Avast explains how it has been monetizing browsing habits of its users since 2013, after Mozilla and Opera removed some Avast tools from their add-on stores
Avast, the multibillion-dollar Czech security company, doesn't just make money from protecting its 400 million users' information.
Context & Ripple Effects
Avast reached multibillion-dollar scale on a free-product model, surviving McAfee and Symantec to absorb rivals like AVG in a $1.3 billion acquisition — a growth story Forbes traced back to its 1988 Czechoslovak origins just months before this piece (the company's history explains why 400 million users matter commercially).
The trigger here is distribution: Mozilla and Opera pulled some Avast tools from their add-on stores, forcing the company to publicly confirm it had been monetizing browsing habits since 2013. The arc closes later — [[a:949983|leaked documents showed the subsidiary Jumpshot sold that browsing data to clients including Pepsi, Google, and Microsoft]], and the [[a:849691|FTC ultimately charged Avast $16.5 million and barred further sales of browsing data for ads]].
First-order effects
- Mozilla and Opera's delisting cuts off Avast's browser-extension channel at the gatekeepers, while its 400 million users learn their protection software has doubled as a data-collection pipeline since 2013.
- Avast must defend the disclosure publicly rather than quietly, because the add-on store removals make its data practice a visible governance issue instead of an invisible revenue line.
Second-order effects
- Buyers of the browsing data exposed by later Jumpshot documents — Pepsi, Google, and Microsoft among them — inherit reputational exposure from a supplier whose consent practices did not hold up.
- Every other security vendor shipping browser extensions now faces the same store-review scrutiny Mozilla and Opera applied to Avast, raising the bar for what add-on ecosystems will tolerate.
Third-order effects
- The endpoint of this pattern is regulatory: the FTC's $16.5M settlement and sales ban establish that misrepresenting how security software uses behavioral data carries direct financial and operational consequences.
- Browser vendors are functioning as de facto privacy regulators — store policies enforced through delisting move faster than agencies and set the compliance floor the FTC later codified.
The trend: Security vendors that monetize user behavior through free products are losing that freedom on two fronts at once — browser platforms policing distribution and regulators policing the claims — pushing the industry toward consent-first data models.