Military Audit: ExpressVPN
Target: ExpressVPN (consumer VPN; Express Technologies Ltd / ExpressVPN Inc; owned by Kape Technologies plc) Domain: Military (Military / Defence) Date: June 2026 Scope: ExpressVPN’s own military/defence-nexus conduct re Israel. Parent Kape Technologies plc, owner Teddy Sagi, and sibling brands (CyberGhost, Private Internet Access, ZenMate) are attributed at the parent/owner/sibling level except where noted as foundational context.
Parent/owner-level context (foundational ownership facts only): Kape Technologies plc, ExpressVPN’s parent since September 2021, is a British-Israeli company whose co-founder Koby Menachemi served in IDF signals-intelligence Unit 8200 and whose CEO Ido Erlichman served in the IDF’s Duvdevan Unit.12 Majority owner Teddy Sagi donated 1 million shekels in 2023 to transport IDF soldiers to the front.3 These facts are recorded here for completeness; they are attributed to Kape/Sagi at the parent/owner level, not to ExpressVPN as an operating entity.
Direct Defence Contracting & Procurement
No public evidence identified of ExpressVPN (Express VPN International Ltd / Express Technologies Ltd) holding any defence or military procurement contract with any government, including Israel, the Israeli Defence Forces, or any Israeli Ministry of Defence entity.
ExpressVPN operates a consumer-facing “military VPN” marketing page.4 Live retrieval of that page confirms it is a standard commercial retail offering aimed at individual service-members - it promotes personal streaming access and family connectivity while deployed, carries standard consumer pricing plans, and includes a 30-day money-back guarantee.4 No government-to-government or B2G procurement language, no military-specification certifications, and no reference to official contract vehicles appear anywhere on the page.4
Searches for ExpressVPN or its registered entity names in association with Israeli defence tenders, IDF procurement, or any formal military contract returned no results.5
Dual-Use Products & Tactical Variants
No public evidence identified of ExpressVPN developing or supplying a tactical or military-variant product to any defence authority.
As a consumer VPN service, ExpressVPN’s core product (encrypted tunnelling software) falls within EAR Category 5 Part II (encryption software / 5D002) under US Bureau of Industry and Security rules.6 Consumer-grade VPN products of this class are broadly licensable under EAR License Exception ENC and do not require individual export licences for distribution to most civilian end-users.6 No BIS enforcement action, export-licence denial, or commodity classification dispute involving ExpressVPN or Express VPN International Ltd has been identified in public records.
No evidence of a purpose-built tactical, intelligence, or signals-intelligence variant of ExpressVPN software has been identified.
Heavy Machinery, Construction & Infrastructure
No public evidence identified. ExpressVPN is a software and consumer-services company. It owns no physical manufacturing, construction, or heavy-engineering capability. No connection to settlement construction, military base infrastructure, or Israeli Defence establishment real-estate has been identified in any retrieved source.
Supply Chain Integration with Defence Primes
No public evidence identified of ExpressVPN holding a supplier or sub-contractor relationship with any Israeli or international defence prime - such as Elbit Systems, Rafael Advanced Defense Systems, IAI, Boeing, Lockheed Martin, or BAE Systems.
Searches for “ExpressVPN” combined with Israeli defence contractors, supply chain integration, and military technology partnerships returned no relevant results.5
Logistical Sustainment & Base Services
No public evidence identified. ExpressVPN provides no base operations, logistics support, fuel, catering, transportation, or facilities-management services to any military installation in Israel or elsewhere.
A search combining “ExpressVPN,” “logistical sustainment,” and “base services” returned no relevant results; the only hits were generic US military sustainment doctrine pages and an unrelated reference.7
Munitions, Weapons Systems & Strategic Platforms
No public evidence identified. ExpressVPN is a consumer digital-privacy company. No retrieved source connects ExpressVPN to the manufacture, sale, maintenance, or financing of munitions, weapons systems, aircraft, naval vessels, armoured vehicles, or any strategic platform in use by any military actor.
Export Licensing, Regulatory & Legal History
The legally significant finding in this domain concerns a senior ExpressVPN executive, not the company itself. Daniel Gericke served as ExpressVPN’s Chief Information Officer from December 2019 until July 2023.8
Prior to joining ExpressVPN, Gericke worked as a contractor for the UAE-based company DarkMatter between January 2016 and November 2019, operating within the covert “Project Raven” programme.9 Project Raven involved former US intelligence and military operatives building and deploying zero-click iOS exploitation tools (“Karma” and “Karma 2”) on behalf of UAE government authorities to surveil human-rights activists, journalists, the Emir of Qatar, and Yemeni opposition figures.910
In September 2021 the US Department of Justice announced a deferred prosecution agreement (DPA) with Gericke and two co-defendants (Marc Baier and Ryan Adams).10 Gericke admitted to violations of the Arms Export Control Act and the International Traffic in Arms Regulations (ITAR) - specifically the unauthorised furnishing of “defense services involving electronic systems, equipment, and software … specially designed for intelligence purposes” to UAE nationals and the UAE government without State Department authorisation.1011 Under the DPA he agreed to forfeit $335,000, cooperate fully with US authorities, and relinquish all security clearances.10 He was subsequently administratively debarred by the State Department on 5 August 2022, barring him from ITAR-regulated activities for at least three years.11
Attribution note: Gericke’s ITAR violations occurred entirely during 2016–2019, before his engagement with ExpressVPN (which began December 2019) and before Kape Technologies’ acquisition of ExpressVPN (September 2021).89 The conduct was therefore personal pre-employment; no charge, civil penalty, debarment notice, or regulatory enforcement action was directed at ExpressVPN as a corporate entity.1011 The DPA explicitly covers only the three named individuals.
ExpressVPN stated publicly that it was aware of “key facts” of Gericke’s employment history before hiring him and that he “disclosed them proactively and transparently,” though the company stated it only learned of the finalised DPA on 7 September 2021.12
Israel nexus: No Israel-related dimension to Gericke’s ITAR violations or the DPA has been identified. The violations concerned UAE government surveillance activities; no Israeli entity, IDF unit, or Israeli intelligence agency is named in any retrieved court filing, DPA document, or media account.91011
There is no public record of ExpressVPN as an entity facing any export-licence denial, BIS enforcement action, or ITAR/EAR regulatory proceeding.
Civil Society Scrutiny & Documented Investigations
Gericke / Project Raven scrutiny: The September 2021 DOJ announcement triggered significant civil-society and media attention directed specifically at ExpressVPN. Edward Snowden publicly warned users to stop using ExpressVPN in light of Gericke’s employment history.13 Internal ExpressVPN employees raised formal concerns, with at least one publicly posted protest questioning the company’s transparency and core values.14 Privacy watchdog and media outlets - including VICE, TechRadar, TechTarget, and Cybernews - published critical investigations of ExpressVPN’s decision to retain Gericke and its claim that his background was an asset rather than a liability.81215
These critiques focused on the tension between ExpressVPN’s stated privacy mission and the employment of an executive who had participated in a state offensive-surveillance programme. However, no civil society investigation has identified a direct connection between this matter and Israel or the Israeli-Palestinian conflict.
Israeli ownership scrutiny: Following Kape Technologies’ acquisition of ExpressVPN in September 2021, advocacy outlets published analyses raising concern about the Israeli ownership and leadership background of Kape Technologies and the implications for user privacy.123 These analyses attribute military and intelligence connections to Kape’s founders and Teddy Sagi - not to ExpressVPN as an operating entity - and no civil society body has published a documented investigation finding ExpressVPN’s own acts to constitute military or defence complicity with Israel.
No report from the Electronic Frontier Foundation, Privacy International, Citizen Lab, or Amnesty International has been identified specifically investigating ExpressVPN’s own conduct in relation to Israeli military or defence matters.16
End Notes
Footnotes
-
https://blog.boycat.io/posts/expressvpn-israeli-ownership-1b-privacy-risk ↩ ↩2
-
https://hackread.com/israeli-firm-kape-technologies-expressvpn-privacy/ ↩ ↩2
-
https://www.middleeasteye.net/live-blog/live-blog-update/outcry-over-expressvpn-ownership-what-israeli-connection-means-user ↩ ↩2
-
https://www.bis.doc.gov/index.php/policy-guidance/encryption/15-policy-guidance/encryption ↩ ↩2
-
https://www.govx.com/a/d7d3284d-4774-4361-df6e-08ddd5281e63/expressvpn ↩
-
https://cybernews.com/news/expressvpn-cio-daniel-gericke-fined-335-000-for-cyber-espionage/ ↩ ↩2 ↩3
-
https://therecord.media/us-fines-former-nsa-employees-who-provided-hacker-for-hire-services-to-uae ↩ ↩2 ↩3 ↩4
-
https://siliconangle.com/2021/09/14/former-nsa-employees-fined-working-uae-hacking-company/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
https://cyberscoop.com/former-us-intelligence-ops-state-department/ ↩ ↩2 ↩3 ↩4
-
https://www.vice.com/en/article/expressvpn-uae-hacking-project-raven-daniel-gericke/ ↩ ↩2
-
https://www.techradar.com/news/edward-snowden-warns-expressvpn-users-to-ditch-the-service-immediately ↩
-
https://www.vice.com/en/article/expressvpn-employees-ask-questions-project-raven/ ↩
-
https://www.techtarget.com/searchsecurity/news/252506801/ExpressVPN-stands-behind-CIO-named-in-UAE-hacking-scandal ↩
-
https://citizenlab.ca/2024/07/vulnerabilities-in-vpns-paper-presented-at-the-privacy-enhancing-technologies-symposium-2024/ ↩