Fired for Watching Netflix on the Company VPN

By — SDET & creator of findWhatIsMyIP.com · 2026-09-04

A corporate laptop with a VPN client, at night

This story runs backwards. It opens where it ended — a man in a waiting room who cannot explain a gap on his CV — and works back to the small, ordinary moment that caused it. The names and the company are invented. The mechanics are not. If your employer gave you a VPN, read to the last line.

The interview he can't finish

It is a hot Karachi afternoon and Bilal is on his third BPO interview this month. The recruiter is warm right up until she looks at the dates. “You were at Cedarline for four months. Why did you leave?” He says, “Restructuring.” She writes something down. They will call Cedarline. He knows what Cedarline will say.

Four months earlier he had the job he wanted: a US client, the night shift, a salary his family was proud of, and a laptop he liked carrying through the building. The laptop came with a VPN that switched on by itself every morning. That VPN is the reason he is in this waiting room. A company VPN is not a perk you own. It is company property, with company rules, and company logging — and he learned each of those the expensive way.

Day 118 — the room with the printout

The meeting was short. HR on one side of the table, a security lead joining by video from the United States. A single sheet slid across: a table of timestamps and domain names. netflix.com, nflxvideo.net, dazn.com, primevideo.com, row after row, most of them stamped between 1 a.m. and 5 a.m. — his shift. He had told himself the whole time that it was encrypted, that nobody could see. The security lead explained, without any heat in his voice, exactly what they had seen and how. Termination for cause: violation of the acceptable-use policy, and misuse of paid working time. No notice. No severance. He signed, and handed back the laptop.

What a VPN actually hides. A VPN encrypts the link between your device and the VPN server. On a corporate VPN, your employer runs that server, so your traffic is decrypted there before it goes anywhere else. Even if they never look inside the contents, they can see every destination domain (from your DNS queries and the unencrypted server name in the TLS handshake), how much data moved, and exactly when. On a managed laptop there is almost always a company certificate installed that lets the corporate proxy read full URLs and page contents as well. “It's encrypted” protects you from the coffee-shop Wi-Fi and from your home internet provider. It does not protect you from the people who operate the VPN. See what a VPN is for the fundamentals.

Day 96 — a line in a bandwidth report

Rewind three weeks. A network analyst at Cedarline runs the routine monthly review of VPN capacity. One account is pulling forty to seventy gigabytes a day through the tunnel, almost all of it from Netflix's content-delivery network and a sports streaming service. He opens the workforce-management export for the same account: marked “available” for the whole shift, call handle-time drifting up, after-call work growing. He checks whether it is one person. It is not — there is a small cluster of five accounts, and the timing and traffic shape say they all learned the trick from the same place. That place is Bilal.

Assume the network is monitored. Company networks log traffic by default: flow records, DNS logs, data-loss-prevention tools, cloud access security brokers, endpoint agents. Nobody is sitting and watching one employee. But the totals get reviewed on a schedule, and anything unusual gets a name attached to it. “One person streaming will never get noticed” is a bet against every monitoring system the company already paid for. At scale you are simply a row in a report, waiting for someone to sort by volume.

Day 60 — “just connect to the office VPN”

A month before that, in the smoking area, Bilal is showing two teammates something on his phone. “Connect to the office VPN, open Netflix — full US catalogue. Same on Prime. It's basically a free upgrade.” Within a week it is five people. Nobody thinks of it as stealing anything. The VPN was already running; the subscriptions were already paid for at home; the shows are just… in a better region now.

Geo-unblocking on a work VPN drags the company in. When staff use the employer's VPN to hop regions, the employer's US IP addresses start to look, from Netflix's side, like a place where lots of accounts suddenly change country. Streaming services blacklist address ranges that behave like that. The range that gets flagged is the same one the company's real US staff and systems use, so a support engineer in Virginia suddenly cannot load an internal tool that allow-lists that address, or the company's own business streaming account starts throwing errors. You are not risking only your job. You are degrading shared infrastructure other people depend on, in order to break a service's terms, using equipment that was never yours to point at it. Our guide to entertainment uses of a VPN covers where this crosses a line even on your own connection.

Day 12 — the extra seasons

Second week on the job. Three in the morning, a quiet stretch between calls. Out of habit Bilal opens Netflix on the work laptop and notices that Suits has three more seasons than it does at home, and a film that has always been “not available in your region” simply plays. It takes him a minute to work out why. The laptop's internet does not come out of Karachi. It comes out of a data centre in Virginia, because everything the laptop does is routed through head office first. He opens a “what is my IP” page to be sure: Ashburn, United States. It feels like he has found a cheat code.

A full-tunnel VPN makes all your traffic wear the company's location. Many corporate VPNs are “full tunnel”: every packet from the laptop — work or not — goes to headquarters, is inspected and filtered, and leaves through the company's own internet connection. That is deliberate. It lets remote staff reach internal systems safely and lets security see everything for threat detection and compliance. A side effect is that consumer services see the company's country instead of yours. That side effect exists for security. It is not a feature for you to use. If you want to see where your own devices come out, that is what What Is My IP and IP to Timezone are for.

Day 1 — “I have read and agree”

Onboarding. IT sets up the laptop, installs the always-on VPN client, and walks him through a stack of documents. One of them is the Acceptable Use Policy. He scrolls to the bottom and clicks I have read and agree, the way everyone does. The parts he did not read: company systems and networks are provided for business purposes; users must not use them to circumvent geographic or content restrictions; all activity on company systems and networks is logged and may be reviewed at any time.

The acceptable-use policy is the document that decides everything. Every phrase that later mattered was already in it — “business purposes,” “must not circumvent,” “logged and may be reviewed.” It is dull on purpose and almost nobody reads it. It is also the line between “a bit cheeky” and “terminated for cause.” If a company hands you a device, read the one page that says what you are allowed to do with it.

What he'd tell himself now

Back in the waiting room. If Bilal could send one message to the version of himself sitting at that desk on day twelve, it would be five lines:

  • The VPN your employer gives you belongs to your employer. Treat every connection through it as logged and tied to your name.
  • A VPN changes where your traffic appears to come from. It does not make you invisible to whoever runs the VPN — and on a work VPN, that is your employer.
  • Anything you would not do with your manager reading over your shoulder, do not do on the company tunnel.
  • For personal streaming or privacy, use a personal VPN, on a personal device, on your own internet connection. Keep the two worlds apart.
  • Read the acceptable-use policy once. The single time it matters, it decides whether you keep your job.

He did not get the job that afternoon. He got the next one, two weeks later, at a smaller firm — and on his first day he read every page they gave him.

Frequently asked questions

Can my employer see what I browse on the company VPN?

Yes. The company runs the VPN server, so your traffic is decrypted there before it continues to the internet. Even without opening the contents they can see which sites you connected to, how much data you moved, and when. Managed laptops usually also carry a company certificate that lets the corporate proxy read full URLs and page content.

Can I be fired for using a work VPN to watch Netflix?

Yes, and often for cause — meaning no notice and no severance — under acceptable-use and misuse-of-time policies, especially when it happens during paid working hours.

Does a VPN hide my streaming from my employer?

No. A VPN hides your activity from the local network and your home internet provider. It does not hide anything from whoever operates the VPN, and on a corporate VPN that operator is your employer.

Is using a company VPN to change Netflix region illegal?

It is generally not a criminal matter. It breaches the employer's acceptable-use policy and the streaming service's terms of service. The consequences are disciplinary, up to dismissal, rather than legal.

What should I use instead for personal streaming?

A personal VPN subscription running on your own phone or laptop, on your own home or mobile internet. Never route personal activity through equipment or a network your employer owns.

Related reading: What is a VPN?, 8 ways a VPN is used for entertainment, What is a proxy?, Changing your IP address for Netflix. · Tools (for your own devices): What Is My IP, IP to Timezone, IP WHOIS Lookup.

Awesome findWhatIsMyIP Blog