Avast was installed on 435 million devices as antivirus protection. Through its subsidiary Jumpshot, it sold those users' complete browsing histories — every URL, every search, timestamped to the second — to Google, Pepsi, Sephora, Home Depot, and over 100 other companies. The FTC fined Avast $16.5 million in 2024. The antivirus you installed to protect yourself was the biggest spyware on your computer. Avast told users the data it sold through Jumpshot was "anonymous" and "de-identified." The FTC proved that was false — each user was assigned a unique persistent identifier that linked every website visit back to their individual device. Researchers at PCMag and Vice's Motherboard obtained leaked Jumpshot data and were able to identify specific users from their browsing patterns. "Anonymous" meant "we gave you a number instead of your name.".
What they claim: 'Avast does not sell user data' and data is 'anonymized.'
What we found: FTC charged Avast with deceiving users. Unique browser identifiers allowed re-identification. Data sold in non-aggregate form. Avast settled for $16.5M and accepted 20-year monitoring.
What they claim: Avast's kernel-level access is used solely for security protection.
What we found: Antivirus has deepest system access: kernel scanning, real-time monitoring, web filtering, HTTPS inspection. Avast used this to harvest browsing data for commercial sale. The security tool became the surveillance tool.
What they claim: Avast HTTPS scanning protects users from encrypted threats while maintaining security.
What we found: Avast's HTTPS scanning is enabled by default (confirmed February 2026) and installs a root CA certificate to intercept all encrypted traffic. CISA Alert TA17-075A warned this practice "drastically reduces connection security." The NDSS 2017 study by Google, Mozilla, Cloudflare and three universities found antivirus HTTPS interception introduced support for known-broken ciphers in 10-40% of connections. Avast — already fined $16.5M for selling 8 petabytes of browsing data — now has default access to decrypt every HTTPS connection on users' machines. The company caught selling browsing data still has, by default, the ability to read all encrypted traffic.
What they claim: Avast protects user privacy by blocking third-party tracking.
What we found: FTC: Avast sold 8 petabytes of browsing data from 435M+ users through Jumpshot to 100+ companies (Google, Microsoft, Pepsi). Every click, search, purchase with unique identifiers. $16.5M fine, 20-year compliance order.
What they claim: Browser extensions provide additional security.
What we found: Researcher Wladimir Palant: extensions collected complete browsing history with unique user IDs. Mozilla and Google removed from stores. Extensions sent far more data than needed.
What they claim: AVG is a separate, independent product.
What we found: Avast acquired AVG ($1.3B, 2016). Same engine, same Jumpshot pipeline. Now both under Gen Digital (Norton parent, $8.1B acquisition 2022). Six brands, one company.
What they claim: Jumpshot was shut down and data practices reformed.
What we found: Closed Jan 2020 only after media exposure. FTC ordered deletion of data AND algorithms. 20-year monitoring. Gen Digital owns the same infrastructure. Consumer payments began Dec 2025 -- 6 years later.