Privacy Ninja



        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

FTC: ISPs Collect and Monetize Far More User Data Than You’d Think

FTC: ISPs Collect and Monetize Far More User Data Than You’d Think

The Federal Trade Commission (FTC) found that the six largest internet service providers (ISPs) in the U.S. collect and share customers’ personal data without providing them with info on how it’s used or meaningful ways to control this process.

“Many internet service providers (ISPs) collect and share far more data about their customers than many consumers may expect—including access to all of their Internet traffic and real-time location data—while failing to offer consumers meaningful choices about how this data can be used,” the FTC said.

Also Read: Employment Application Template: What Information Required

This was found as part of a study, started in 2019, into the privacy practices of U.S. broadband companies and related entities and how they collect, retain, use, and disclose info about consumers and their devices.

The six broadband providers included in FTC’s report are AT&T Mobility, Cellco Partnership (aka Verizon Wireless), Charter Communications Operating, Comcast (aka Xfinity), T-Mobile U.S., and Google Fiber.

The FTC also included in the study three advertising entities affiliated with these companies: AT&T’s Appnexus rebranded as Xandr, Verizon’s Verizon Online, and Oath Americas rebranded as Verizon Media.

Together, the six companies currently control roughly 98 percent of the nation’s mobile Internet market, according to the FTC.

The FTC also noted that these tech giants have expanded beyond fixed residential internet and mobile internet services into other areas.

By including voice, content, smart devices, advertising, and analytics services, they could further increase the volume of customer data they can collect and share with third parties.

Troubling data collection, protection, and sharing practices

“The report identified several troubling data collection practices among several of the ISPs, including that they combine data across product lines; combine personal, app usage, and web browsing data to target ads; place consumers into sensitive categories such as by race and sexual orientation; and share real-time location data with third-parties,” the FTC said.

As the FTC further discovered, the ISPs amass huge pools of sensitive consumer data and use it in ways their customers do not expect and could cause them harm, primarily when classifying them by demographic characteristics, including race, ethnicity, gender, or sexuality.

Although many ISPs claim to offer consumers choices, the choices they provide are often a sham, at times nudging them toward even more data sharing.

“Even though several of the ISPs promise not to sell consumers personal data, they allow it to be used, transferred, and monetized by others and hide disclosures about such practices in fine print of their privacy policies,” the FTC added.

“For example, several news outlets noted that subscribers’ real-time location data shared with third-party customers was being accessed by car salesmen, property managers, bail bondsmen, bounty hunters, and others without reasonable protections or consumers’ knowledge and consent, according to the report.”

Furthermore, because of their problematic privacy practices and protections, they can be at least as privacy-intrusive as large advertising platforms, given that they have direct access to their consumers’ entire unencrypted internet traffic.

Even when connecting to sites that encrypt their traffic or using VPNs, ISPs can still collect the domains their customers connect to and analyze their browsing behavior.

Also Read: Data Protection Trustmark Certification: Business Advantage

Former FCC Chair Ajit Pai blamed for current state of things

U.S. Senator Ron Wyden said in a statement following FTC’s report that Ajit Pai, the former head of the FCC, is likely the one who made it possible for tech firms to disregard their users’ privacy by harvesting and using their data for business purposes.

“If Congress needed any more proof that America desperately needs a consumer privacy law, the Federal Trade Commission’s report about internet service providers’ rampant abuse of their customers’ private, personal browsing information should be enough to get Washington to act,” Wyden said.

“Whether it’s advertisers, tech companies or Big Cable, corporate America is showing absolute contempt for the idea that consumers can control personal details about their lives. Democrats have introduced multiple comprehensive privacy bills that would crack down on this flagrant abuse.

“Finally, it’s worth remembering that former Federal Communications Commission Chair Ajit Pai opened the floodgates to ISPs’ unchecked use of browsing data when he repealed the Obama-era broadband privacy and net neutrality regulations.

“The FCC needs every tool available to stop cable companies from gouging consumers and selling their data.”



Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection


We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.


Click one of our contacts below to chat on WhatsApp

× Chat with us