Archive for Surfshark

Half of the top mobile apps silently collect browsing history

Posted in Commentary with tags on September 1, 2026 by itnerd

recent Surfshark analysis shows that 45% of top mobile apps collect information about the websites their users visit. Of the 40 leading Android and iOS apps analyzed across gen AI, social media, e-commerce, and messaging, 18 report collecting browsing history in their app store privacy labels.

Social media collects the most, followed by e-commerce

Nine out of 10 social media apps collect browsing history on at least one platform. Facebook, Instagram, TikTok, X, YouTube, and Pinterest collect it on both Android and iOS. Reddit, LinkedIn, and Snapchat collect it on Android only. Discord was the only social media app that collects it on neither platform.

This data helps platforms build a clearer picture of user interests, target advertising more specifically, and shape in-app feeds based on websites visited outside the app.

Half of the e-commerce apps analyzed collect browsing history on at least one platform. eBay, Shopee, and Shopify collect it on both Android and iOS, while Taobao collects it on iOS only and AliExpress on Android only. The commercial value is direct: the more these apps know about a user’s online interests, the more effectively they can recommend and advertise products. The cost is that browsing habits become increasingly difficult to keep private.

Messaging and generative AI apps also track websites visited

Three messaging apps collect browsing history: Rakuten Viber, Messenger, and LINE. Their parent companies can use this data to build more detailed profiles of users and their interests.

Collection was the least common in the generative AI category. Google Gemini was the only app of the 10 analyzed to report collecting browsing history.

METHODOLOGY

Surfshark analyzed 40 of the most popular mobile apps, 10 each in generative AI, social media, e-commerce, and messaging, selected mainly from Cloudflare’s ranking of the most popular internet services worldwide. For each app, it was recorded whether its Apple App Store privacy label reported collecting “Browsing History” and whether its Google Play Store label reported “Web Browsing History,” then compared results by platform and category. A separate set of browsers was analyzed outside the 40-app sample. For the complete research material behind this study, visit here.

Meta and Google are the most data-hungry Big Tech companies

Posted in Commentary with tags on August 20, 2026 by itnerd

new study by Surfshark reveals a significant disparity in how the world’s largest technology companies handle personal information. After analyzing 171 Apple App Store apps from Google, Apple, Microsoft, Amazon, and Meta, researchers found that Meta’s apps are the most “data-hungry,” collecting an average of 25 out of 35 possible data types, more than triple the average of Apple (7) or Microsoft (8).

The study analyzed apps across 35 unique data categories, ranging from precise location and browsing history to purchase data linked to user identity. Company averages varied widely: Meta’s apps collected 25 data types on average, followed by Google with 17, Amazon with 12, Microsoft with 8, and Apple with 7. The sample included 44 Google apps, 41 Apple apps, 40 Microsoft apps, 34 Amazon apps, and 12 Meta apps.

The seven most data-hungry apps in the study were all developed by Meta. Meta AI collected 33 data types, followed by Meta Horizon, Meta Business Suite, Meta Ads Manager, Messenger, Forum, and Facebook with 32 each. Notably, all of this data is linked directly to the user’s identity.

Google dominates TOP 40 ranking while Microsoft and Apple remain the least data-hungry

Google accounted for 29 of the 40 most data-hungry apps in the study, compared with 9 from Meta and 2 from Amazon. Google apps in that group collected between 18 and 26 data types each. Although Google’s apps collected fewer data types on average than Meta’s, its presence across the ranking highlights the scale of data collection throughout its extensive app ecosystem. Meanwhile, Amazon Alexa was the most data-hungry non-Meta app, collecting 28 data types.

Microsoft and Apple consistently ranked as the least data-hungry developers across app categories. Microsoft ranked either the least or second-least data-hungry developer in most categories, with the lone exception of Graphics & Design. Apple covered the widest range of categories (15 in total) and consistently ranked as the least data-hungry developer. For example, Apple’s 13 Utilities apps collected an average of 6 data types, compared with 17 for Google’s Utilities apps.

To see a more detailed profile of each Big Tech company, please see the blog post: https://surfshark.com/research/study/big-tech-data-collection  

$1.40 for fake engagement on social media isn’t the issue. It’s our naive attitude to scams

Posted in Commentary with tags on August 4, 2026 by itnerd

Have you ever been drawn to an advertised product when reviews and comments were all positive, with a good user experience, and a large number of views? You have most likely been tricked into content that has been boosted with fake engagement. Surfshark has revealed the true cost of fake popularity on social media, showing how genuine public interest can be overshadowed by fake engagement for just $1.40, and warns that views, comments, or followers do not confirm content legitimacy.

Chief Security Officer at Surfshark, Tomas Stamulis, explained that the primary issue is not the low cost of fake engagement itself, but rather our own naive attitude and lack of skepticism when browsing online. We often interact with and plainly trust ads or pages without recognizing them as potential scams because our mindset is not yet set to filter content and actively search for identifiers that verify legitimacy.

Surfshark’s analysis shows a clear pattern that fake views on social media posts are the cheapest form of engagement across all analyzed platforms. Prices range from $1.40 per 1,000 views on TikTok to $6.70 per 1,000 views on YouTube. By contrast, comments are the most expensive form of fake engagement on social media. Based on the available data, the average price for 1,000 comments was lowest on YouTube at $93, followed by Instagram at $104, TikTok at $140, and Facebook at $287.

According to Stamulis, social media spam filters constantly scan for bot interactions and comments. For this reason, AI, combined with human input, is needed to ensure uniqueness. As a result, when encountering high engagement and only positive comments, we should approach it with skepticism and carefully verify the legitimacy of the advertiser or product.

Scammers can fake followers or reposts to trick you

Study shows that shares, reposts, and retweets tend to be the second-most expensive form of fake engagement. TikTok is the most expensive platform on which to purchase fake shares, at $68 per 1,000, followed by Instagram and Facebook at $37 and X at $27. YouTube is an outlier, with shares costing only $17 per 1,000.

Followers and subscribers are also relatively inexpensive to purchase. The advertised price for 1,000 fake followers ranges from $14 to $20 on Facebook, TikTok, Instagram, and X. YouTube is a clear outlier, with 1,000 artificial subscribers costing $78 — more than four times the average price of followers on the other four platforms.

Stamulis shares some tips on how to verify ads or page legitimacy:

  1. Check the follower-to-engagement ratio. A legitimate account should have around 1-5% or total followers as likes. If the account has 500 000 followers, but it gets 200 likes, something is not ok.
  2. Check the actual comments section. Phrases like “Great content!”, “Love this!”, “Amazing post” most likely are fake. Comments posted within the same narrow time window and have similar phrasing can be flagged as fake.
  3. Check the growth history. There are designated tools to check the growth of the account. Sudden spikes in growth can suggest the page has fake engagement.
  4. Analyze followers. Review 10-20 profiles. Bot accounts tend to have similar username formats, account creation dates around the same period, and follow many accounts with few friends.

Guest Post: Meta’s Muse Image release highlights “consent on” crisis in AI training on social media

Posted in Commentary with tags on July 10, 2026 by itnerd

The launch of Meta’s new Muse Image tool has brought renewed scrutiny to a systemic privacy issue: the “consent on” default setting for AI training on social media. This release marks a significant shift from using data for general model improvements to a more personal and potentially invasive application of generative AI.

“While past AI developments mostly worked out of sight, Muse Image changes the game by letting users directly reference public Instagram accounts to create images using data from those posts. This shift turns the ‘consent on’ default into a critical privacy risk, as individuals have no way of knowing when their personal photos are being harvested as source material for someone else’s AI-generated content,” says Luís Costa, Research and Insights Team Lead at Surfshark.

According to a recent Surfshark study, nearly all major social media platforms prioritize AI development over user privacy by default, using active data collection for model training.

The study found that 8 out of the 10 most popular social media platforms set AI training consent to “on” by default. This “opt-out” rather than “opt-in” model means that unless users proactively navigate complex settings and forms to revoke access, their years of posts, photos, and even private interactions have likely already been integrated into training sets.

“If you’ve ever shared content on social media, it’s highly likely that your photos are already being exploited as a resource for AI training without your clear consent. Our findings revealed that because platforms lack user-friendly opt-out options, much of this data usage is effectively irreversible. Opting out today only prevents future collection, but it cannot undo the training that has already occurred,” says Costa.

The issue of using user content for AI training is also highlighted by other social media platforms, most notably Reddit, which offers no option to opt out of AI model training. Its vast forum discussions are openly used for global AI development, highlighted by contracts with Google and OpenAI to license this user-generated data. In contrast, Discord stands out as the singular exception among the 10 platforms examined. It explicitly states that it does not use user data for AI training.

For the complete research material behind this study, click here.

Note that the IT Nerd has covered mitigating this privacy breach here.

Google approved 90% of Play Store submissions, but later removed 2 million apps

Posted in Commentary with tags on June 16, 2026 by itnerd

Last year, Google and Apple removed nearly 2.2 million mobile applications from both stores, highlighting a low rejection rate: 9 out of 10 submissions to Google Play went through. Interestingly, Apple more than doubled its total App Store removals, surpassing 166,000, with fraud accounting for 54% of those removed (90,608). In contrast, Google saw a significant decline in total removals, from 3.9 million to 2 million, and its fraud-related deletions dropped to only 5% of its total removals.

Surfshark’s analysis shows that in 2025, Apple rejected 23% of submissions to the App Store, whereas Google Play’s rejection rate was nearly three times lower at 8%, meaning 9 out of 10 submissions went through. As a result, Google deleted over 2 million apps for violating its terms and conditions — nearly half the number deleted in 2024. Meanwhile, Apple’s App Store Transparency Report shows that app removals more than doubled, to nearly 167,000, compared with over 82,500 in 2024.

Fraud (54%) and the removal of obsolete software (43%) were the primary drivers behind App Store deletions. Fraud-related removals were primarily associated with developers from China (13%), Pakistan (11%), the United States (11%), Turkey (11%), and Vietnam (8%).

According to the Google Play Annual Transparency Report, the most frequent reason for removals on their platform was data protection and privacy violations (44%). Other significant factors for Google Play included the distribution of ineligible goods, services, or content (35%), infringements on consumer information (13%), and instances of fraud or scams (5%).

You can read the report here: Google and Apple removed millions of apps in 2025

Guest Post: Pressing political topics reduce people’s vigilance against bots

Posted in Commentary with tags on May 19, 2026 by itnerd

More than 700 participants took part in a week-long experiment conducted by Surfshark and MSc students from Malmö University. Of them, 53% correctly identified more bots than they wrongly flagged humans as bots on the simulated social platforms. However, nearly half (47%) failed the task. A cybersecurity expert warns that the number of people unable to tell bots from real humans on social media will continue to grow rapidly.

“The ‘Bot or Not’ game and experiment help us keep connecting the dots and better understand the influence bad bots have on us, real social media users. Earlier this year, we found that major platforms remove over 6.3 billion fake accounts every year — roughly 47 times the annual number of babies born worldwide (around 135 million). Bots are being generated by the billions, and our latest experiment shows that half of the participants can no longer tell them apart from real people. This trend will accelerate, as the technology lets bots blend in seamlessly with real human profiles,” says Justas Pukys, Senior Product Manager at Surfshark.

When our emotions take over, bots thrive

The results of the recent social media bot experiment were eye-opening. The data suggests that engaging with sensitive political or social topics may reduce people’s ability to spot bots and make them more likely to falsely accuse real people.

The moment the “Bot or Not” simulation shifted to a more emotional tone, our participants’ bot-detection skills dropped. When the debate turned political and focused on immigration, participants’ bot-detection rate dropped to 54%, meaning that nearly half the social media bots slipped right past the players. Participants’ accuracy rate also declined to 63%, showing a spike in internet paranoia when participants accused humans of being bots.

The women’s rights topic presented the biggest bot-spotting challenges. The bot-detection rate crashed to 49%, meaning users missed more bots than they found. Worse, their accuracy rate fell to 61%, showing players most often accused real human content of being bot-generated.

“In comparison, while engaging in the data centers, a more technical debate for many, users performed the largest bot-detection rate of 71% (finding the majority of the bots), and a high (76%) accuracy rate. This suggests that when not directly emotionally triggered, we could detect more AI bots and are less likely to falsely accuse real humans,” explains Luís Costa, Research Lead at Surfshark.

The “Bot or Not” game is now online for everyone to play and take part.

Can we distinguish who is who on social platforms in the future?

“The experiment’s results are novel and significant. They suggest we can’t simply ‘read’ our way out of ‘botted’ social media. Bot-detection skills appear to be shaped by age, preferred platforms, and time spent on them. But the most striking finding was that our biggest blind spot is emotion: when debates get heated, it hijacks our digital radar.

To fight back against automated deception, we don’t need better textual analysis. We need a cooler head and a deeper awareness of our own vulnerabilities,” claims Luís Costa.

Justas Pukys, a cybersecurity expert at Surfshark, shares practical recommendations.

“Don’t forget to double-check the information you find on social media. Also, don’t take everything random users post at face value. Be careful when accepting and interacting with private messages that offer you prizes, invite you to click on strange links, or try to grab your attention with lines like ‘Your family member has been in an accident!’,” he advises.

The expert also highlights the importance of digital security hygiene, such as using anti-scam tools daily. They will help you analyze the content of emails, text messages, and websites and assess whether it has been generated by bots or other attackers.

This “Bot or Not” experiment inspired the launch of Surfshark’s Cybersecurity Advocacy Fund, which provides up to €100,000 in annual financial support distributed among students, researchers, and creative cybersecurity awareness initiatives worldwide. The upcoming application process will open in September 2026 — more information will follow.

METHODOLOGY

This bot-detection study analyzed data from 710 participants who played the interactive simulation “Bot or Not.” This machine and gameplay were created by Interaction Design students from Malmö University for the UNFOLD exhibition — a design competition for universities around the world during Milan Design Week, the world’s largest trade fair. Throughout the week-long public exhibition, visitors were invited to take part in the experiment.

Please find the full research methodology here.

Cybersecurity expert explains Instagram’s bot purge and what users should do next

Posted in Commentary with tags , on May 8, 2026 by itnerd

This week, Instagram users woke up to something that is already being called The Great Purge of 2026, as the platform reportedly removed millions of fake user accounts, affecting many platform users’ follower numbers, including famous influencers and celebrities.

However, this isn’t an isolated event. Major social media platforms are constantly struggling to maintain the authenticity of their user bases. To put this in perspective, recent research from Surfshark shows that the most popular social media platforms collectively remove about 6.3 billion fake accounts and 11.1 billion pieces of spam content every year.

Tomas Stamulis, Chief Security Officer at Surfshark, shared his insights into the situation:

“While I’m convinced that the vast majority of fake accounts removed in Instagram’s latest purge were bots, I’m also sure that many legitimate users were caught in the crossfire. With the rapid evolution of AI, creating and managing bots that mimic human behavior has become incredibly simple. Instagram, being a highly visual platform, is particularly susceptible to this, as AI can easily fake engagement without the need for the complex, context-aware interactions you might see on platforms like LinkedIn.”

Stamulis notes that a purge of this scale wouldn’t be possible without the help of artificial intelligence and notes that while AI can really help with a bot problem, some legitimate accounts might be misidentified as bots in the process.

“No AI system is without its flaws, and a purge of this scale inevitably means that legitimate users get flagged as bots. A fundamental drawback of any AI system lies in its reliance on the data it was trained on. If the training data is biased or certain legitimate behaviors are underrepresented, the AI can misinterpret the actions of real users as inauthentic. For instance, if an individual consistently follows a large number of new accounts in a short period due to a niche interest or an event, the AI might interpret this as bot-like behavior, when in reality, it’s an authentic user action. These ‘false positives’ can lead not only to temporary inconvenience but also to lost revenue for businesses or damaged reputations for creators.”

If your legitimate Instagram account was impacted by the recent Instagram bot purge, a cybersecurity expert shared a few tips:

“First, immediately document everything by taking screenshots of your profile, follower count, and any notifications or error messages, as this evidence is crucial for your appeal. While going through Instagram’s official appeal process, avoid third-party services, as these can also be flagged as bot behavior. Be clear, concise, and human in your language, explaining your situation.”

Guest Post – Surrounded by bots: Social media platforms delete 6.3B fake accounts, with Facebook and X at the top of the list

Posted in Commentary with tags on March 5, 2026 by itnerd

Popular social media platforms are constantly removing massive amounts of fake accounts and spam content. Surfshark’s analysis of annual public transparency reports reveals the staggering scale of this cleanup: Facebook, TikTok, X, and LinkedIn collectively remove 6.3B fake accounts. These platforms, along with YouTube and Instagram, also remove 11.1B pieces of spam content. On the dark market, fake account prices start at $0.08.

While AI agents are learning to interact with each other on their designated social media, bots pretending to be humans continue to sink popular platforms.

“I am convinced that the majority of fake accounts on social media are bots. Especially with the evolution of AI, producing and managing bots becomes easier. On some platforms, AI can fully cover the needs of “faking”. In contrast, on others it’s not that simple — for example, on Facebook, where interaction with real people and response to context are required,” says Justas Pukys, Senior Product Manager at Surfshark.

He explains that bots are programs designed to impersonate humans. They are centrally controlled, like marionettes, and trained to deceive both systems and humans. In addition, bots can also be real people who manage several accounts with a common goal, for example, to influence social media users’ attitudes, push an agenda on a certain issue, provoke society, or show exaggerated support for certain institutions or figures.

Comparing fake account removal volumes to active users reveals the enormous scale of the monitoring and removal that social media must perform.

On some platforms, the number of annual removals rivals or even exceeds the entire active user base. For example, Facebook, with 3B active users, removes 4.5B fake accounts annually — a volume 1.5 times its user count. Similarly, X reports removing 671M accounts each year for platform manipulation and spam, a figure that surpasses its 570M active users. TikTok deletes 1B fake accounts, equivalent to over half its active user base — 1.9B.

“Considering those platforms’ size, global reach, and impact on human opinion and behavior, I wouldn’t be surprised if the number of fake accounts and content were even higher than presented in the official transparency reports. Also, I believe these numbers will continue to grow drastically in the future, unless social media finds effective ways to combat the threat,” says cybersecurity expert at Surfshark.

Real users face increasing scam risks

Given that social media is flooded with fake accounts and content, a really worrying issue is that real users can easily be scammed and harmed, both morally and financially. Consider these recommendations from Surfshark’s experts on how to avoid getting scammed:

Pay attention to suspicious account profile details: fake accounts usually have very few photos or only associative images. Usually, the account is created recently and has a vague or overly promotional bio.

Be aware of unnatural behavior: fake accounts often send friend requests to many people in a short period of time. They may immediately send you links or other suspicious offers, usually encouraging you to move the conversation to WhatsApp or Telegram quickly.

Fake accounts send repetitive or copy-paste comments: they tend to post the same message under many posts. They typically offer “too good to be true” benefits, such as crypto, giveaways, and miracle cures.

What should you do to avoid harm?

  • Don’t engage with suspicious accounts and content: don’t reply, argue, or click links;
  • Always check: look at important details such as the account’s age, bio, and number of friends;
  • Report the account and content: use the social media platform’s report feature;
  • Protect yourself: enable two-factor authentication (2FA) on your account, make your social media profile private, and avoid sharing personal details publicly.

Surfshark Says Internet censorship increased in 2025: 81 restrictions in 21 countries

Posted in Commentary with tags on January 19, 2026 by itnerd

Government-imposed internet shutdowns introduced in 2025 alone reached 2.5 billion people — about a third of the world’s 8.2 billion population, Surfshark’s annual study shows.

Key insights:

  • 2025 began with 47 internet restrictions imposed by 22 countries.
  • Throughout the year, 81 new restrictions were introduced across 21 countries, 29% increase compared to 2024.
  • Asia continues to lead the world in internet censorship cases. The governments of 10 Asian countries imposed 56 new restrictions.
  • India remained the country with the most internet restrictions (24).
  • Social media was targeted in 21 out of 81 internet restrictions introduced in 2025, a slight increase from 18 social media restrictions in 2024.
  • Telegram was the most-restricted social media platform in 2025.

You can read the research here: surfshark.com/research/study/internet-shutdowns-2025

Guest Post – AI agents, Christmas markets, and sneaky greetings: holiday scams targeting you

Posted in Commentary with tags on December 8, 2025 by itnerd

Addictive scrolling, which develops faster than you think, is not the only thing you should watch out for this holiday season. A Surfshark expert highlights the main online risks you can encounter while scrolling.

Unsupervised AI shopping agents

AI shopping agents are a booming trend, with Big Tech announcing AI updates that can buy the exact sweater you are searching for and even call the shop to ask if they have it in stock. The trend of using chatbots like ChatGPT or Gemini AI to assist you with shopping is also at its peak.

Tomas Stamulis, Chief Security Officer at Surfshark, says the risk arises when you trust AI shopping assistants entirely and without double-checking. “I sometimes use a chatbot to help me with shopping. However, I evaluate what online shops it offers because sometimes they can be scams, taking me to malicious websites. So, always review what AI suggests before purchasing, and never grant unlimited access to your financial details.”

Phone snatching in Christmas markets

Phone snatching, when street criminals take your mobile phone from your hands, usually unlocked, is a particularly common crime in crowded Christmas markets. A moment of your distraction can result in far-reaching consequences. According to Surfshark expert Tomas Stamulis, taking simple steps can help protect you from the damage caused by phone snatching. “Stay vigilant in public, especially in crowded or high-risk areas. Keep your phone out of sight when not in use. Use an anti-spying screen so people around you can’t easily see what you’re doing. Also, ensure “Stolen Device Protection” is active on iOS or “Theft Protection” on Android (depends on device) and your home and work addresses are correct.”

Sneaky links in Christmas greetings

People’s interest in creating Christmas greetings online and sharing them with loved ones does not go unnoticed by scammers. You probably receive those snappy interactive greetings via social media, email, and SMS. Thank the sender for goodwill, yet never click the links included in those greetings. If you did and were led to a strange site, we hope you didn’t provide any of your private information, such as your real name, surname, email address, telephone number, or home address.

Sorry, it’s too good to be true

Have you ever encountered a Christmas deal that seemed too good to be true? It probably was. Scammers create fake gift deals for popular and hard-to-find items to trick shoppers into falling for them. Mr. Stamulis advises being skeptical of Christmas deals that seem unrealistically good. “Always verify the offer by checking the retailer’s official website. If you spot something that seems like a ‘hot deal’, look closely at URLs and other text for typos or unusual characters, which are red flags.”

Gifting your personal data via public Wi-Fi

Free Wi-Fi is available at cafes, restaurants, train stations, hotels, and other public spaces for your convenience. It’s just that the number one rule for a privacy-conscious person is never to use free public Wi-Fi. Public networks are frequently exploited by hackers, who can intercept sensitive data, including account credentials, email addresses, passwords, and financial information. “Without an active VPN, using public Wi-Fi is insecure; it’s like gifting your personal data to total strangers,” points out Tomas Stamulis.

Christmas cleaning your private data will thank you for

Most people want to tie up loose ends before the New Year. Paying back debts, making peace with those you’ve argued with, and just finishing unfinished business. Review the apps you’ve accumulated over the year and get rid of those that just take up space. Surfshark conducted at least a few studies that revealed mobile apps to be extremely data-hungry and privacy-intrusive. Your private data will thank you for this Christmas cleaning.

ABOUT SURFSHARK


Surfshark is a cybersecurity company offering products including an audited VPN, certified antivirus, data leak warning system, private search engine, and a tool for generating an online identity. Recognized as a leading VPN by CNET and TechRadar, Surfshark has also been featured on the FT1000: Europe’s Fastest Growing Companies ranking. Headquartered in the Netherlands, Surfshark has offices in Lithuania and Poland. For information on Surfshark’s operations and highlights, read our Annual Wrap-up. For more research projects, visit our research hub.