The VPN market quietly consolidated into a handful of parent companies. Here is who controls what — with the acquisition dates, the prices, and the difference between a proven scandal and an internet rumor.
"No-logs," "privacy-first," "founded by activists" — the marketing is nearly identical across the category. The ownership is not. Over the last decade a few holding companies have rolled up the most-advertised brands, and a parent company's incentives, home jurisdiction, and track record tell you more about a VPN than any landing page.
This is a map of who owns whom as of 2026: the founders, the roots, the ownership timeline with dates, and the controversies. We separate the three things most write-ups blur together — proven events with public records behind them, whispers that remain unproven allegations, and clean records where the dirt simply isn't there. Where a widely repeated "fact" is wrong, we say so.
The four roll-ups below — Kape, Nord Security, Ziff Davis, and the Aura/Point Wild lineage — control a large share of the brands you see advertised. The independents sit at the bottom.
| Parent / owner | Brands | Service jurisdiction | Record |
|---|---|---|---|
| Kape Technologies (Isle of Man; private, Teddy Sagi) | ExpressVPN, CyberGhost, Private Internet Access, ZenMate | BVI / Romania / US | proven issues |
| Nord Security (Amsterdam, NL) | NordVPN, Surfshark | Panama / Netherlands | 1 breach |
| Ziff Davis (US, public) | IPVanish, StrongVPN | United States | past logging |
| Point Wild / ex-Aura (US) | Hotspot Shield, Betternet, UltraVPN | United States | FTC complaint |
| McAfee (US) | TunnelBear | Canada | mostly clean |
| Certida LLC (Texas, US) | VyprVPN (ex-Golden Frog) | US (was Switzerland) | jurisdiction shift |
| Proton AG (Geneva, CH) | Proton VPN | Switzerland | strong |
| Mullvad / Amagicom AB (Sweden) | Mullvad | Sweden | clean |
| Windscribe (Toronto, CA) | Windscribe | Canada | independent |
No story captures the industry's reinvention better than Kape. The company was founded in 2011 as Crossrider, a browser-extension and ad-monetization platform whose toolkit was widely abused to push adware — Malwarebytes still ships a detection family called Adware.CrossRider.1 Crossrider shut down that platform in 2016, rebranded to Kape Technologies in 2018, and pivoted into consumer privacy by acquiring VPNs.2 The irony — an ex-adware company selling privacy — is the single most-cited fact about Kape, and it is accurate.
In 2023, Israeli billionaire Teddy Sagi, already the majority holder, took Kape private through Unikmind Holdings, raising his offer to 290 pence (US$3.60) per share and valuing Kape's equity at roughly US$1.58 billion on completion in May 2023. Kape delisted from London's AIM market and is now wholly Sagi-owned.34
proven Beyond the Crossrider adware lineage, Kape's most significant conflict of interest is editorial: in 2021 it acquired Webselenese, the company behind the "independent" review sites vpnMentor and WizCase, for about US$149 million. A holding company that owns three major VPNs and the review sites that rank them is a textbook conflict — and post-acquisition, those sites' rankings favored Kape-owned brands.11
Separately, ExpressVPN's then-CIO Daniel Gericke was one of three former U.S. operatives named in a September 2021 U.S. Department of Justice deferred-prosecution agreement over Project Raven, a UAE surveillance operation; Gericke's share of the settlement was US$335,000. It was a settlement, not a conviction, and ExpressVPN publicly stood by him — but a VPN's security chief paying to settle a foreign-spying case is a legitimate trust question.12
whisper Speculation about Israeli-intelligence ties — driven by Sagi's nationality and an unrelated decades-old conviction — recurs online but rests on no evidence. We flag it as rumor, not finding. On the upside, the Kape brands now commission independent no-logs audits and publish them.
Kape's brands are technically capable, and the audits are real. The hard part is structural: the same owner controls the products and once controlled the "independent" sites reviewing them. If you buy a Kape VPN, do it on the product's audited merits — never on a top-10 list, because some of those lists were in-house.
NordVPN traces to childhood friends Tomas Okmanas (Tom Okman) and Eimantas Sabaliauskas, working out of the Lithuanian tech incubator Tesonet (co-founded 2008). The company dates to 2012 and the NordVPN product launched in 2013 — a small but worth-correcting nuance to the usual "founded 2012" shorthand.1314 The service is operated under Panama jurisdiction, while parent Nord Security is headquartered in Amsterdam.15
Surfshark, founded in 2018 by Vytautas Kaziukonis, began under British Virgin Islands jurisdiction but relocated its HQ to the Netherlands in 2021 — so the commonly cited "BVI" label is now outdated.16 In a deal announced in 2021 and finalized in 2022, Nord Security and Surfshark merged under one holding company while continuing to run as separate brands with separate infrastructure.17
proven In 2018, a single NordVPN server in a Finland data center was accessed via an insecure remote-management tool the data center had added without Nord's knowledge. No user logs or credentials were exposed, but the bigger problem was disclosure: Nord learned of it in 2019 and only went public in October 2019 after it surfaced on social media. An expired TLS key was taken; the delayed disclosure, more than the breach itself, drew the criticism.18
whisper Nord's close ties to Tesonet — which also runs data-harvesting and residential-proxy businesses — fuel recurring "they share your data" allegations. These remain circumstantial and unproven; Nord denies them and its independent audits support the no-logs claim. Worth noting precisely: Nord's no-logs assurance audits were done by PwC in 2018 and 2020, then by Deloitte from 2022 onward — repeated independent verification is a genuine point in its favor.19
The 2018 breach was real but limited; the repeated, switching-auditor transparency since is more reassuring than a single audit would be. The Tesonet questions are about trust in the corporate family, not a documented leak. Reasonable mainstream choices — just know you're buying into a large commercial group, not a scrappy independent.
IPVanish launched in 2012 under Mudhook Media, a subsidiary of Highwinds Network Group. Highwinds (with IPVanish) was bought by StackPath in February 2017, and in 2019 IPVanish moved to J2 Global — since renamed Ziff Davis — under its NetProtect unit.20
proven The defining controversy predates current ownership. In 2016, under Highwinds, IPVanish handed detailed connection logs — source IPs and session times — to Homeland Security Investigations in a criminal case, despite marketing a "zero-logs" policy. The episode (publicly reported in 2018) is one of the clearest cautionary tales in the category: a no-logs promise is only as good as the corporate will and jurisdiction behind it. IPVanish has since changed ownership and submitted to independent auditing.21
Different owners, U.S. jurisdiction, an audited policy today — but the 2016 incident is exactly why we weight verifiable audits and jurisdiction over slogans. If your threat model includes U.S. legal process, a Five-Eyes-based VPN with a logging history is not where to start.
Hotspot Shield is the flagship of AnchorFree, founded in 2005 by David Gorodyansky and Eugene Malobrodsky; the VPN launched in 2008.22 The ownership chain since is one of the messiest in the industry: AnchorFree rebranded to Pango; Pango was acquired by Aura (founder/CEO Hari Ravichandran) in July 2020; in 2024 Aura split and spun Pango back out; and in December 2024 Pango merged with TotalAV's parent and rebranded as Point Wild, which now owns Hotspot Shield alongside Betternet, UltraVPN and others.23
proven In August 2017, the Center for Democracy & Technology filed an FTC complaint against Hotspot Shield's free tier, alleging undisclosed data sharing, interception and redirection of user traffic to advertising partners, and ad injection — practices flatly at odds with a privacy product.24
A documented FTC complaint over traffic interception, plus an ownership trail so convoluted it's hard to say who's accountable today, makes this lineage the hardest to recommend for anyone who actually needs privacy. The free tier especially monetizes the thing you're trying to protect.
TunnelBear was founded in 2011 by Daniel Kaldor and Ryan Dochuk in Toronto, and acquired by McAfee in March 2018.25 It was an early adopter of annual independent security audits, and its record is largely free of major scandal — complaints tend to be about performance and feature limits rather than trust.
Clean record and audit-forward, but U.S.-owned and operated from Canada — two Five Eyes countries. Fine for casual privacy and unblocking; not the pick if jurisdiction is central to your threat model.
VyprVPN was built by Golden Frog, founded in December 2009 by internet veterans Ron and Carolyn Yokubaitis, with its privacy jurisdiction in Switzerland (not the Netherlands, a detail frequently mis-stated). In 2023 it was acquired by Certida LLC of Texas, shifting the operation to U.S. jurisdiction.26
proven Historically, VyprVPN retained connection metadata for up to ~30 days. It addressed this in 2018 with one of the industry's first public no-logs audits, by Leviathan Security Group, which found issues that were then fixed.27 whisper The live concern is structural: a 2023 move from Switzerland to Texas trades one of the world's stronger privacy jurisdictions for a Five Eyes member — the opposite of the direction privacy buyers want.
An audited history and a real fix to its logging, but the jurisdiction shift to the U.S. is a meaningful downgrade for anyone choosing a VPN on privacy grounds. Re-evaluate it as a U.S. service now, not the Swiss one it used to be.
Three notable providers have no roll-up parent, and it shows in how they behave under pressure.
Proton grew out of CERN: the company was founded in 2014 (the ProtonMail era) by Andy Yen, Jason Stockman and Wei Sun, and Proton VPN launched in May 2017. Since June 2024, Proton AG has been controlled by the non-profit Proton Foundation, a structure explicitly designed to keep the mission insulated from acquirers.2829
proven, with a key distinction The 2021 "Proton logged a user" story is real but is routinely misattributed. It involved ProtonMail, not Proton VPN: compelled by a legally binding Swiss order (routed via Europol from French police), ProtonMail logged the IP address of a French climate activist. Email contents stayed encrypted, and Proton has noted it doesn't log IPs by default. It's a useful reminder that no provider is above its home country's law — but it was an email-service order, not a VPN logging failure.30
Launched in 2009 by Fredrik Strömberg and Daniel Berntsson, Mullvad is wholly owned through Amagicom AB with no outside investors, and is famous for anonymous accounts — a random account number, no email required.31 proven (in its favor) In April 2023, Swedish police arrived at Mullvad's office with a search warrant intending to seize customer data and left empty-handed because none existed — about the strongest real-world validation of a no-logs claim available.32
Founded in 2016 by Yegor Sak, Alex Paguis and Mark Ulicki, Windscribe is fully owned by its founders and staff.33 proven In June 2021, Ukrainian authorities seized two Windscribe servers; the company candidly disclosed that those two servers were not properly encrypted and stored an OpenVPN certificate and key on disk, then re-architected to keep keys in memory only. The honesty of the post-mortem earned more trust than the incident cost — though it's a reminder that Canada is a Five Eyes country.34
If transparency under pressure is your bar, the independents clear it most convincingly. Mullvad and Proton VPN are the reference points for privacy-first buyers; Windscribe earns credit for candor despite a Five-Eyes home.
1. Consolidation concentrates incentive. Kape, Nord Security, Ziff Davis and the Aura/Point Wild lineage control a large share of the advertised market. When one owner runs multiple "competing" brands — and, in Kape's case, once ran the review sites too — the comparison you're reading may be a sale, not an analysis.
2. Acquisitions move jurisdictions and policies. The dates matter: PIA (Dec 2019), ExpressVPN (Sep 2021) and VyprVPN (2023) each changed the calculus of the product overnight. VyprVPN's Switzerland-to-Texas move is the clearest example of a deal making a service less private.
3. Jurisdiction is marketed, not always real. A Panama or BVI service entity is a legal address; the engineers, executives and infrastructure may sit in a surveillance-alliance country. Check the parent, not just the privacy-policy boilerplate.
4. The recurring failure modes are mundane. Subscription dark patterns, audits that quietly go stale, and "no-logs" claims that were never tested account for most real-world harm — more than exotic intelligence conspiracies. The independents (Mullvad, Proton, Windscribe) tend to score highest precisely because their behavior under legal pressure is documented.
No provider is perfect, and the right VPN depends on your threat model, not a leaderboard. But a few durable conclusions hold up against the records: for maximum privacy, favor proven, independently owned no-logs services whose claims have survived a real-world test — Mullvad's empty-handed police raid and Proton's non-profit structure are the gold standard. For mainstream use, the large commercial brands are capable, but buy them on their current, dated audits and jurisdiction — not on slogans, and never on a "top 10" list whose owner you haven't checked. And treat any acquisition as a reset: when a VPN changes hands, its old promises don't automatically carry over. Verify the latest audit, transparency report and company registry before you trust — or pay for — any of them.
Sources accessed and verified June 2026. VPN ownership, audits and policies change frequently — confirm current details against company registries and the latest transparency reports before relying on them.
VPNInsider.org · Industry Analysis · updated monthly · June 2026.