News February 18, 2021

Spy pixels: Email security threat is massive

February 18, 2021

A BBC commissioned a study from the British email server Hey to identify the number of spy pixels circulating in correspondence on the internet. The result? Shocking. At least two-thirds of the emails received by its users contained the tracking tool. And this could be much higher, since the number of registrations on Hey's server is much smaller than on large platforms such as Gmail or Outlook.

The study, conducted in the United Kingdom, found that numerous companies use spy pixels in their advertising emails. Mainly, big brands such as Asos, HSBC, Unilever, Vodafone and others. Considering the reach of these global brands, the impact of this spread of spying is immense.

What are these invasive pixels?

The name spy pixel explains the concept of the tool well. These are usually images in .gif or .png format measuring 1 x 1 pixel and that have the same color as the background where they are inserted. In other words, they are invisible to the naked eye. When you open an email that automatically loads the images, the sender already knows that you opened the email and, depending on the spy service they use, even knows how many times they were opened.

And how does he know this? Well, every image on the internet is hosted on a server. To open the image, the computer sends a download request to the hosting location, and with that, the information is recorded and passed on to whoever hires the spy service. And the risks are great, after all, the IP of the machine is recorded and with this information it is possible to know the street where the email was opened. David Hansson, co-founder of Hey, claimed that these spy pixels “are a grotesque threat to privacy”.

The law exists, but…

In the UK and some parts of Europe, there is a law that protects users from this type of intrusion called the Privacy and Electronic Communications Regulation (PECR). Both of these regulations outline guidelines for how people's data can be used and require companies to make clear what methods they have for collecting information, as well as whether they need to have consent for the collection.

Pat Walshe, an internet privacy consultant, told the BBC that the law is very clear, but requires greater enforcement. After all, even the European Union body responsible for PECR uses spy pixels in its newsletter.

Brazil is no exception. In theory, the General Data Protection Law, of 2018, could classify the use of spy pixels without authorization. In practice, almost no one adapted yet. Newsletter and email marketing applications are the same as those used abroad, and use the resource to provide feedback to those who send the emails.

Image: Webphotographer (iStock)

Read too