Protecting over 200 million PCs, Macs, & Mobiles – more than any other antivirus

July 8th, 2014

Tens of thousands of Americans sell themselves online every day

The Internet has become a virtual flea market, with online consumer-to-consumer sites like Amazon, eBay, and Craigslist selling millions of products every day. Used smartphones are a popular sales item on eBay – more than 80,000 people list their phones for sale each day. It seems like a smart way to make some extra money, but AVAST has found out that many fail to protect their identity in the process. 

AVAST recovers an abundance of personal data from used smartphones 

Most sellers delete all of their personal data prior to selling their used devices… or so they think. We purchased 20 used Android phones off eBay and used simple and easily available recovery software to restore deleted files. The amount of data we were able to retrieve was astonishing and proves that simply deleting is not enough.

Our analysts found the following:

  • More than 40,000 stored photosUsed Smartphones for Sale
  • More than 1,500 family photos of children
  • More than 750 photos of women in various stages of undress
  • More than 250 selfies of what appear to be the previous owner’s manhood
  • More than 1,000 Google searches
  • More than 750 emails and text messages
  • More than 250 contact names and email addresses
  • Four previous owners’ identities
  • One completed loan application

One phone even had a competitor’s security software installed, but unfortunately it did not help the former owner as it revealed the most personal information out of all the phones we analyzed. 

No one cares about my old photos, messages and Google searches, right?

Wrong! As the old saying goes, a picture is worth a thousand words. Now add private Facebook messages that include geo-location, Google searches for open job positions in a specific field, media files, and phone contacts. Put all of these pieces together to complete the puzzle and you have a clear picture of who the former smartphone owner was. Stalkers, enemies, and thieves can abuse personal data to stalk, blackmail and steal people’s identities. They can use this information to watch people’s every move, exploit their strange fetishes, open credit cards in their name, or even continue what they started by further selling their personal information online. 

How to permanently delete and overwrite data from your Android phone 

Deleting files from your Android phone before selling it or giving it away is not enough. You need to overwrite your files, making them irretrievable. To do so, install avast! Anti-Theft from the Google Play Store for free. Once you have the app installed, turn on the “thorough wipe” feature within the app. You will then need to create a my.avast account to connect to the phone (this allows users to remotely wipe their phones in theft cases as well). The final step is to wipe the phone clean, which will delete and overwrite all of your personal data. 

AVAST Used Smartphone Infographic

Read about our investigation:

Android Forensics, Part 1: How we recovered (supposedly) erased data

Thank you for using avast! Antivirus and recommending us to your friends and family. For all the latest news, fun and contest information, please follow us on FacebookTwitter and Google+. Business owners – check out our business products.

  1. osm
    July 9th, 2014 at 17:26 | #1

    Interesting post.

    I have a question. You recommend using avast! Anti-Theft to help protect the phone. As I understand it, the benefit of this is to enable a remote wipe that will properly wipe the phone (which might not be the case with other remote wipe products).

    I am also interested in whether or not I need to protect my data from the possibility of a thief removing flash memory prior to me having a chance to issue a remote wipe command (or just after a remote wipe command has been issued). Does avast! Anti-Theft offer any protection in this scenario or is it impossible for someone to read the flash memory once it has been removed from the phone (therefore protection for this scenario not needed)?

  2. July 9th, 2014 at 21:46 | #2

    @osm
    Hi osm,
    Thanks for your question. Yes, we recommend avast! Anti-Theft for the benefits you mentioned: you can lock it remotely and geo-locate the thief. But if a thief removes the SD card from the device before you run the wipe via anti-theft, then the data will not be deleted.

    Jaromír Hořejší, one of the authors of the upcoming series on the forensics performed on each of the phones, suggests encrypting your data, “If the thief physically removes the the external memory before the remote wipe starts, then of course such data won’t be deleted. The thief can put the memory card into a card reader and use PC to download all the data stored on it. However, data on external storage could be encrypted. See the article here,
    http://www.techverse.net/encrypt-android-phones-external-sd-card/

  3. icewin
    July 13th, 2014 at 13:58 | #3

    Which versions of Android are affected?

  1. July 8th, 2014 at 17:17 | #1
  2. July 8th, 2014 at 17:58 | #2
  3. July 8th, 2014 at 21:26 | #3
  4. July 8th, 2014 at 21:36 | #4
  5. July 8th, 2014 at 21:48 | #5
  6. July 8th, 2014 at 22:36 | #6
  7. July 9th, 2014 at 01:34 | #7
  8. July 9th, 2014 at 06:16 | #8
  9. July 9th, 2014 at 07:55 | #9
  10. July 9th, 2014 at 09:47 | #10
  11. July 9th, 2014 at 10:01 | #11
  12. July 9th, 2014 at 10:22 | #12
  13. July 9th, 2014 at 10:24 | #13
  14. July 9th, 2014 at 10:26 | #14
  15. July 9th, 2014 at 10:26 | #15
  16. July 9th, 2014 at 11:01 | #16
  17. July 9th, 2014 at 11:15 | #17
  18. July 9th, 2014 at 11:37 | #18
  19. July 9th, 2014 at 11:45 | #19
  20. July 9th, 2014 at 12:46 | #20
  21. July 9th, 2014 at 13:08 | #21
  22. July 9th, 2014 at 13:12 | #22
  23. July 9th, 2014 at 13:15 | #23
  24. July 9th, 2014 at 13:32 | #24
  25. July 9th, 2014 at 13:41 | #25
  26. July 9th, 2014 at 14:01 | #26
  27. July 9th, 2014 at 14:08 | #27
  28. July 9th, 2014 at 14:23 | #28
  29. July 9th, 2014 at 14:51 | #29
  30. July 9th, 2014 at 15:21 | #30
  31. July 9th, 2014 at 16:15 | #31
  32. July 9th, 2014 at 16:24 | #32
  33. July 9th, 2014 at 16:27 | #33
  34. July 9th, 2014 at 16:32 | #34
  35. July 9th, 2014 at 16:43 | #35
  36. July 9th, 2014 at 16:46 | #36
  37. July 9th, 2014 at 16:59 | #37
  38. July 9th, 2014 at 17:06 | #38
  39. July 9th, 2014 at 18:12 | #39
  40. July 9th, 2014 at 18:23 | #40
  41. July 9th, 2014 at 18:52 | #41
  42. July 9th, 2014 at 18:57 | #42
  43. July 9th, 2014 at 19:59 | #43
  44. July 9th, 2014 at 20:14 | #44
  45. July 9th, 2014 at 20:15 | #45
  46. July 9th, 2014 at 20:50 | #46
  47. July 9th, 2014 at 21:12 | #47
  48. July 9th, 2014 at 21:31 | #48
  49. July 9th, 2014 at 22:12 | #49
  50. July 9th, 2014 at 22:27 | #50
  51. July 9th, 2014 at 22:31 | #51
  52. July 9th, 2014 at 22:32 | #52
  53. July 9th, 2014 at 23:08 | #53
  54. July 9th, 2014 at 23:43 | #54
  55. July 10th, 2014 at 00:11 | #55
  56. July 10th, 2014 at 00:15 | #56
  57. July 10th, 2014 at 00:33 | #57
  58. July 10th, 2014 at 00:54 | #58
  59. July 10th, 2014 at 01:20 | #59
  60. July 10th, 2014 at 01:39 | #60
  61. July 10th, 2014 at 03:00 | #61
  62. July 10th, 2014 at 03:27 | #62
  63. July 10th, 2014 at 03:29 | #63
  64. July 10th, 2014 at 03:55 | #64
  65. July 10th, 2014 at 04:27 | #65
  66. July 10th, 2014 at 05:16 | #66
  67. July 10th, 2014 at 05:47 | #67
  68. July 10th, 2014 at 07:06 | #68
  69. July 10th, 2014 at 07:22 | #69
  70. July 10th, 2014 at 09:16 | #70
  71. July 10th, 2014 at 09:57 | #71
  72. July 10th, 2014 at 10:12 | #72
  73. July 10th, 2014 at 14:29 | #73
  74. July 10th, 2014 at 14:49 | #74
  75. July 10th, 2014 at 15:21 | #75
  76. July 10th, 2014 at 16:17 | #76
  77. July 10th, 2014 at 17:11 | #77
  78. July 10th, 2014 at 18:02 | #78
  79. July 10th, 2014 at 20:09 | #79
  80. July 10th, 2014 at 20:32 | #80
  81. July 10th, 2014 at 21:10 | #81
  82. July 10th, 2014 at 22:21 | #82
  83. July 10th, 2014 at 23:47 | #83
  84. July 11th, 2014 at 01:14 | #84
  85. July 11th, 2014 at 01:16 | #85
  86. July 11th, 2014 at 01:50 | #86
  87. July 11th, 2014 at 02:28 | #87
  88. July 11th, 2014 at 02:50 | #88
  89. July 11th, 2014 at 03:19 | #89
  90. July 11th, 2014 at 03:59 | #90
  91. July 11th, 2014 at 13:48 | #91
  92. July 11th, 2014 at 14:01 | #92
  93. July 11th, 2014 at 14:16 | #93
  94. July 11th, 2014 at 14:42 | #94
  95. July 11th, 2014 at 15:18 | #95
  96. July 11th, 2014 at 15:42 | #96
  97. July 11th, 2014 at 16:13 | #97
  98. July 11th, 2014 at 16:14 | #98
  99. July 11th, 2014 at 16:25 | #99
  100. July 11th, 2014 at 16:51 | #100
  101. July 11th, 2014 at 18:02 | #101
  102. July 11th, 2014 at 18:11 | #102
  103. July 11th, 2014 at 18:14 | #103
  104. July 11th, 2014 at 19:25 | #104
  105. July 11th, 2014 at 20:12 | #105
  106. July 11th, 2014 at 21:19 | #106
  107. July 11th, 2014 at 21:24 | #107
  108. July 11th, 2014 at 21:46 | #108
  109. July 11th, 2014 at 21:53 | #109
  110. July 11th, 2014 at 21:55 | #110
  111. July 11th, 2014 at 22:36 | #111
  112. July 11th, 2014 at 23:32 | #112
  113. July 12th, 2014 at 01:32 | #113
  114. July 12th, 2014 at 01:37 | #114
  115. July 12th, 2014 at 02:02 | #115
  116. July 12th, 2014 at 02:13 | #116
  117. July 12th, 2014 at 02:39 | #117
  118. July 12th, 2014 at 06:04 | #118
  119. July 12th, 2014 at 07:06 | #119
  120. July 12th, 2014 at 07:13 | #120
  121. July 12th, 2014 at 07:45 | #121
  122. July 12th, 2014 at 08:05 | #122
  123. July 12th, 2014 at 08:34 | #123
  124. July 12th, 2014 at 12:00 | #124
  125. July 12th, 2014 at 12:14 | #125
  126. July 12th, 2014 at 12:23 | #126
  127. July 12th, 2014 at 15:33 | #127
  128. July 12th, 2014 at 15:35 | #128
  129. July 12th, 2014 at 17:19 | #129
  130. July 12th, 2014 at 18:13 | #130
  131. July 12th, 2014 at 18:46 | #131
  132. July 13th, 2014 at 01:44 | #132
  133. July 13th, 2014 at 02:38 | #133
  134. July 13th, 2014 at 03:37 | #134
  135. July 13th, 2014 at 04:14 | #135
  136. July 13th, 2014 at 06:56 | #136
  137. July 13th, 2014 at 11:41 | #137
  138. July 13th, 2014 at 13:44 | #138
  139. July 13th, 2014 at 19:36 | #139
  140. July 13th, 2014 at 21:27 | #140
  141. July 13th, 2014 at 22:15 | #141
  142. July 14th, 2014 at 01:59 | #142
  143. July 14th, 2014 at 04:01 | #143
  144. July 14th, 2014 at 05:50 | #144
  145. July 14th, 2014 at 07:00 | #145
  146. July 14th, 2014 at 09:03 | #146
  147. July 14th, 2014 at 10:49 | #147
  148. July 14th, 2014 at 10:53 | #148
  149. July 14th, 2014 at 12:57 | #149
  150. July 14th, 2014 at 15:03 | #150
  151. July 14th, 2014 at 16:37 | #151
  152. July 14th, 2014 at 17:26 | #152
  153. July 14th, 2014 at 17:44 | #153
  154. July 14th, 2014 at 18:05 | #154
  155. July 14th, 2014 at 18:28 | #155
  156. July 14th, 2014 at 18:47 | #156
  157. July 14th, 2014 at 20:15 | #157
  158. July 15th, 2014 at 12:47 | #158
  159. July 15th, 2014 at 13:00 | #159
  160. July 15th, 2014 at 14:19 | #160
  161. July 15th, 2014 at 19:00 | #161
  162. July 15th, 2014 at 19:20 | #162
  163. July 15th, 2014 at 19:45 | #163
  164. July 15th, 2014 at 20:00 | #164
  165. July 16th, 2014 at 14:18 | #165
  166. July 16th, 2014 at 17:00 | #166
  167. July 16th, 2014 at 23:29 | #167
  168. July 17th, 2014 at 11:24 | #168
  169. July 17th, 2014 at 17:01 | #169
  170. July 17th, 2014 at 18:04 | #170
  171. July 17th, 2014 at 19:01 | #171
  172. July 18th, 2014 at 13:27 | #172
  173. July 20th, 2014 at 10:10 | #173
  174. July 22nd, 2014 at 08:39 | #174
  175. July 23rd, 2014 at 05:52 | #175
  176. July 27th, 2014 at 02:07 | #176
  177. July 29th, 2014 at 16:35 | #177
You must be logged in to post a comment.