Sign in

Wolfie Christl

@wchr.bsky.social
4.8K followers 359 following 509 posts

Public-interest researcher at Cracked Labs | Research fellow at Citizen Lab | Vienna, Austria | Tech and society. Tracking, surveillance, data economy, platform power, algorithmic decisions, datafication of work. wolfie.crackedlabs.org/en

PostsRepliesMedia
Wolfie Christl @wchr.bsky.social · 18h
Übermorgen Freitag um 16:45 sprech ich bei der @re-publica.com in Wien zum Thema "Illegale Massenüberwachung mit App- und Werbedaten" und zum hochproblematischen Kauf des Überwachungsystems "Webloc" durch das österreichische Innenministerium: vienna.re-publica.com/de/session/i...
073
Wolfie Christl @wchr.bsky.social · 24/09/2026
News hat Beschäftigte von österreichischen Inlands- und Militärgeheimdiensten identifiziert, ihre Wohnhäuser, Arzt- und Friseurbesuche - auf Basis eines kommerziell erwerbbaren Datensatzes aus der digitalen Werbung, der Standortdaten von 562.448 Smartphones in AT enthält: www.news.at/investigativ...
13529
Reposted by Wolfie Christl
The Citizen Lab @citizenlab.ca · 23/09/2026
Join senior researcher @wchr.bsky.social at @re-publica.com in Vienna on October 2nd to discuss how government agencies are accessing behavioural data from online advertising for surveillance purposes. Register here: tickets.infield.live/event/re-pub...
0116
Reposted by Wolfie Christl
Ailo @airavn.eurosky.social · 21/09/2026
It’s been 8 years since we published our report on how Google tricks people into extensive location tracking, and simultaneously filed complaints against Google. Today the decision from the Irish Data Protection Commission arrived: a €400 million euros fine. www.forbrukerradet.no/siste-nytt/d...
forbrukerradet.no
Google Fined €403 Million Following Consumer Council Report
Google has been fined €403 million by the Irish Data Protection Commission after the Norwegian Consumer Council exposed how the company manipulated users into accepting extensive tracking.
45937
Reposted by Wolfie Christl
Wurzelmann (Herbst era) @wurzelmann.at · 15/09/2026
Endlich ein sinnvoller Artikel über "KI" und die ganze unnötige Marketing-Scheiße, die von anderen Medien/Journalist*innen einfach ohne Recherche abgeschrieben werden. Schön zusammengefasst, gute Quellen, sinnvoll erklärt und objektiv besprochen. So geht das, danke @sukahiroaki.bsky.social!
derstandard.at
Von wegen KI-Apokalypse: Das Problem sind verantwortungslose Unternehmen, nicht magische KI
Warum die Diskussion über existenzielle Risiken durch KI an den realen Problemen vorbeigeht und die Hersteller von ihrer Verantwortung befreit
413266
Wolfie Christl @wchr.bsky.social · 14/09/2026
Proud I helped create the website for a 2002 Vienna conference where she discussed her stuff 🙃
041
Wolfie Christl @wchr.bsky.social · 12/09/2026
"This investigation reveals what data is harvested from Romanians, who ends up receiving it, and why the ads shown on platforms with conspiratorial and extremist content are among the most valuable to this network", based on analyzing 100k ads shown across 131 websites, by @victorilie.bsky.social:
snoop.ro
The Kremlin’s Digital Pirates: How Russian Tracking Pixels Harvest Romanians’ Data to Fund Conspiracies and Extremism - Snoop
This investigation reveals what data is harvested from Romanians, who ends up receiving it, and why the ads shown on platforms with conspiratorial and extremist content are among the most valuable to ...
255
Wolfie Christl @wchr.bsky.social · 09/09/2026
4 years after our investigation into profiling in UK online gambling, and 2 years after the ICO confirmed UK GDPR breaches based on our findings, a new study found "widespread dark patterns and non-compliance of GDPR requirements on UK online gambling sites": www.sciencedirect.com/science/arti...
193
Wolfie Christl @wchr.bsky.social · 09/09/2026
Germany's domestic intelligence agency, the Verfassungsschutz, refers to the sale of mobile app location data as a "grave privacy intrusion" and warns that foreign actors may use the data to approach or attack individuals in the security/defense industries: www.verfassungsschutz.de/SharedDocs/p...
12514
Wolfie Christl @wchr.bsky.social · 04/09/2026
"The Army said ... that advertising IDs had been blocked on Windows computers 'since before 2021' but that Android and Apple ​mobile devices had only had it disabled by default 'since at least February 2026'." So US military phones were widely exposed until 2026? www.reuters.com/business/med...
reuters.com
EXCLUSIVE: US military turns off ad trackers on devices amid Middle East targeting reports
The effort to ​reduce the location data generated by smartphones comes as military officials weigh increasingly strict restrictions on phone use overall.
083
Wolfie Christl @wchr.bsky.social · 01/09/2026
This is significant. The requirements listed in a recent procurement notice for ICE's renewed purchase of LexisNexis Risk's LexID and Accurint Virtual Crime Center products mention inferring identity from "behavioral indicators, device metadata, network signatures, commercial telemetry data".
23032
Wolfie Christl @wchr.bsky.social · 01/09/2026
The Northern California Regional Intelligence Center (NCRIC) showed interest in buying Penlink's ad-based geolocation mass surveillance system Webloc, according to FOI records obtained by @shawnsegal.bsky.social, which also contain a recent Webloc promo brochure: fineprint.report/feed/ncric-p...
fineprint.report
A Bay Area Fusion Center Asked PenLink to Test Ad-ID Location Tracking on an Active San Jose PD Case
On August 5, 2026, an Assistant Deputy Director at the Northern California Regional Intelligence Center (NCRIC) emailed PenLink asking about a trial of Webloc,
051
Wolfie Christl @wchr.bsky.social · 22/08/2026
The Dutch GDPR regulator fined Uber €825m for deactivating driver accounts through automated systems. Paul-Olivier Dehaye, founder of a group that helped drivers access data, "eventually leading to the Dutch investigation", said they're preparing a class-action suit: www.reuters.com/world/dutch-...
reuters.com
EXCLUSIVE: Dutch regulator fines Uber $966 million for automating driver suspensions
The Dutch Data Protection Authority has fined Uber €825 million ($966 ‌million) for deactivating driver accounts through automated systems without adequately informing them, according to an August 17 ...
0104
Reposted by Wolfie Christl
Zach Edwards @thezedwards.bsky.social · 12/08/2026
So proud to launch our new startup today -- decryptads.com -- check out the coverage today from @josephcox.bsky.social and the team at @404media.co about why we're tackling this important privacy, ad tech and security challenge.
162
Reposted by Wolfie Christl
Jeremy White @jeremywired.bsky.social · 12/08/2026
SECRET SAUCE: @thiccreese.bsky.social wanted to find out what data McDonald’s loyalty program had on him. He got back a 515-page file that was equal parts amusing and concerning, even showing how the brand's algorithm predicts his next purchase. Full piece on @wired.com www.wired.com/story/mcdona...
wired.com
McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There
I requested a copy of my data from McDonald’s loyalty program and received an extensive, personalized report that algorithmically predicts my next purchase.
614857
Reposted by Wolfie Christl
Sebastian Meineck @sebmeineck.bsky.social · 11/08/2026
Ein Werkzeug namens #Webloc kann Menschen mit Daten aus dem Werbe-Tracking teils metergenau orten und verfolgen. Bislang war nur bekannt, dass staatliche Stellen das nutzen. Jetzt zeigen Recherchen: Die Technologie wird offenbar auch Unternehmen angeboten. #ADINT netzpolitik.org/2026/angebot...
netzpolitik.org
Gefährliches Überwachungs-Werkzeug breitet sich aus
Ein Werkzeug namens Webloc kann Menschen mit Daten aus dem Werbe-Tracking teils metergenau orten und verfolgen. Bislang war nur bekannt, dass staatliche Stellen das nutzen. Jetzt zeigen Recherchen: Di...
7189132
Wolfie Christl @wchr.bsky.social · 07/08/2026
I think execs and engineers should be criminally liable when they carelessly set up self-reinforcing software services that somehow execute cyberattacks, like everyone else who executes cyberattacks. If you cannot reliably control the behavior of your software environment then just don't set it up.
23410
Wolfie Christl @wchr.bsky.social · 06/08/2026
"advertising SDKs don’t just allow developers to share location data–they often encourage it" Excellent investigation by Lena Cohen and @legind.bsky.social into mobile app SDK vendors that share data on millions with third parties, feat InMobi, BidMachine, Verve, Huawei: www.eff.org/deeplinks/20...
eff.org
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing users’ location by default when embedded in apps granted location ...
165
Wolfie Christl @wchr.bsky.social · 03/08/2026
Penlink's intrusive ad-based surveillance system Webloc was offered to French businesses (!) via the security firm Amarante, and deployed for the benefit of a subsidiary of the French luxury goods giant LVMH, according to an investigation by @yphilippin.bsky.social and @anttonrouget.bsky.social:
1129
Reposted by Wolfie Christl
Ron Deibert @rondeibert.bsky.social · 03/07/2026
NEW @citizenlab.ca report: Member of 🇪🇺 Euro Parliamentary committee (#PEGA) tasked with investigating spyware abuses himself hacked with Pegasus spyware 👇 citizenlab.ca/research/mem...
citizenlab.ca
Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Eur...
01813
Reposted by Wolfie Christl
netzpolitik.org @netzpolitik.org · 30/06/2026
Das Werkzeug Webloc soll Menschen anhand ihrer Handy-Standorte ausspionieren können. Zu den bislang bekannten Kunden gehören die US-Abschiebemiliz ICE und die abgewählte Orbán-Regierung in Ungarn. Jetzt ist klar: Auch Österreich hat zugegriffen. netzpolitik.org/2026/million...
netzpolitik.org
Regierung in Österreich will Menschen mit illegalen Daten orten können
Das Werkzeug Webloc soll Menschen anhand ihrer Handy-Standorte ausspionieren können. Zu den bislang bekannten Kunden gehören die US-Abschiebemiliz ICE und die abgewählte Orbán-Regierung in Ungarn. Jet...
110457
Reposted by Wolfie Christl
Wolfie Christl @wchr.bsky.social · 26/06/2026
Das österreichische Innenministerium kauft große Mengen hochsensibler Daten von Smartphone-Apps über die Standorte, Bewegungen und andere Verhaltensweisen der halben Bevölkerung für: Überwachungszwecke. Vermutlich schon seit 2024, illegal nach der DSGVO, verfassungsrechtlich fragwürdig. Thread:
derstandard.at
Was macht das Innenministerium mit einer Überwachungssoftware, die auch die US-Behörde ICE einsetzt?
Lizenzen für umstrittene Systeme wurden verlängert. Datenschützer warnen vor Überwachung, das Ministerium hält sich bedeckt. Was können diese Systeme?
35135
Wolfie Christl @wchr.bsky.social · 26/06/2026
Public records confirm that the Austrian Ministry of the Interior bought Webloc, a geolocation mass surveillance system based on data from mobile apps and digital advertising = almost certainly illegal under the GDPR. Austria is now - after Hungary - the second EU state known to use such a system.
14820
Wolfie Christl @wchr.bsky.social · 26/06/2026
Das österreichische Innenministerium kauft große Mengen hochsensibler Daten von Smartphone-Apps über die Standorte, Bewegungen und andere Verhaltensweisen der halben Bevölkerung für: Überwachungszwecke. Vermutlich schon seit 2024, illegal nach der DSGVO, verfassungsrechtlich fragwürdig. Thread:
derstandard.at
Was macht das Innenministerium mit einer Überwachungssoftware, die auch die US-Behörde ICE einsetzt?
Lizenzen für umstrittene Systeme wurden verlängert. Datenschützer warnen vor Überwachung, das Ministerium hält sich bedeckt. Was können diese Systeme?
35135
Reposted by Wolfie Christl
Süleyman Zorba @zorbasu.bsky.social · 25/06/2026
Vor wenigen Monaten wollte mir das Innenministerium auf meine Anfrage nicht einmal sagen, ob es die Überwachungssoftware Tangles einsetzt. Begründung: nationale Sicherheit. Jetzt gibt das BMI den Einsatz offen zu. 🧵
1128
Wolfie Christl @wchr.bsky.social · 25/06/2026
Finding the state/surveillance actors who misuse the digital advertising ecosystem in this ocean of commercially and criminally motivated ad fraud and malvertising is non-trivial 🤖
081
Wolfie Christl @wchr.bsky.social · 19/06/2026
Oh, Auren Hoffman, founder of data brokers RapLeaf (which later became LiveRamp) and SafeGraph/Veraset (which sold mobile location data to US govt agencies).
041
Reposted by Wolfie Christl
Ron Deibert @rondeibert.bsky.social · 17/06/2026
Data bought, rights ignored: European intelligence services' use of commercially sourced data Excellent research by Interface Govt security agencies are now routinely undertaking unwarranted mass surveillance thanks to the poorly regulated ad industry www.interface-eu.org/publications...
interface-eu.org
Data bought, rights ignored: European intelligence services' use of commercially sourced data
interface (formerly Stiftung Neue Verantwortung) emerges as Europe's premier Think Tank for cutting-edge tech policy. Our expert team navigates AI, cybersecurity, and more, shaping the continent's dig...
21510
Reposted by Wolfie Christl
Pat Walshe - Privacy Matters 🇮🇪🇬🇧🇪🇺 @privacymatters.bsky.social · 02/06/2026
The practices reported here & elsewhere for a significant period of time, should convince the ‘cookie harms’ deniers that it’s not just about cookies & that ‘cookies’ & other tracking technologies are not without harms …
189
Wolfie Christl @wchr.bsky.social · 02/06/2026
At least one German state-level criminal police department (LKA) purchased location data from digital advertising for surveillance, despite lacking a lawful basis, prompting an investigation by the state's data protection authority. Highly problematic on many levels: netzpolitik.org/2026/daten-s...
netzpolitik.org
Deutsche Polizei nutzt offenbar rechtswidrig Databroker
In mindestens zwei Bundesländern hat sich die Polizei Daten von Databrokern beschafft, wie Recherchen von netzpolitik.org und BR erstmals zeigen. Mit solchen Daten könnten sich Handys metergenau orten...
14832
Reposted by Wolfie Christl
netzpolitik.org @netzpolitik.org · 02/06/2026
In mindestens zwei Bundesländern hat sich die Polizei Daten aus der Werbe-Industrie beschafft, wie Recherchen von netzpolitik.org und BR erstmals zeigen. Mit solchen Daten könnten sich Handys metergenau orten lassen. Fachleute halten das für illegal. netzpolitik.org/2026/daten-s...
netzpolitik.org
Deutsche Polizei nutzt offenbar rechtswidrig Databroker
In mindestens zwei Bundesländern hat sich die Polizei Daten aus der Werbe-Industrie beschafft, wie Recherchen von netzpolitik.org und BR erstmals zeigen. Mit solchen Daten könnten sich Handys metergen...
13349173
Wolfie Christl @wchr.bsky.social · 28/05/2026
"U.S. forces deployed to war zones have ​been targeted using commercially available location data" Just like I, @johnnyryan.bsky.social and others warned. US Senator Wyden says it's time to "start treating the adtech industry as a national security threat". Agreed. www.reuters.com/business/med...
reuters.com
Exclusive: Pentagon says US military personnel are reportedly being targeted using location data
It's an illustration of how the global surveillance ‌economy is shaping the battlefield.
22215
Wolfie Christl @wchr.bsky.social · 21/05/2026
"In the entire period of the GDPR we have had no almost no decisions that make a substantial change to how these companies use data. There's been no impact. The GDPR may as well not have been written" @johnnyryan.bsky.social on Ireland's bigtech GDPR non-enforcement: www.youtube.com/watch?v=cneL...
youtube.com
re:publica 26: Johnny Ryan – How we avoid dystopia
YouTube video by re:publica
0149
Wolfie Christl @wchr.bsky.social · 21/05/2026
"Die Datenschutzbehörde und nun auch die Gerichte haben klar bestätigt, dass Cookie-Banner eine gleichwertige 'Ja'- und 'Nein'-Option anbieten müssen ... Dass sogar der öffentlich-rechtliche ORF ganze 8 Jahre nach Einführung der DSGVO hier eine gerichtliche Extraeinladung braucht, ist empörend"
042
Wolfie Christl @wchr.bsky.social · 20/05/2026
"A publicly exposed web front reveals new details on a tracking system for foreigners and delivers many insight into the capabilities of security organs to track individuals in real time" Analysis of test instance of a Chinese govt mass surveillance system: netaskari.substack.com/p/sharp-eyes...
netaskari.substack.com
Sharp Eyes: Mass surveillance of foreigners in China - Part 1
A publicly exposed web front reveals new details on a tracking system for foreigners and delivers many insight into the capabilities of security organs to track individuals in real time.
161
Reposted by Wolfie Christl
Open Rights Group @openrightsgroup.org · 18/05/2026
The UK data watchdog is all bark, no bite. From failing to investigate complaints to forgoing regulatory action in favour of a slap on the wrist, the ICO isn't doing its job. It's time that the regulator is overhauled, because data protection laws only work if they're enforced. Read our blog ⬇️
openrightsgroup.org
The ICO isn’t doing its job – why the data watchdog needs to be reset
The Information Commissioner’s Office (ICO) is currently missing its Commissioner, after unspecified HR complaints about John Edwards.
12321
Reposted by Wolfie Christl
Vas Panagiotopoulos @vaspanagiotopoulos.com · 05/05/2026
“Under pressure to deliver in the fight against serious cross-border crime, Europol built and operated a shadow data analysis platform containing large volumes of sensitive information, which operated without key legal and technical safeguards.” www.computerweekly.com/news/3666425...
computerweekly.com
‘They protect the law while breaking it’: Inside Europol’s shadow IT system | Computer Weekly
Under pressure to deliver in the fight against serious cross-border crime, Europol built and operated a shadow data analysis platform containing large volumes of sensitive information, which operated ...
23239
Wolfie Christl @wchr.bsky.social · 29/04/2026
"Um potenzielle Anleger zu ködern ... schalteten sie irreführende Online-Werbung" ...kriminelles Netzwerk mit Callcentern und 450 MitarbeiterInnen zerschlagen, gut so. Aber wann werden Meta, Google und andere Werbenetzwerke endlich als potentzielle Mittäter belangt? www.justiz.gv.at/wksta/wirtsc...
justiz.gv.at
Millionenschwerer Internetbetrug mit Prominenten-Fakenews: International agierende Callcenter in Albanien ausgehoben
132
Reposted by Wolfie Christl
Wolfie Christl @wchr.bsky.social · 27/04/2026
Die Marktgemeinden Kronstorf und Hargelsberg, die oberösterreichische Landesregierung und der Landesfischereiverband sind nun offenbar alle Teil der PR-Abteilung von Google, das in Kronstorf eine monströse Serverfarm baut, die laut APG mehr Strom ziehen wird als alle Privathaushalte in OÖ zusammen.
1137
Wolfie Christl @wchr.bsky.social · 27/04/2026
Die Marktgemeinden Kronstorf und Hargelsberg, die oberösterreichische Landesregierung und der Landesfischereiverband sind nun offenbar alle Teil der PR-Abteilung von Google, das in Kronstorf eine monströse Serverfarm baut, die laut APG mehr Strom ziehen wird als alle Privathaushalte in OÖ zusammen.
1137
Wolfie Christl @wchr.bsky.social · 23/04/2026
New @citizenlab.ca report with an incredibly sophisticated analysis of covert surveillance operations with a focus on location tracking, which target phones by exploiting global 3G/4G telecom networks and sending invisible SMS while acting as trusted telecom operators: citizenlab.ca/research/unc...
citizenlab.ca
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose h...
11812
Reposted by Wolfie Christl
Szabolcs Panyi @szabolcspanyi.bsky.social · 21/04/2026
💥Days after Viktor Orbán lost reelection, Hungary's data protection authority is investigating Webloc — an Israeli tool that harvests mobile ad data for mass surveillance, likely violating GDPR. We exposed its use by Hungary on @vsquare.bsky.social with @citizenlab.ca: vsquare.org/goulash-with...
112154
Reposted by Wolfie Christl
Wolfie Christl @wchr.bsky.social · 21/04/2026
"the U.S. needs to clamp down on the collection and sale of geolocation data" @lawfaremedia.org / @tom.risky.biz on our report on ad-based surveillance, highlighting the "national security and privacy risks of pervasive and easily obtainable geolocation data": www.lawfaremedia.org/article/it-i...
lawfaremedia.org
It Is Time to Ban the Sale of Precise Geolocation
The latest edition of the Seriously Risky Business cybersecurity newsletter, now on Lawfare.
055
Wolfie Christl @wchr.bsky.social · 21/04/2026
"the U.S. needs to clamp down on the collection and sale of geolocation data" @lawfaremedia.org / @tom.risky.biz on our report on ad-based surveillance, highlighting the "national security and privacy risks of pervasive and easily obtainable geolocation data": www.lawfaremedia.org/article/it-i...
lawfaremedia.org
It Is Time to Ban the Sale of Precise Geolocation
The latest edition of the Seriously Risky Business cybersecurity newsletter, now on Lawfare.
055
Wolfie Christl @wchr.bsky.social · 20/04/2026
ICE entered into another 1-year $12.2m contract for a system that looks a lot like surveillance tech based on advertising/app data, according to public records reported by The Lever. The system/program, called 'SAFE HAVEN', aims to track, locate and profile migrants and 'extremists', among others.
21711
Reposted by Wolfie Christl
Frank Bajak @fbajak.bsky.social · 17/04/2026
A leaked document obtained by @citizenlab.ca says Webloc sells data/identifiers including geolocation from "up to 500 million mobile devices across the globe” to U.S. and foreign security agencies (including ICE) and military. H/t @rondeibert.bsky.social www.lawfaremedia.org/article/it-i...
lawfaremedia.org
It Is Time to Ban the Sale of Precise Geolocation
The latest edition of the Seriously Risky Business cybersecurity newsletter, now on Lawfare.
21312
Reposted by Wolfie Christl
Wolfie Christl @wchr.bsky.social · 16/04/2026
Last week, we published a @citizenlab.ca report on the ad-based location surveillance system Webloc, its capabilities and its customers. Webloc obtains data from consumer apps installed on phones. How? We don't know. But the ad targeting segments shown in this 2021 Webloc screenshot caught my eye:
12313
Wolfie Christl @wchr.bsky.social · 17/04/2026
Last week, we at @citizenlab.ca and @vsquare.bsky.social exposed Hungarian intelligence’s use of Webloc, an ad-based surveillance system that relies on mobile app data. Update: The Hungarian GDPR regulator told @szabolcspanyi.bsky.social it has launched an ex officio investigation into the matter.
1168
Reposted by Wolfie Christl
Ron Deibert @rondeibert.bsky.social · 16/04/2026
The advertising ecosystem upon which surveillance vendors like Penlink draw their data is a toxic, poorly regulated and exploitative swamp My @citizenlab.ca colleague @wchr.bsky.social with some follow-on observations about this swamp related to our "Uncovering Webloc" report published last week 👇
096
Wolfie Christl @wchr.bsky.social · 16/04/2026
Last week, we published a @citizenlab.ca report on the ad-based location surveillance system Webloc, its capabilities and its customers. Webloc obtains data from consumer apps installed on phones. How? We don't know. But the ad targeting segments shown in this 2021 Webloc screenshot caught my eye:
12313