More than 700 participants took part in a week-long experiment conducted by Surfshark and MSc students from Malmö University. Of them, 53% correctly identified more bots than they wrongly flagged humans as bots on the simulated social platforms. However, nearly half (47%) failed the task. A cybersecurity expert warns that the number of people unable to tell bots from real humans on social media will continue to grow rapidly.
“The ‘Bot or Not’ game and experiment help us keep connecting the dots and better understand the influence bad bots have on us, real social media users. Earlier this year, we found that major platforms remove over 6.3 billion fake accounts every year — roughly 47 times the annual number of babies born worldwide (around 135 million). Bots are being generated by the billions, and our latest experiment shows that half of the participants can no longer tell them apart from real people. This trend will accelerate, as the technology lets bots blend in seamlessly with real human profiles,” says Justas Pukys, Senior Product Manager at Surfshark.
When our emotions take over, bots thrive
The results of the recent social media bot experiment were eye-opening. The data suggests that engaging with sensitive political or social topics may reduce people’s ability to spot bots and make them more likely to falsely accuse real people.
The moment the “Bot or Not” simulation shifted to a more emotional tone, our participants’ bot-detection skills dropped. When the debate turned political and focused on immigration, participants’ bot-detection rate dropped to 54%, meaning that nearly half the social media bots slipped right past the players. Participants’ accuracy rate also declined to 63%, showing a spike in internet paranoia when participants accused humans of being bots.
The women’s rights topic presented the biggest bot-spotting challenges. The bot-detection rate crashed to 49%, meaning users missed more bots than they found. Worse, their accuracy rate fell to 61%, showing players most often accused real human content of being bot-generated.
“In comparison, while engaging in the data centers, a more technical debate for many, users performed the largest bot-detection rate of 71% (finding the majority of the bots), and a high (76%) accuracy rate. This suggests that when not directly emotionally triggered, we could detect more AI bots and are less likely to falsely accuse real humans,” explains Luís Costa, Research Lead at Surfshark.
The “Bot or Not” game is now online for everyone to play and take part.
Can we distinguish who is who on social platforms in the future?
“The experiment’s results are novel and significant. They suggest we can’t simply ‘read’ our way out of ‘botted’ social media. Bot-detection skills appear to be shaped by age, preferred platforms, and time spent on them. But the most striking finding was that our biggest blind spot is emotion: when debates get heated, it hijacks our digital radar.
To fight back against automated deception, we don’t need better textual analysis. We need a cooler head and a deeper awareness of our own vulnerabilities,” claims Luís Costa.
Justas Pukys, a cybersecurity expert at Surfshark, shares practical recommendations.
“Don’t forget to double-check the information you find on social media. Also, don’t take everything random users post at face value. Be careful when accepting and interacting with private messages that offer you prizes, invite you to click on strange links, or try to grab your attention with lines like ‘Your family member has been in an accident!’,” he advises.
The expert also highlights the importance of digital security hygiene, such as using anti-scam tools daily. They will help you analyze the content of emails, text messages, and websites and assess whether it has been generated by bots or other attackers.
This “Bot or Not” experiment inspired the launch of Surfshark’s Cybersecurity Advocacy Fund, which provides up to €100,000 in annual financial support distributed among students, researchers, and creative cybersecurity awareness initiatives worldwide. The upcoming application process will open in September 2026 — more information will follow.
METHODOLOGY
This bot-detection study analyzed data from 710 participants who played the interactive simulation “Bot or Not.” This machine and gameplay were created by Interaction Design students from Malmö University for the UNFOLD exhibition — a design competition for universities around the world during Milan Design Week, the world’s largest trade fair. Throughout the week-long public exhibition, visitors were invited to take part in the experiment.
Please find the full research methodology here.
Half of the top mobile apps silently collect browsing history
Posted in Commentary with tags Surfshark on September 1, 2026 by itnerdA recent Surfshark analysis shows that 45% of top mobile apps collect information about the websites their users visit. Of the 40 leading Android and iOS apps analyzed across gen AI, social media, e-commerce, and messaging, 18 report collecting browsing history in their app store privacy labels.
Social media collects the most, followed by e-commerce
Nine out of 10 social media apps collect browsing history on at least one platform. Facebook, Instagram, TikTok, X, YouTube, and Pinterest collect it on both Android and iOS. Reddit, LinkedIn, and Snapchat collect it on Android only. Discord was the only social media app that collects it on neither platform.
This data helps platforms build a clearer picture of user interests, target advertising more specifically, and shape in-app feeds based on websites visited outside the app.
Half of the e-commerce apps analyzed collect browsing history on at least one platform. eBay, Shopee, and Shopify collect it on both Android and iOS, while Taobao collects it on iOS only and AliExpress on Android only. The commercial value is direct: the more these apps know about a user’s online interests, the more effectively they can recommend and advertise products. The cost is that browsing habits become increasingly difficult to keep private.
Messaging and generative AI apps also track websites visited
Three messaging apps collect browsing history: Rakuten Viber, Messenger, and LINE. Their parent companies can use this data to build more detailed profiles of users and their interests.
Collection was the least common in the generative AI category. Google Gemini was the only app of the 10 analyzed to report collecting browsing history.
METHODOLOGY
Surfshark analyzed 40 of the most popular mobile apps, 10 each in generative AI, social media, e-commerce, and messaging, selected mainly from Cloudflare’s ranking of the most popular internet services worldwide. For each app, it was recorded whether its Apple App Store privacy label reported collecting “Browsing History” and whether its Google Play Store label reported “Web Browsing History,” then compared results by platform and category. A separate set of browsers was analyzed outside the 40-app sample. For the complete research material behind this study, visit here.
Leave a comment »