A recent research project, led by Prof. Sze Yiu Chau from the Department of Information Engineering, found that many VPN setups around the globe are insecure. The discovered vulnerabilities allow a network attacker, such as a rogue hotel or café Wi-Fi operator, to easily and stealthily obtain the passwords of users when they attempt to connect to their organizational VPNs. Additionally, some vulnerabilities even enable hackers to take over control of the user's device, which can cause additional damages.