Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Avast antivirus harvested user data, then sold to Google, Microsoft

Last updated

The Mac and Windows version of Avast antivirus has been used to harvest user data, an investigation claims, with some sensitive info sold to third parties, including Google, Microsoft, and Intuit.

Avast offers a selection of free and paid-for antivirus and security tools, in both free and in paid-for formats. The tools are popular, with more than 435 million active users per month using it on Macs, PCs, and mobile devices, to keep their data safe from harm.

As part of its offerings, Avast's software provides the option to opt-in to allowing the firm to collect some types of user data, which it then sells on via subsidiary Jumpshot. An investigation by Vice and PC Mag using leaked user data, contracts, and other documents has revealed both the extent of these sales, as well as the breadth of the data being sold by the firm.

Data acquired for the investigation revealed the information collected by Avast is wide-ranging, including Google searches, location look-ups and GPS coordinates from Google Maps, LinkedIn pages, and YouTube video listings. More disturbingly, records porn site visits that are anonymized offer the date and time the user visited the sites, as well as search terms and viewed videos in some instances.

Despite the efforts to anonymize the data, some experts claimed the highly specific browsing data could be used to find out identities.

A wide net

The amount of data being collected may not be well advised to consumers of Avast, with the investigation advised by multiple users they were not aware of the sale of said browsing data.

The subsidiary claims it has data from 100 million devices, with the investigation claiming Jumpshot repackages data collected from Avast into a number of different packages. This also includes a so-called "All Clicks Feed" option, where clients paid millions of dollars to be able to track a user's behavior and movement across websites.

The list of clients include many major firms, such as Google, Yelp, Microsoft, and Pepsi.

Collecting the data was, until recently, conducted via Avast's browser plugin, one that provides warnings to the user about suspicious and malicious websites. A report by security researcher and AdBlock Plus creator Wladimir Palant in October revealed the plugin was used to harvest data in October, prompting Mozilla, Opera, and Google to remove access to Avast's extensions.

Avast told the investigation in a statement it has stopped providing browsing data collected by the extensions to Jumpshot.

The investigation further found from a source and leaked documents that Avast is still performing harvesting, but via the anti-virus software itself, rather than the browser plugins. In the last week, an internal document reveals Avast has started asking users of the free antivirus tool to opt-in to data collection once again.

"If they opt-in, that device becomes part of the Jumpshot Panel and all browser-based internet activity will be reported to Jumpshot," a line of text from an internal handbook advised. The data collected, according to the document, would answer questions about what URLs a user visited, as well as when and in what order.

Lucrative data

The data is a lucrative income for Avast. In copies of contracts with Jumpshot clients, one marketing firm paid over $2 million for data access in 2019, which provided an "Insight Feed" for 20 domains from 14 countries around the world.

That data included the inferred gender of users based on browsing behavior, their age, the "entire URL string" with personally identifiable information removed, and other details. Device IDs are "hashed" to prevent identification of individuals by clients, but as the device IDs do not change for a user unless they completely reinstalled Avast tools, this could allow for a large swathe of data on one user to be built up over time, leading to possible identification down the line.

Avast informed the investigation "because of our approach, we ensure that Jumpshot does not acquire personal identification information, including name, email address, or contact details, from people using our popular free antivirus software." The company went on in a statement to reiterate users had the ability to opt out of sharing data, and that it had started "implementing an explicit opt-in choice for all new downloads of our AV" as of July 2019, with all existing free users prompted to make a choice by February 2020.

It was also insisted Avast complies with the California Consumer Privacy Act and Europe's GDPR across its entire global user base. "We have a long track record of protecting users' devices and data against malware, and we understand and take seriously the responsibility to balance user privacy with the necessary use of data," the statement pressed.



20 Comments

supremedesigner 18 Years · 85 comments

Ohhh snap!!!

That is why I don't download Avast or any freebies. I wondered if CCleaner does the same thing by selling the infos to 3rd parties?

Gaby 6 Years · 194 comments

So google, in an obvious PR stunt played the sheep and revoked access to the extension even though they were slyly paying for the data being collected. I guess they didn’t count on being outed as one of their customers...  

Why anyone would willingly opt in to data collection in the first instance is what I will never understand. Their needs to be some sort of education for people to understand best practices for and why they should be protecting their identity and personal information. Not to mention some firm laws put in place governing any and all collection and or sale of that data because these conniving corporations will simply come up with ever more creative ways of spying on and monetising individuals. 

gatorguy 13 Years · 24627 comments

Ohhh snap!!!

That is why I don't download Avast or any freebies. I wondered if CCleaner does the same thing by selling the infos to 3rd parties?

The reportedly used to (at least share) a couple years ago and like Avast claimed it was all anonymized and unidentifiable. I thought an update last year gave users a lot more control over that but you'd have to research it to be sure. FWIW Avast does own them now. 

gatorguy 13 Years · 24627 comments

Gaby said:
So google, in an obvious PR stunt played the sheep and revoked access to the extension even though they were slyly paying for the data being collected. I guess they didn’t count on being outed as one of their customers...  
Why anyone would willingly opt in to data collection in the first instance is what I will never understand. Their needs to be some sort of education for people to understand best practices for and why they should be protecting their identity and personal information. Not to mention some firm laws put in place governing any and all collection and or sale of that data because these conniving corporations will simply come up with ever more creative ways of spying on and monetising individuals. 

Sometimes companies call it analytics for "improving the app and/or user experience". It can still end up collecting user data for other purposes. We all tend to allow it tho when they make it sound so innocuous, and in fact it's the default in a lot of operating systems and applications. You have to actively opt out. 

As for Google, Microsoft etc buying data it was apparently from Jumpstart and almost certainly predated the Avast purchase of the company this past year. Jumpstart FWIW was a fairly well-regarded and very well-known "analytics" firm who dealt with a wide swath of big businesses who needed reliable information on internet marketing: Site traffic, where leads originate, browser shares, conversion rates, etc. Heck Apple themselves might have purchased data from them as they were a trusted source on various web metrics and site visits and a useful resource for those spending money on web advertising. 

The problem is when the companies we trust to protect us from harvesting are doing the harvesting themselves. That's why all the large browsers, Mozilla, Google, Microsoft etc removed the Avast browser extensions after being advised that that they were pulling user data via their malware detection software without disclosing where and what it was being used for. At least that's what I'm reading. 

cy_starkman 16 Years · 653 comments

mac anti virus software is the virus

wow, so windows