On 4 January 2025, a hacker posted on a Russian cybercrime forum claiming to have pulled 17 terabytes of data out of Gravy Analytics, a location-data broker, along with root access to the company’s servers. The sample they released held roughly 30 million location points pulled from ordinary apps — Grindr, Tinder, MyFitnessPal, flight trackers, games — and it was precise enough to place named devices at the White House, the Kremlin, Vatican City, military bases, and health clinics. Gravy Analytics had been telling investors it tracked more than a billion devices a day. A month earlier, the US Federal Trade Commission had already moved against the company and its subsidiary Venntel for selling this exact kind of data — the FTC’s complaint named tracking at medical clinics, places of worship and military installations specifically — and for supplying it to the Department of Homeland Security, the IRS and the FBI. None of that data came from a wiretap or a subpoena. It came from advertising.
The mechanism connecting an ad on your phone to a federal agency’s tracking database is real-time bidding: the system that decides, in the time it takes a page to load, which ad you’ll see. This is the first of a five-part series on the machinery of surveillance capitalism — what it is, who profits from it, and eventually, what to do about it. Part one is the machine itself: how it works, who the players are, and why the incentives point exactly where they do.
What the term describes
Surveillance capitalism is Shoshana Zuboff’s term, from her 2019 book of the same name, for a specific business model rather than surveillance in general. The pattern: a company collects far more behavioural data than it needs to run its product — not just what you bought, but how long you hovered over it, what you typed and deleted, where you were standing. Zuboff calls this excess “behavioural surplus.” That surplus is fed into models that don’t describe you so much as predict you — what you’ll click, buy, believe or do next — and those predictions, not your attention, are the actual product. They’re sold into what Zuboff calls behavioural futures markets: marketplaces where advertisers, insurers, political campaigns and, as the Gravy Analytics case shows, government agencies pay for a forecast of your future behaviour.
The auction that runs every time a page loads
The mechanism that generates most of this behavioural surplus, at a scale nothing else on the internet matches, is real-time bidding — the ad-auction system used across the modern web and most apps. Real-time bidding is not obscure or fringe adtech; it’s the reason nearly every ad you see anywhere is the one you see. Here’s what happens in the roughly 100 milliseconds between a page starting to load and an ad appearing on it.
That broadcast-to-everyone step is the part most people don’t know exists, and it’s the part that matters most. The Irish Council for Civil Liberties measured it directly in a 30-day study: as of 2022, the average American had their location and online activity broadcast this way 747 times a day, and the average European 376 times a day — figures the ICCL itself called an undercount, since Facebook’s and Amazon’s bidding traffic wasn’t included. Google alone authorised 4,698 companies to receive this data about US users. By January 2025, the Electronic Frontier Foundation put the total volume at hundreds of billions of bid requests daily across the industry; each of the eight major ad exchanges alone handles tens to hundreds of billions per day on its own. Losing a bid costs a company nothing — and the data it received while losing is now simply theirs, with no requirement to delete it, and no way for you to know it was ever sent.
Where the losing bids end up
A company doesn’t need to win a single ad auction to build a surveillance business out of losing them. This is the part of the machine visible in the Gravy Analytics case, and it isn’t unique to that one company. Mobilewalla, another data broker, built a database on more than a billion people with roughly 60% of it sourced from bid-request traffic, then sold access to clients tracking union organisers, Black Lives Matter protesters, and the home addresses of healthcare workers. Near Intelligence pulled from over a billion devices via the same bidstream and sold data to the US Defense Department. Rayzone Group reportedly registered itself as an ordinary advertiser specifically to gain access to bid-request data, then repackaged it as a government tracking tool. None of these companies needed to hack anything. Posing as a bidder was enough, because the auction sends the data to every participant by design, and nothing in the protocol distinguishes a real advertiser from one that only ever intends to lose.
The FTC’s December 2024 order against Gravy Analytics and Venntel — finalised in January 2025, just as the breach was unfolding — now bars the companies from selling or using location data tied to sensitive places (medical clinics, places of worship, shelters, military sites) except for limited law enforcement or national security purposes. That carve-out is doing a lot of work: it prohibits the specific abuse regulators could prove in this one case while leaving the sale of the same underlying data to those same agencies largely intact. A settlement with one broker doesn’t touch the auction that produced the data in the first place, or the thousands of other companies receiving the same broadcasts today.
Why this is the business model, not a side effect
None of this is incidental to how the biggest technology companies make money — it’s the majority of how they make money. In the last quarter of 2025 alone, Google’s advertising business brought in US$82.3 billion, 72% of Alphabet’s US$113.8 billion in total revenue that quarter — a ratio that has held for years. Meta’s advertising revenue reached US$196.2 billion for the full 2025 year, 97.6% of everything the company earned. When a company’s entire revenue is a rounding error away from being 100% advertising, the incentive to collect more behavioural data, model it more precisely, and hold onto it longer isn’t a bug in an otherwise well-intentioned product — it’s the product. Every design decision that makes an app more “engaging” is a decision that generates more behavioural surplus to sell.
Why “techno-fascism”
This series uses that word deliberately, and it’s worth being precise about what it’s claiming rather than leaving it as an unexamined label. The specific claim is this: infrastructure built by private companies for advertising is now a primary source of the surveillance capability governments use on their own populations, obtained through a purchase rather than a warrant. In the United States, the Fourth Amendment restricts the government from searching your location or communications without judicial oversight — but courts have not settled that the same restriction applies when the government simply buys the data on the open market instead of compelling it. Privacy researchers and civil liberties groups call this the “data broker loophole,” and the Gravy Analytics case is a concrete instance of it operating exactly as described: a company builds a location-tracking capability to sell ads, and government agencies become customers rather than obtaining a court order. The fascism in the term isn’t rhetorical flourish; it names a specific, documented fusion of private commercial infrastructure and state power, built without anyone designing it as a surveillance system in the first place.
Limitations
Not every company that receives a losing bid misuses it. The overwhelming majority almost certainly discard data from auctions they don’t win, if only because storing and monetising it takes deliberate effort most bidders won’t bother with. The abuses documented here are the identified cases, not proof that most participants in real-time bidding behave this way — the honest position is that the system makes this abuse possible and hard to detect, not that it is universal.
Regulatory responses already exist and are having some effect: the EU’s ePrivacy and GDPR framework has forced some transparency requirements onto the bidding process, Google has been phasing out third-party cookies in Chrome, and the FTC’s location-data enforcement actions (Gravy Analytics is one of several) are a real, if narrow, constraint. None of these fixes the core architecture — a broadcast to every bidder, with no technical enforcement of what happens to the data afterward — and none of them are complete as of this writing.
The “techno-fascism” framing is this series’ analytical lens, not a settled legal or academic consensus. The underlying facts — the auction mechanism, the broker sales, the government purchases — are documented and sourced below. The framing that connects them is ours, stated plainly so it can be judged on its own terms rather than mistaken for a neutral description.
What’s next in this series
Part 2 moves from diagnosis to defence: private messaging (Signal, SimpleX, Session, Matrix) and the actual threat models each one addresses. Parts 3 through 5 cover browsing and search, social media and media consumption, and storage, cloud and AI — each asking the same question this piece has been setting up: given the machine described above, what specifically breaks it for a given part of your digital life, and what doesn’t.
Sources
- Gravy Analytics data broker breach: trove of location data threatens privacy of millions, TechCrunch, 13 January 2025
- FTC Finalizes Order Prohibiting Gravy Analytics, Venntel from Selling Sensitive Location Data, Federal Trade Commission, January 2025
- The Age of Surveillance Capitalism, Shoshana Zuboff, 2019
- Real-Time Bidding Evidence, Irish Council for Civil Liberties
- Online Behavioral Ads Fuel the Surveillance Industry — Here’s How, Electronic Frontier Foundation, 6 January 2025
- Alphabet Announces Fourth Quarter and Fiscal Year 2025 Results, Alphabet Inc., 4 February 2026
- Meta Reports Fourth Quarter and Full Year 2025 Results, Meta Platforms Inc., 28 January 2026