Avast fined $16.5 million for ‘privacy’ software that actually sold users’ browsing data
Avast, the cybersecurity software company, is facing a $16.5 million fine after it was caught storing and selling customer information without their consent. The Federal Trade Commission (FTC) announced the fine on Thursday and said that it’s banning Avast from selling user data for advertising purposes.
From at least 2014 to 2020, Avast harvested user web browsing information through its antivirus software and browser extension, according to the FTC’s complaint. This allowed it to collect data on religious beliefs, health concerns, political views, locations, and financial status. The company then stored this information “indefinitely” and sold it to over 100 third parties without the knowledge of customers, the complaint says.
A joint investigation from Motherboard and PCMag first brought attention to Avast’s data privacy practices in 2020. Avast shut down its data harvesting arm, called Jumpshot, shortly after the reports emerged. Although Avast said it removed identifying information before selling user data, the FTC found it “failed to sufficiently anonymize consumers’ browsing information.” Instead, it sold data with unique identifiers for each browser, revealing websites visited, timestamps, the type of device and browser used, and location.
The FTC also claims Avast deceived users by saying its software would help eliminate tracking on the web — when it actually did the tracking itself. In addition to a $16.5 million fine, the FTC’s proposed order prevents Avast from misrepresenting what it does with the data it collects. It must stop “selling or licensing any browsing data” from Avast products to advertisers, as well as delete all of the web browsing data obtained by Jumpshot. Avast is also required to notify affected customers that their data has been sold without their knowledge.
“We are committed to our mission of protecting and empowering people’s digital lives,” Avast spokesperson Jess Monney said in a statement to The Verge. “While we disagree with the FTC’s allegations and characterization of the facts, we are pleased to resolve this matter and look forward to continuing to serve our millions of customers around the world.”
The FTC has been cracking down on poor data privacy practices in recent weeks. In January, the FTC reached a settlement with Outlogic (formerly X-Mode Social) that prevents the data broker from selling information that can be used to track users’ locations. It banned InMarket from selling precise user locations as well.
Update February 22nd, 5:56PM ET: Added a statement from Avast.
Avast, the cybersecurity software company, is facing a $16.5 million fine after it was caught storing and selling customer information without their consent. The Federal Trade Commission (FTC) announced the fine on Thursday and said that it’s banning Avast from selling user data for advertising purposes. From at least 2014…
Recent Posts
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023