u/LuisCosta_

Surfshark Research: Tech companies have paid $3.5 billion in AI fines since 2022. 9 out of 10 cases come down to one issue: consent

Surfshark Research: Tech companies have paid $3.5 billion in AI fines since 2022. 9 out of 10 cases come down to one issue: consent

Hey everyone!

Not that long ago our research team looked into every major AI-related fine and settlement since 2022 to see which companies were penalized, how much they paid, and what they were penalized for.

The total: over $3.5 billion across 10 cases involving 7 companies. The pattern is pretty clear. 9 out of 10 cases came down to the same issue: using people's data to train AI without proper consent.

Here's what stood out:

  • Meta paid $1.4 billion for collecting biometric data to train facial recognition without consent.
  • Clearview AI has been fined $105 million by four separate European regulators for scraping billions of facial images. It hasn't paid any of them, arguing it has no physical presence in Europe.
  • Google was fined $291 million for training AI on copyrighted and personal data without authorization.
  • OpenAI was fined $17 million by Italy's data protection authority, but an Italian court later annulled it, showing how uncertain AI regulation still is.

Full study with methodology: https://surfshark.com/research/chart/ai-related-fines

With AI training becoming so widespread, do you feel like you still have a say in where your data ends up, or does it feel like privacy is becoming impossible to manage?

u/LuisCosta_ — 10 days ago

I'm a Surfshark researcher who spent two weeks getting scammed on purpose — here's how a network of 39 fake airline support groups operates on Facebook

Recently, I started digging into fake airline support groups on Facebook. Not just spotting them, but actually engaging to see how the scam plays out from the inside.

The backstory: if you search Facebook for airline customer support, complaint pages, or refund help for major European airlines, you'll find groups that look legitimate. We identified 39 of them. Combined, they had 220,018 members. The patterns across these groups (naming conventions, admin behavior, post templates) suggest this isn't a bunch of individual scammers. It's a coordinated impersonation network.

Their standard pitch: "Send us your refund money, and we'll book you a new flight."

So I did what any curious researcher would do. I made contact, played along, and recorded the call. The person on the other end was calm, professional, and had a polished script. If you'd just had a flight canceled and were stressed and looking for help, this would feel like real customer service.

I've posted the full call recording on YouTube for anyone who wants to hear exactly how it goes: https://youtu.be/xGheklCS9MI?si=Qw0iF_XeAF4b8iRY

And here’s the link to the full research: https://surfshark.com/blog/facebook-airline-scam-network

A few things worth noting:

  • These groups target people at their most frustrated (canceled flights, missed connections, refund issues);
  • The scam relies on urgency and trust. They sound like they know what they're doing;
  • Facebook's group moderation doesn't seem to catch these at scale. 39 groups were still active when we ran this research.

If you've ever searched for airline help on social media, you've probably scrolled past one of these. Happy to answer questions about my experiment and anything else that we found out.

u/LuisCosta_ — 17 days ago

You asked where Mistral was in our chatbot data collection ranking. Here's what we found.

When we published our updated data collection ranking of the top 10 chatbots on the App Store a few months ago, a fair few of you flagged the same thing in the comments: where's Mistral? At the time, it hadn't hit the popularity threshold we use for inclusion, but a lot of you were curious, so we ran the numbers separately.

How it breaks down (Vibe by Mistral):

  • 2 data types linked to users: name and email Address, used strictly for app functionality;
  • 4 data types not linked to users (anonymized): three from user content and diagnostics for app functionality, one product interaction data point used for analytics.

No health data, no precise location, no financial category, no advertising data. For reference:

  • Meta AI: 33
  • Google Gemini: 23
  • ChatGPT: 17
  • Claude, Poe, DeepSeek: 13 each
  • Industry average: 14
  • Vibe by Mistral: 6

One extra thing worth flagging.

Mistral is also the only chatbot on the leading list that's headquartered in Europe. The other 11 apps in the landscape (per Zapier's most recent roundup) are all US-based, except for DeepSeek (China). Whether jurisdiction matters to your threat model is a personal call, but for people who care about GDPR jurisdiction data handling, it's not a small detail.

Standard caveat

Numbers reflect what developers self-declare in App Store nutrition labels. That's a useful common denominator, but it's a floor, not a ceiling, and it doesn't cover what happens to your prompt content once it lands on their servers. Treat the ranking as a comparative signal, not the full picture.

TL;DR

Vibe by Mistral (formerly Le Chat) collects 6 data types, based on App Store disclosures pulled in June 2026. That's less than half the 14-type industry average from our earlier study, and nearly three times less than ChatGPT.

Curious to hear from anyone here who has tried Vibe by Mistral. How does it hold up in practice for the tasks you use ChatGPT or Gemini for?

Happy to answer questions on methodology.

u/LuisCosta_ — 24 days ago

Are official app stores actually safe? 2.2 million apps were removed in 2025 for privacy violations, fraud, and more.

We looked into the latest transparency reports from Google and Apple to see how many apps got pulled from their stores in 2025 and why.

The numbers: nearly 2.2 million apps removed, roughly 6,000 per day.

  • On Google Play, 44% of removals were for data protection and privacy violations;
  • On the App Store, 54% were removed for fraud;
  • Apple rejected nearly 1 in 4 app submissions before they went live. Google rejected 1 in 10;
  • Google Play Protect blocked 266 million risky installs on top of that;
  • Apple terminated over 193,000 developer accounts, a 32% increase from the year before.

One interesting trend: Google Play removals actually dropped by half compared to 2024. Apple's more than doubled.

Official app stores are still the safest place to download apps, but the numbers show they're far from perfect. Worth checking reviews, permissions, and the developer before you install anything.

Full study: https://surfshark.com/research/chart/removed-apps-2025

How do you decide whether an app is safe to install?

u/LuisCosta_ — 1 month ago

We analyzed 15 mobile browsers and their location data practices. 8 collect your location even though browsers don't need it to function.

u/LuisCosta_ — 2 months ago

How to avoid ticket scams: we surveyed 1,000 people on how fake ticket purchases actually happen

u/LuisCosta_ — 2 months ago

How safe is your credit card info after buying merch from your team's online store? We analyzed 25 cyberattacks targeting sports organizations to find out.

u/LuisCosta_ — 3 months ago

Can you spot AI bots on social media? We built a game to test it.

Hey everyone! We partnered with master’s students from Malmö University who built a bot-detection game, and we'd love for you to try it.

It drops you into a simulated social media comment section and gives you 120 seconds to figure out which comments were written by a bot and which were real. Four different topics, 10 bot comments to find.

So far, 710 people have played, and nearly half couldn't beat it. We're curious how this community does.

Give it a go and share your results here: https://botornot.one/

u/LuisCosta_ — 3 months ago

Can you opt out of AI training on social media? We studied 10 platforms. Reddit doesn't even give you the option.

u/LuisCosta_ — 3 months ago

Can you tell a bot from a real person? We tested it. Nearly half of people failed.

Hey everyone!

We partnered with master’s students from Malmö University who built a bot-detection game where 710 players had to spot AI-generated comments in a simulated social media feed. The game tested players across four topics, two neutral (data centers, pineapple on pizza) and two emotionally charged (immigration, women's rights).

Some highlights:

  • Only 53% of participants won the game. The average player caught just 58% of bots;
  • Reddit and X users tied for the best bot-detection rate at 68%. Facebook users scored low at 47% and were the most likely to falsely accuse real people of being bots;
  • This was the big one: topic matters. On data centers, players caught 71% of bots. On immigration, that dropped to 54%. On women's rights, it fell to 49%. The more emotional the topic, the more bots slipped through unnoticed;
  • You'd think being online all the time would sharpen your instincts. It doesn't. Moderate users who check social media a few times a day actually outperformed people who are online almost constantly;
  • And all of this is happening while fake accounts cost as little as $0.08 to create. Platforms deleted 6.3 billion fake accounts and 11.1 billion spam content pieces last year.

The game is still live if you want to test yourself: https://botornot.one/

Full study with methodology: https://surfshark.com/blog/bot-detection-experiment

How often do you engage with a comment before even considering it might not be a real person?

u/LuisCosta_ — 3 months ago

What topic should our research team investigate next?

Hey everyone! I'm Dr. Luís Costa, Surfshark's Research Lead. For those who don't know, we run data-driven studies on digital privacy, cybersecurity, and how tech affects everyday life.

Some of our recent work:

We're picking what to dig into next and want to hear from you! 🫵

What topic in online privacy, cybersecurity, or digital habits would you want to see us research? Could be something that bugs you, something you've been curious about, or a question you think nobody's actually answered with real data yet.

Throw your ideas below, nothing is off the table.

reddit.com
u/LuisCosta_ — 3 months ago

Deepfakes have been making headlines for years, but most of the conversation is about the technology itself, not the financial damage it's doing.

So we pulled 7 years of fraud data from the AI Incident Database, Resemble.AI, and the OECD to find out who's losing money, how much, and what people should actually watch out for. Here's what stood out:

  • Deepfake fraud has caused $2.19 billion in global losses, with $1.65 billion of that reported in 2025 alone;
  • The most effective scam? Using deepfakes of celebrities and government officials to push fake investment opportunities, accounting for 52% of all losses. Think of all those deepfaked Elon Musk crypto ads you've probably scrolled past, or the Brad Pitt scam that made the news not long ago;
  • The US leads globally at $712 million, with 43% from corporate attacks. Remember the Hong Kong case where a finance worker joined a video call with deepfaked versions of his colleagues and transferred $25 million? That's the kind of thing driving these numbers;
  • The US also accounts for 99.9% of all deepfake family impersonation losses worldwide. Imagine getting a call from your mom in a panic asking for money, except it's not actually her voice, it's a clone. That's already a $124 million problem.

Full research → https://surfshark.com/research/chart/deepfake-fraud-countries

How do you see deepfake scams evolving from here? Do you have a plan to protect yourself, or does it feel like one of those things that's hard to prepare for?

u/LuisCosta_ — 4 months ago

Hey everyone,

So every January, like clockwork, fitness searches spike globally. This year, interest in personal training hit its highest point since 2022. A lot of that growth is being driven by AI — apps promising personalized coaching at a fraction of what a human trainer costs.

That made us curious. If these apps are using AI to personalize your experience, what are they actually collecting to make that happen?
We went through Apple App Store privacy disclosures and privacy policies for five of the most popular workout apps — Strava, Nike Training Club, Peloton, LADDER, and Fitness+. The gap between them was... pretty wide:

  • Strava collects 20 out of 35 data types linked to your identity — location, purchase history, photos, search history, the works. Nike Training Club sits at 19;
  • Peloton? Just 2;
  • 4 out of 5 track you across other apps and websites. Fitness+ was the only one that doesn't;
  • All 5 have AI features. Some, like Strava, openly state they use your data to train their AI models.

The methodology of the study: we used Google Trends to track global search interest in "fitness" and "personal training" from January 2022 onward. For the data collection analysis, we selected apps from a CNET list based on the largest number of monthly active users in 2025 (via Similarweb), and reviewed their Apple App Store privacy disclosures and privacy policies for AI-related practices.

You can check the full research → https://surfshark.com/research/chart/ai-fitness

Do you use any of these apps? Did any of these findings surprise you?

u/LuisCosta_ — 4 months ago