browsing destinations from your ISP and the local network, which is real privacy in transit. It does not stop tracking through logins, cookies, or fingerprinting, so it covers one piece of privacy, not the whole picture.

Sources

  1. NCSC — Virtual private networks (infrastructure guidance) — accessed
  2. EFF Surveillance Self-Defense — Choosing the VPN that's right for you — accessed
  3. PCMag — 7 dangerous VPN myths you probably believe — accessed
  4. Brave — What does a VPN protect? — accessed
  5. Consumer Reports — VPN testing: poor privacy, security, hyperbolic claims — accessed
  6. Private Internet Access — Security audit 2025 — accessed
  7. Proton VPN blog — No-logs audit — accessed
  8. Windscribe — Has Windscribe been audited? — accessed