Researchers say software vendors routinely collect customer and business data and incorporate it into commercial products.
Table of Contents
Table of Contents
Spy on Any Website
Get traffic data and keyword intel on competitors instantly.
New research says software vendors are routinely collecting far more customer data than is needed and using it to build commercial products.
The findings come from Clark Barron, founder of Blackout, a company that provides GTM threat intelligence through forensic analysis of marketing software. His research examines browser code, JavaScript, network traffic, and application behavior to compare what vendors say their products do with what the software actually does after it’s installed.
“The thing that really opened the floodgates for me was when I uncovered an actual defeat device in theebsite visitors. By defeat device, I mean actual, like Volkswagen Dieselgate, like hiding — hiding from compliance auditors — hiding from CIPA litigators, and things like that.”
Barron found that the code called two different servers depending on whether it detected it was being inspected. If it identified signs of automated analysis or compliance auditing, it disabled its tracking functionality. If it detected what appeared to be a normal visitor, the tracking code executed as expected.
Barron says the practice is widespread.
“I’ve analyzed over 700 vendors, and it’s growing by the day, and no one’s clean,” Barron said. “There are a few analytics platforms, not attribution, but analytics platforms that are as clean as it gets, but when you venture into the realm of actual marketing software, like ABM vendors, intent data providers, all of that, de-anonymization — absolutely not. No. No one’s clean.”
How and why this happens
Marketing departments routinely connect software to CRM systems, marketing automation platforms, customer support platforms, analytics systems, and AI tools. Those integrations usually give vendors access to customer records, sales pipelines, service tickets, emails, and internal communications, including information Barron says is unnecessary for the services they provide.
“Why does an intent data provider need access to your data to provide you with a product?” said Barron. “[They’re] taking all of your CRM data, all of your internal communications, every single byte of data that they can get on your company, laundering it through their own aggregation machines, and then just selling it back to your competitors.”
Vendors are allowed to connect to all those data sources because marketers don’t view the integrations as security decisions and think of vendors as partners, not adversaries.
“[Marketers] don’t ever think, ‘Gosh, this thing is interacting with my data. I wonder what it’s doing with my data,’” said Chris Penn, co-founder and chief data scientist at Trust Insights.
Even when marketers ask that question, most lack the technical expertise to verify the answer themselves.
“When we’re talking about marketers and sales professionals … it’s just not their discipline, they are not technical enough to know that there are red flags even,” said Barron. “There is a huge operational security failure point happening … all these vendors have access and full visibility into your internal communications that you think are private.”
10X your SEO with Semrush for Enterprise.
The world’s most powerful SEO platform, purpose-built for Enterprise.
Request demo
AI expands the exposure
AI increases the risk by allowing connected systems to exchange data and instructions with less human oversight. Model Context Protocol (MCP) lets AI systems connect to external applications, data sources, and tools.
“When you install an MCP, you are connecting to somebody else’s computer,” said Penn. That “means that if you don’t know what instructions an MCP is giving, you could be dealing with data exfiltration.”
Last month, HubSpot got into trouble for just that. That’s when it came to light that the company had changed its terms of service to take enrichment data from one company and use it to enrich or supplement another company’s records. Then it automatically opted in all of its customers.
“HubSpot, in its MCP, asked the model, ‘Hey, what else are you working on?’” said Penn. “And that was a prompt that the agents would understand and answer, passing that data back. Did the marketer consent to that? Maybe, maybe not. I’m sure it’s in the terms and conditions somewhere. But did we knowingly consent with informed consent?”
Customer backlash prompted HubSpot to reverse the change days after it became public.
The bottom line
The research raises a business question alongside a security one: What happens to customer data after it leaves your systems? Barron says vendors use that information to build commercial products, meaning companies can end up contributing data that benefits competitors as well as themselves.
“Their attribution dashboards start lying to them. Their customer acquisition costs start going through the roof, and they don’t know why,” Barron said. “They don’t understand that they’re actually subsidizing their competition’s customer acquisition cost.”
Barron says many marketers misunderstand both the ownership of first-party data and how their customer information feeds commercial intent products used across the market.
“A lot of people are just now starting to realize that things like intent data … it’s ‘Soylent Green,’” Barron said. “‘Soylent Green’ is people. It’s your own data just being repackaged and sold back to you.”
MarTech is owned by Semrush. We remain committed to providing high-quality coverage of marketing topics. Unless otherwise noted, this page’s content was written by either an employee or a paid contractor of Semrush Inc.
Google’s “preferred sources” feature allows users to customize their search results by selecting news outlets they want to see more often in the “Top Stories” section.
