Sophos researchers find 25 “fleeceware” apps on the Play Store, installed by 600M+ users, that abuse the apps' free trial mechanic to charge obscene fees
Context & Ripple Effects
Sophos' January 2020 disclosure marks the moment 'fleeceware' got a name: 25 Play Store apps with 600M+ installs that stay inside Google's rules while weaponizing the free-trial mechanic against users. It is the subscription-era successor to an older Play Store abuse pattern — the premium-SMS apps secretly charging users via text messages that researchers flagged back in 2017.
What makes this report matter is how it reframed app-store fraud from rule-breaking to rule-abuse: these apps pass review because they disclose their terms, just in ways designed to be missed. The pattern did not stay contained — Sophos went on to find the same trial-abuse playbook among top-grossing iOS apps within months (30+ fleeceware apps on the App Store), and the count kept climbing.
First-order effects
- Google faces immediate takedown pressure on 25 specific apps reaching an install base of over 600 million, while users who signed up for 'free trials' are being billed recurring fees they did not meaningfully consent to.
- Sophos converts its research into a named category — fleeceware — giving both stores and security buyers a label for a threat class that previously looked like ordinary apps.
Second-order effects
- Apple's App Store gets pulled into the same scrutiny, since the trial mechanic is shared infrastructure — and indeed the same researchers surfaced the pattern there months later, including among highest-grossing apps.
- App-store operators face pressure to redesign trial-to-subscription flows themselves, because review teams cannot catch abuse that is technically compliant — shifting the burden onto billing UX and refund policy rather than malware scanning.
Third-order effects
- If the trajectory holds — from 25 apps here to the 204 fleeceware apps researchers catalogued across both stores a year later — subscription-trap design becomes a persistent gray-market industry living inside official storefronts, forcing platforms to police intent rather than code.
- Consumer trust in free trials erodes structurally, pushing legitimate developers toward harder paywalls upfront and giving regulators a fresh angle on app-store billing practices.
The trend: Mobile app fraud is migrating from overt technical exploits like premium-SMS dialers toward legally compliant subscription traps that exploit store mechanics, scaling faster than platform review can catch.