Major VPN providers such as NordVPN, ExpressVPN, and Proton VPN are facing attacks through typosquatting, where fake domains mimic their official sites. A report indicates that 14 percent of these imitation domains are malicious. Users are advised to take precautions to avoid falling victim to these scams.
Typosquatting, a simple yet dangerous tactic, is being used against popular VPN services. According to a TechRadar article published on February 11, 2026, top providers including NordVPN, ExpressVPN, and Proton VPN are among those targeted by lookalike domains. These fake websites exploit minor typing errors to deceive users seeking secure browsing tools.
The report highlights that 14 percent of the identified fake domains have been found to be malicious, potentially leading to data theft or malware installation. While specific details on the number of affected domains or the exact nature of the threats were not elaborated, the article emphasizes the vulnerability of VPN users to such impersonation attempts.
To stay safe, the piece suggests verifying domain names carefully and using official app stores or bookmarks for accessing VPN services. This incident underscores ongoing cybersecurity challenges in the digital privacy sector, where trusted brands become prime targets for cybercriminals.
No further contradictions or additional timelines were noted in the available information.