CipherWatch All articles
Password & Account Security

Guarding the Guards: How Antivirus Vendors Turned Your Security Software Into a Surveillance Tool

CipherWatch
Guarding the Guards: How Antivirus Vendors Turned Your Security Software Into a Surveillance Tool

For most Americans, installing antivirus software feels like a responsible act—a digital seatbelt fastened before merging onto the information superhighway. The implicit contract seems straightforward: the user grants the software deep, privileged access to their system, and in return receives protection from malware, ransomware, and other threats. What that contract rarely makes explicit is what happens to the trove of behavioral data the software collects in the process of performing its stated function.

The answer, in a number of documented cases, is that the data is packaged, analyzed, and sold.

The Architecture of Trusted Access

Endpoint security software occupies an unusually powerful position on any device it inhabits. To do its job effectively, an antivirus or internet security suite must monitor running processes, inspect network traffic, read file system activity, and track application behavior in real time. This level of access—far deeper than nearly any other consumer application—is granted on the assumption that the vendor will use it exclusively for protective purposes.

That assumption has proven optimistic.

In 2020, a joint investigation by Motherboard and PCMag revealed that Avast, one of the world's most widely installed security vendors, had been harvesting granular browsing data from its users and routing it through a subsidiary called Jumpshot to sell to corporate clients including major retailers, advertising agencies, and investment firms. The data included records of individual web searches, Google Maps queries, LinkedIn profile visits, and YouTube viewing histories—all theoretically anonymized, but structured in ways that researchers demonstrated could be re-identified. The exposure prompted Avast to shutter Jumpshot and issue a public apology, but the episode illustrated how completely the security software model can be repurposed for commercial data extraction.

Avast was not an isolated case. Researchers and privacy advocates have documented telemetry practices across a wide range of security vendors that, while sometimes less egregious, share the same structural problem: the software collects far more than it needs to perform its protective function, and the surplus data flows toward revenue streams that users never consented to fund.

What "Telemetry" Actually Means

Security vendors routinely defend their data collection under the umbrella of "telemetry"—a term that sounds technical and neutral, and that covers a legitimate core practice. Sharing anonymized threat signatures and suspicious file hashes with a vendor's cloud infrastructure genuinely improves detection rates across the user base. That is a defensible, even beneficial, use of aggregated data.

The problem arises when telemetry expands to encompass detailed behavioral profiling that has no plausible connection to threat detection. Logging which websites a user visits, how long they spend on specific pages, which applications they open in sequence, and what search terms they enter does not make the software better at catching malware. It makes the vendor better at selling advertising insights.

Privacy researchers point to a structural incentive that explains the drift. Security software is often sold at low cost or distributed free, particularly to consumers. The business model requires a revenue source beyond the sticker price, and behavioral data—collected at scale from millions of users who have granted kernel-level access to their machines—is extraordinarily valuable. The temptation to monetize that access is, in the absence of strong regulatory guardrails, almost irresistible.

The Regulatory Blind Spot

Federal privacy law in the United States does not comprehensively regulate the collection or sale of behavioral data by software vendors. The Federal Trade Commission has authority to pursue unfair or deceptive trade practices, and the Avast case ultimately resulted in a 2024 FTC settlement requiring the company to pay $16.5 million and prohibiting it from selling user browsing data. That outcome, while meaningful, required a years-long investigation and addressed conduct that had already affected hundreds of millions of users.

Beyond FTC enforcement actions, there is no sector-specific statute governing what endpoint security vendors may collect, retain, or sell. State-level frameworks such as the California Consumer Privacy Act provide some protection for residents of participating states, but coverage is uneven and enforcement resources are limited. For the majority of American consumers, the primary protection against exploitative telemetry practices is the vendor's privacy policy—a document that, studies consistently show, almost no one reads and fewer still fully understand.

The irony is not subtle. The regulatory frameworks designed to protect consumer data from corporate exploitation contain a gap large enough to accommodate the very tools consumers purchase to protect themselves.

Evaluating Endpoint Security With Privacy in Mind

The practical challenge for consumers is that abandoning endpoint protection entirely is not a realistic response to these concerns. Malware threats are genuine, and unprotected systems face real risks. The goal, rather, is to select tools that perform their stated function without doubling as surveillance infrastructure.

Several criteria are worth examining before committing to any security product.

Audit the privacy policy with specificity. Generic language about "improving our services" or "sharing data with trusted partners" is a warning sign. A vendor genuinely committed to privacy should be able to specify, in plain language, exactly what data is collected, how long it is retained, and under what circumstances it is shared with third parties. Vague disclosures are not accidental.

Investigate the vendor's business model. A free product has to generate revenue somewhere. If a security suite is available at no cost and the vendor does not clearly explain how it sustains operations, data monetization is a plausible answer. Paid products are not automatically trustworthy, but the financial pressure toward data commercialization is structurally lower.

Look for independent audits. Some vendors submit their products to third-party privacy and security audits and publish the results. This practice is not universal, but it provides a degree of external accountability that self-reported compliance cannot.

Consider open-source or minimalist alternatives. For technically proficient users, open-source endpoint tools offer the advantage of code transparency—the community can inspect what the software actually does, rather than relying on vendor assurances. Windows Defender, Microsoft's built-in security solution, has matured considerably and operates under a different set of commercial incentives than independent vendors whose revenue depends on data sales.

Review permissions and opt-out options. Many security products include settings that allow users to limit telemetry sharing beyond the minimum required for threat detection. These options are not always prominently displayed, but they exist. Taking the time to configure them is a meaningful, if partial, mitigation.

The Deeper Problem

The antivirus telemetry issue is, at its core, an instance of a broader pattern that CipherWatch has documented across multiple sectors: the tools and platforms Americans rely on for safety, convenience, and connection are increasingly designed to extract value from the very users they purport to serve. Security software is simply a particularly uncomfortable example, because the access it requires is so extensive and the trust it demands is so complete.

Choosing an endpoint security product now requires the same skeptical scrutiny that consumers are beginning to apply to social media platforms, smart home devices, and data brokers. The question is no longer simply whether the software stops viruses. It is also whether the software respects the person it was installed to protect.

In the absence of comprehensive federal privacy legislation, that scrutiny falls entirely on the individual user—which is, it must be said, an unreasonable burden to place on anyone who simply wanted to keep their computer safe.

All Articles

Related Articles

One Number to Rule Them All: The SIM-Swap Epidemic Draining Bank Accounts and Crypto Wallets Across America

One Number to Rule Them All: The SIM-Swap Epidemic Draining Bank Accounts and Crypto Wallets Across America

The Body as Password: Why Biometric Authentication Carries Risks That No Security Patch Can Fix

Recycled and Compromised: How Credential Stuffing Turns Yesterday's Data Breaches Into Today's Account Takeovers

Recycled and Compromised: How Credential Stuffing Turns Yesterday's Data Breaches Into Today's Account Takeovers