Technique
ISP Data Harvesting
Also known as: ISP Surveillance, ISP Data Collection, Supercookie Tracking, UIDH Tracking
Exploitation of an Internet Service Provider's privileged position in the network to collect, aggregate, and monetize subscriber data. ISPs can observe all unencrypted traffic, DNS queries, connection metadata, and browsing patterns. Techniques include deep packet inspection (DPI) to analyze packet…
Common attack flows
How it fits in a scam
Before
This is often where the scam begins.
Defense
How to defend against this
How to spot it
- Unexpected targeted ads based on private browsing activity not shared on social media
- Receiving marketing from third parties related to obscure or niche browsing topics
- ISP privacy policy changes or opt-out notifications indicating new data-sharing programs
- Presence of injected HTTP headers (X-UIDH) visible in network traffic analysis
- Personalized scam contacts referencing specific ISP subscription details
Tools you can use
Steps you can take
Further reading
Vice / Motherboard
Report on FTC study finding ISPs collect and sell extensive subscriber data including location, browsing, demographics, and IoT device activity
ExpressVPN Blog
Analysis of FTC report showing ISPs collect data unnecessary for service delivery including race, sexual orientation, and political affiliation
EFF - Verizon X-UIDH
Details on Verizon injecting persistent supercookie headers into all unencrypted mobile traffic for cross-site tracking
EPIC - Deep Packet Inspection
Overview of DPI privacy concerns including ISP use for behavioral profiling, ad targeting, and content monitoring without consent