The internet security software provider, Avast!, sold hundreds of millions of people’s highly sensitive and personal web browsing data through a subsidiary company, Jumpshot.
Avast! has a huge number of 435 million active users per month, of which Jumpshot has data from 100 million devices. Avast! have free and paid products, which partly explains their large user base, and many free users have stated that they were unaware of their data being sold and had not agreed to this. It is likely that the Avast! free product was subsidised by or founded on (or both!) monetising user data in this way
An investigation by Motherboard and PCMag found that Avast! – via Jumpshot – sold personal data to many of the world’s biggest companies such as Google, Yelp, Microsoft, McKinsey, Pepsi and Home Depot. It was revealed that the Avast! software installed on users’ computers collects data, and that Jumpshot repackages it into various different products that are then sold on. It was shown that some clients paid millions of dollars for data that included a “All Clicks Feed,” which tracks user movement across all their browsing in precise detail.
In many cases, this data was to remain confidential between the company selling and the clients purchasing. Employees from companies including Expedia, IBM, Intuit, Loreal, and Home Depot, for example, were instructed not to talk publicly about their involvement. Microsoft declined to comment on the specifics of why it purchased such data, and stated that it doesn’t have a current relationship with Jumpshot.
The data obtained through the investigation shows that specific information, such as Google searches, lookups of locations, LinkedIn page visits, particular YouTube videos, and websites visited were shared. From the collected data, it is possible to determine what date and time a user visited sites, and in some cases what search term they entered into these sites.
Avast! first collected user data through a browser plugin which was they said was intended to “warn users of suspicious websites”. When this was previously exposed, browser makers Google, Mozilla and Opera removed Avast!’s browser extensions. After this, Avast! stopped collecting data through browser plugins but instead began to collect data through their core software itself.
Since this investigation was published, just last week, Avast! began asking its existing users to opt-in to data collection, despite most being completely unaware their data was being collected previously.
The investigation has had a significant impact, which Avast! seems to have recognised. Avast! has published that their relationship with Jumpshot and data collection will be terminated with immediate effect. However, it is clear Avast! was abusing customer data and privacy without their knowledge.
Despite their response, we recommend that you cease using all Avast! software, even if you have a paid license.
This is a good example of a company providing a seemingly beneficial service and/or piece of software that is in fact masquerading to do something else. As with many things online, if it seems too good to be true then it very likely is too good to be true!
