By 2026, the strange afterlife of Avast's privacy scandal had become a cautionary tale for anyone who ever trusted a free or paid antivirus tool with their browsing life. Almost 3.7 million people were deemed eligible to collect money from a $16.5 million settlement with the Federal Trade Commission (FTC). The case centered on Avast, a popular antivirus and security software company, which the FTC said collected and sold customer data for years without proper consent. For customers who bought Avast products between August 2014 and January 2020, the settlement briefly turned an old software purchase into an unexpected claim number and a possible check.

The story began long before the emails arrived. The FTC alleged that Avast misrepresented how it would share browsing information collected from some of its products. That information was not merely technical noise. According to the agency, it included sensitive details such as religious beliefs, political leanings, location data, and financial information. Avast then allegedly sold that data through a subsidiary called Jumpshot to more than a hundred companies. For a brand whose browser extension once used the tagline 'Browse With Privacy,' the irony was difficult to miss.

avast-s-16-5-million-privacy-settlement-what-3-7-million-users-learned-by-2026-image-0

Starting on February 24, 2025, the FTC opened the claim process. The agency's notice said eligible customers would receive an email with a Claim Number. From there, they could visit the official settlement claims portal, enter the number, and apply for a payment online. Those who did not receive an email but knew they had bought an Avast product during the covered period could contact the FTC's refund administrator for support. The payment amount, the FTC warned, would depend on several factors, including how many people filed a claim. That meant a refund might not equal what a customer originally paid in the 2010s, though it could possibly exceed that amount.

avast-s-16-5-million-privacy-settlement-what-3-7-million-users-learned-by-2026-image-1

By 2026, the initial claim window had ended, and the settlement had moved from breaking news into privacy lore. For those who filed on time, the waiting game was familiar: the more claimants who participated, the more the $16.5 million pot would be divided. For those who missed the deadline, the FTC's refund administrator remained the only sensible point of contact, though late claims were not guaranteed to be accepted. The episode still offered a clear reminder that consumer settlements can be worth pursuing when the fund is large and the wrongdoing is well documented.

Avast has said it shut down Jumpshot in 2020 and promised to delete all Jumpshot data. It also reached out to companies that had bought the data and asked them to do the same. In its own language, Avast described the FTC's allegations as involving 'misrepresentation' rather than intentional stealing. The distinction mattered legally, but for consumers, the outcome still felt like a breach of trust. A security company that promised protection had allegedly turned private browsing signals into a product for advertisers.

Settlement Detail What Happened
Company Avast
Allegation Misrepresenting how it shared browsing data
Settlement amount $16.5 million
Eligible purchase window August 2014 to January 2020
Claim opening date February 24, 2025
Eligible people About 3.7 million
Payment factors Number of claims filed and other factors
Data involved Religious beliefs, political leanings, location, financial information
Subsidiary accused of selling data Jumpshot

Why did the Avast settlement matter so much? 🛡️ First, it showed that privacy violations can carry a price even when the conduct is buried in terms of service and product design. Second, it demonstrated that users do not need to be famous or powerful to become part of a major consumer action. Third, it underlined a simple truth: antivirus software, browser extensions, and other security tools should never become surveillance engines by another name.

For the millions of people who bought Avast between 2014 and 2020, the settlement was a rare moment of accountability. Some received emails. Some filed claims. Some ignored the notice, assuming it was junk. By 2026, the whole affair had become a lesson in reading the fine print, watching for FTC alerts, and treating privacy claims as more than pennies on the dollar. The pot was large enough that applying felt productive, especially for those who remembered paying for software that was supposed to keep them safe.

⏳ The timeline also mattered. The case covered purchases from August 2014 through January 2020, a period when many users were less aware of how much browsing data could be repackaged and sold. The FTC's action arrived later, but it reached backward, offering compensation to people who might have forgotten which security suite they installed years earlier. That long lookback made the settlement unusual and, for many claimants, unexpectedly nostalgic.

🔍 In the end, the Avast saga was not just about one company or one $16.5 million fund. It was about the hidden economy of personal data and the ways ordinary software can blur the line between protection and exploitation. As 2026 unfolded, privacy-focused search engines, tracker blockers, and stricter browser settings had become more common alternatives for users who no longer wanted to be the product. The Avast case did not fix the entire problem, but it did give millions of people a reason to ask who was watching, what was being sold, and whether a familiar security brand deserved their trust.