Skip to content

What surveillance can actually do

Answers to "how far has surveillance actually gone" tend to swing between two extremes. Overstatement convinces people that nothing helps, understatement leaves them underprepared, and both lead to bad decisions.

Two numbers to start with. One advertising audience list in circulation contains 650,000 segments, one of which is labelled "I generally get a raw deal out of life"2. Taiwanese prosecutors and police applied for 16,663 communication-record retrieval orders in 2025, covering 147,422 phone lines3. The two are entirely different in kind, and they call for different defenses.

What follows covers five layers: platforms and data brokers, telecom carriers, states and law enforcement, commercial spyware, and open-source intelligence profiling. Cost and reach run in opposite directions across the first four; the fifth sits off that line. For what to do about it, see what an ordinary person should actually do.

How to read this page

  • Capability is not the same as being used on you: Cost per target differs by orders of magnitude across these four layers. Commercial collection is close to free, so it covers everyone; a commercial spyware licence runs to tens of thousands of dollars, so the target list is short. The fifth layer is cheap and still selective, so whether it reaches you depends on how publicly you operate.
  • Capability moves fast, institutions move slowly: Retention periods and warrant thresholds are more stable than the technical picture, so weight them more heavily when judging long-term risk.
  • Absence of evidence is not evidence of absence: Only claims with a public record appear here. Where nothing could be verified, the page says so.

Two adversaries fall outside this page. Fraud and account takeover cost ordinary people the most money in practice; see what an ordinary person should actually do. An employer-issued device, or tracking software a partner or parent installs on your phone, costs a few dollars or is built in already, and sits far closer to most people than any state-level capability; see domestic violence and tech-enabled abuse.

The other groupings on this site line up with these layers. Threat modeling sorts adversaries into six tiers and what an ordinary person should actually do into three kinds. Layer one here corresponds to their "platform operators" and "commercial data collection", layers three and four to "national law enforcement" and "targeted investigation", and telecom is the shared infrastructure underneath the first two. The fifth layer has no counterpart on either page, and the role examples in threat modeling now name it.

The legal layer does not transfer across jurisdictions

The warrant thresholds, retention periods, and facial-recognition status below use Taiwan as the worked example, because that is this site's primary context. They are illustrative, not universal — check your own jurisdiction. In mainland China, mandatory real-name registration, statutory data retention, and content moderation built into the platform layer drop that threshold sharply, and public speech alone can be enough to open a case; see posting on mainland Chinese platforms and speaking online from Singapore and Malaysia. Hong Kong has measured national-security sentences in years since the 2020 National Security Law and the 2024 Safeguarding National Security Ordinance, and since March 2026 refusing to surrender a device password during a national-security investigation is itself an offense, including for passengers merely transiting through the airport; see the Hong Kong section of cross-border travel and device searches. The platform and spyware layers do transfer.

Four paired bars, left to right: platforms and ads, telecoms, state and law enforcement, and commercial spyware. The upward bar is how many people that layer reaches, and it gets shorter to the right: platforms and ads reach everyone, while commercial spyware works from a short list. The downward bar is the cost of using it on one person, and it gets longer to the right: platforms and ads cost almost nothing, while a commercial spyware licence runs to tens of thousands of dollars. The two measures run in opposite directions, which is why capability is not the same as being used on you. A band underneath carries the fifth layer, open-source intelligence profiling: the material is your own public speech and event information, the cost sits at the level of the leftmost column, and the target selection resembles the rightmost, so the pattern of the first four does not hold there.
Cost and reach run in opposite directions across the first four layers, and the fifth is off that line

The first point above, drawn out. The cheaper a layer is per target, the more people it covers, which makes it the layer you actually meet. The right-hand column has the strongest capability and, because of the price, the shortest list. The band beneath the bars is the fifth layer, priced like the far left and targeted like the far right.

Platforms, advertisers, and data brokers

The widest layer. Marginal cost per person is close to zero, so everyone is in it.

What it can do

Infer attributes you never disclosed

In June 2023 The Markup obtained the audience-segment list of the ad exchange Xandr: 650,000 segments, supplied by data brokers including Oracle, Experian, and Acxiom — companies that run no website or app of their own and whose business is collecting and selling personal data — with Oracle alone accounting for 36% of them2. Most are mundane to the point of comedy: "Heavy Purchaser – Meat Pies – Refrigeration", "Indulgent Dog Owners", "Tattoo Addicts", "Past Purchases > Autos > Makes > Subaru", "Newly Engaged". Others are less funny: "Credit Crunched – City Families", "Tough Times" (the list's own gloss: older, lower income, ethnically diverse singles), "Neuroticism – Easily Deflated", "I generally get a raw deal out of life", and health segments broken down by medication and diagnosis. The input is behavioral records, not anything you filled in.

That particular list is a US-market artifact, and no comparable public list exists for most other countries. The same brokers operate elsewhere, but the scale and segment detail are not on the public record.

Join you together across apps and devices

Phone numbers and email addresses are the usual join keys, and contact-list uploads pull in people who never created an account. The mechanics are in how platforms collect your data.

Know roughly where you are after you turn location off

IP addresses, previously joined Wi-Fi networks, and cell towers all yield an approximate position. Turning off GPS removes meter-level precision, and the position is still derivable.

What there is no evidence for

Routine covert audio recording belongs here. An automated analysis of 17,260 Android apps found no evidence of covert audio exfiltration; what it did find was screen recording sent to third parties. Targeting gets its accuracy from the two capabilities above, behavioral records and cross-device joining, neither of which needs a microphone or trips any permission prompt. The full account, including the 2024 pitch-deck episode, is in how platforms collect your data.

Where the boundary sits

Inference is one thing, offering it to advertisers as a checkbox is another. Meta removed detailed targeting options for sensitive categories, including political affiliation, health causes, sexual orientation, and religion, in 20224. What was restricted is the interface sold to advertisers. The inference inside the platform did not go away.

Telecom carriers

Covers everyone with a phone number. The records are generated automatically, without anyone needing to take an interest in you.

What it can do

Communication records

Content is not in them; nearly everything else is. One entry looks roughly like this: on a given day at 21:04, your number dialled another number, the call lasted 4 minutes 12 seconds, and the handset was attached to a particular cell tower. Tower precision depends on density, from a few hundred meters in a city to several kilometers in rural areas. Encryption of content does not affect this layer, because the record is generated on the network side.

How far back it reaches is set by statutory retention

Taiwan's rule is three months for local calls and six months for domestic long-distance, international, and mobile communications5. In plain terms: going back six months, what time you leave home, where you go at weekends, and which week you suddenly started calling someone frequently are all reconstructable. Past that window the carrier must respond in writing that the records cannot be provided, so the retention period is the ceiling on any after-the-fact investigation. Periods vary widely by country, so check the rule where you live.

What it cannot do

Carriers cannot read end-to-end encrypted content. To a carrier, a Signal message is ciphertext.

They also cannot read your messages inside a messaging app. What the carrier sees is that you connected to that service; the message content and the other party live on the platform side, and obtaining them means approaching a different holder. Telecom communication records, network connection logs, and platform-side message records are three different things held by three different parties.

States and law enforcement

Bounded by legal process, which puts a ceiling on volume. Taiwan is the worked example below.

Interception

Interception requires a judge-issued warrant, generally limited to offenses carrying a minimum sentence of three years or to an enumerated list. Authorization is time-limited, and the agency must report back to the court afterwards6. Ordinary cases do not reach this bar.

Retrieving communication records

A tier lower. A court-issued retrieval order is the default. The same statute, however, carves out an exception: offenses carrying a minimum sentence of ten years, plus an enumerated list that includes robbery, snatching, fraud, extortion, kidnapping for ransom, narcotics, and money laundering. For those, a prosecutor or an authorized judicial police officer may retrieve records without going to a court6. Fraud sits inside that exception, and it is the case type an ordinary person is most likely to touch.

Actual scale

Taiwan's Ministry of Justice reports 16,663 retrieval-order applications in 2025, covering 147,422 phone lines3. Against a population of 23 million that is a small proportion, and still far from rare enough to ignore. Year-by-year figures are at the Ministry of Justice statistics site, and interception figures at the Judicial Yuan's communication-surveillance statistics.

Buying from the commercial layer

Warrant thresholds govern requests to carriers and platforms. The data brokers in layer one sell on an open market, outside that process entirely. This route is routinely left out of discussions about the scale of surveillance.

Linking a device around end-to-end encryption

End-to-end encryption puts message content beyond the reach of conventional interception. The alternative route is to attach an investigator's computer to the target account as a second device. WhatsApp, Telegram, and Threema offer web clients; Signal ships a desktop app. Linking a new device is ordinary product functionality. Confirmation codes can be obtained by physically handling an unlocked phone, by tricking the target into scanning a QR code, or by intercepting a code delivered over SMS. Once the link is established, subsequent messages sync across, and most clients also push the existing message archive. The encryption itself is never broken.

Germany has the fullest public record. In January 2020, during a witness interview, officers of the Federal Criminal Police Office (Bundeskriminalamt, BKA) covertly activated WhatsApp Web on phones that a couple had voluntarily handed over so that messages from their daughter could be reviewed12. In a separate case in March 2022, police attached themselves to a suspect's Telegram account and copied roughly four months of prior conversation before he cut the link a few hours later13. The Customs Criminal Office (Zollkriminalamt, ZKA) piloted the method from late 2023 and moved it into permanent operation in August 202514.

The legal boundary was drawn by the Federal Court of Justice (Bundesgerichtshof, BGH) in January 2026. The court held that covertly attaching to an account is source telecommunications surveillance (Quellen-Telekommunikationsüberwachung), that only content generated after the moment of judicial authorization may be collected, and that retrieving older messages exceeds the warrant — grounds on which it set aside part of the conviction13.

Taiwan has no comparable public record, and the Communication Security and Surveillance Act contains no provision addressing device linking. The reason to include it here is the route it exposes: warrant thresholds govern what agencies may request from carriers and platforms, and say nothing about an agency using a vendor's own feature to open its own door into an account. There is exactly one thing to do at the user end — review the account's linked-device list regularly and remove anything you do not recognize15.

Facial recognition

Taiwan's National Police Agency ran a live facial-matching function in its M-Police system, drawing on household-registration photographs. In December 2021 the function was suspended over questions of authority and legal basis, with the agency stating at the time that it would resume once the legal framework was completed8. No public announcement of resumption was found at the time of verification; treat the agency's own notices as authoritative. What was suspended is live matching against household-registration photographs. Street camera networks operate under separate legal bases and are outside this section.

What there is no evidence for

No public record indicates blanket real-time content interception in Taiwan. Two institutional limits are real: interception is authorized case by case and reported back to the court, and communication records past the retention window simply cannot be produced.

Other jurisdictions

Mainland China and Hong Kong differ enough that none of the above transfers. See the warning box near the top of this page.

Commercial spyware

Highest cost, fewest targets, and the highest capability ceiling of the four.

What it can do

Zero-click exploits compromise a device without you tapping anything. Once a device is compromised, end-to-end encryption stops protecting anything, because the implant reads content that has already been decrypted on the device: the message is read at the same moment you can read it.

In July 2026 Amnesty International published a full analysis of Pegasus's architecture, drawing on internal marketing and technical documents disclosed in WhatsApp's litigation against NSO Group9. In the same month, Citizen Lab reported that the iPhone of a former Member of the European Parliament had been infected with Pegasus at least three times across 2022 and 202310.

Why most people are not on the list

Licenses are expensive and operating the tooling takes staff, so buyers choose targets. Publicly documented cases number in the thousands, against billions of handsets, which puts the odds for any given person extremely low. Those cases cluster among journalists, human rights workers, lawyers, politicians, and the people around them.

Common misconceptions

  • Turning it off and on fixes it: Most infection chains do not persist, so a reboot clears that particular implant. What it clears is only that one instance; the same chain can reinfect immediately, so rebooting is not a defence.
  • A new phone means a clean slate: Replacing the handset deals with the implant already on it, not with being targeted again.
  • Antivirus software will catch it: Consumer antivirus does nothing at this layer.

The one thing an ordinary person can do

Lockdown Mode on iPhone and Advanced Protection on Android switch off a batch of commonly exploited features, at the cost of some functionality. Apple's own guidance is explicit: most people do not need it, and it exists for people who may be targeted by state-level or mercenary spyware, such as journalists, activists, and government officials11. To decide whether that includes you, start from threat modeling.

Open-source intelligence profiling

Cost and reach run in opposite directions across the four layers above. This one sits off that line: the cost is close to layer one, and the target selection is as deliberate as layer four.

Anthropic's September 2026 abuse report documented several clusters of banned accounts whose work was turning public speech, social posts, and event information into individual dossiers, daily briefings, and target lists, for government customers or for internal use inside an agency1. That output used to require a full analyst team. In the documented cases a single operator sustained it with a templated workflow, the model handling translation, summarization, drafting, and formatting.

What it can do

Pull one person's public activity across platforms into a single file

Collection spans WeChat, Xiaohongshu, Douyin, and Weibo alongside LinkedIn, Instagram, Threads, X, and Facebook, reported on a daily cycle. Dossier fields include date of birth, place of birth, emigration date, and social accounts (report pp. 91-92).

Profile people by the pressure points that can be used on them

One case converted bulk-extracted group chats into structured data, profiling people for economic pressure, family separation, and ideological disillusionment, and specifically flagging targets whose relatives remain in Xinjiang (pp. 86-89).

Produce advance venue intelligence for lawful public events

Accounts tied to a municipal security bureau requested assembly points, routes, and end points for events overseas, among them a democracy march in Vancouver and screening sessions at the Oslo Freedom Forum, all of them lawful and public (pp. 93-97). The corresponding preparation is in activists and protest digital safety.

Run as routine daily output

Another case ingested 15 to 30 foreign news articles a day, scored them for political sensitivity, and produced briefings written for officials, with monitoring categories that include Taiwanese political activity and Taiwanese media coverage (pp. 98-101).

What it cannot do

This layer does not compromise devices and does not read end-to-end encrypted content. The collection stage described in the report ran on separate infrastructure with no model involved, and that capability belongs to the layers above.

Being written into a file and being acted on are different things. The summonses and "control" measures in the report were aimed at citizens inside mainland China. For someone outside that jurisdiction, being recorded is usually followed by listing and continued tracking (pp. 93-97).

Where the boundary sits

Anthropic sees only what passed through its own models, so equivalent activity elsewhere is out of scope. Attribution and confidence levels are Anthropic's own judgments, and several cases carry a low or medium confidence marker in the report. Page-by-page notes and the report's own limits are in our summary of it.

The one thing an ordinary person can do

Take an inventory of your own public exposure. People who give interviews, act as spokespeople, or appear at public assemblies are likelier to end up on these lists than people who never speak publicly. For organizers, the disclosure-timing entry in activists and protest digital safety covers what to publish when.

How would I know if I were targeted

Each of the five layers has one action you can take yourself.

  • Platform layer: Open Google's My Ad Center and Meta's ad preferences to see the topics the system thinks you care about, then use data export for the full record. The steps are in how platforms collect your data. Nothing else on this site shows you your own profile as directly.
  • Telecom layer: Request your own call detail records from your carrier; the scope is broadly what a retrieval order would produce.
  • State and law enforcement layer: Under Article 15 of Taiwan's Communication Security and Surveillance Act, the executing agency must report after surveillance ends and the court notifies the person who was surveilled. Notification can be deferred where it would defeat the purpose, but the grounds must be reassessed every three months and notice must still follow once they lapse7. Lawful interception, in other words, has a built-in path to being told afterwards. Whether an equivalent exists where you live is worth checking.
  • Device layer: Review the active-session list on each service and turn on unknown-tracker alerts for AirTags and on Android. If you suspect commercial spyware, Citizen Lab and the Access Now Digital Security Helpline both provide forensic help. Amnesty's open-source Mobile Verification Toolkit (MVT) checks a phone backup against known traces of compromise, and takes some technical background to run.
  • Open-source profiling layer: Search once for your own name, your usual handle, and your organization. What comes back is the raw material this layer works from. Organizations running public events should also check how much venue and schedule detail is already published.

Which measure stops which layer

Read it this way. The two left-hand columns are the ones you are most likely to face, and the first four rows are largely effective there. The commercial spyware column costs too much to be aimed at most people; treat it as the ceiling on capability rather than as your expected risk. The rightmost column is a different case: it is cheap and still selective, so whether it applies depends on how publicly you operate, and the first four rows do almost nothing against it.

The table covers communication and account measures only. Facial recognition and physical camera networks are not on it, and the equivalent for fraud and account takeover is in what an ordinary person should actually do.

Measure Platforms & ads Telecom State & law enforcement Commercial spyware Open-source profiling
End-to-end encryption Message content protected; behavioral signals and linkage still collected Content protected, records still generated Content protected, records still obtainable No protection, decrypted on device Not applicable; the material is what you published
VPN Substitutes the source IP the platform sees; the account is still you Your carrier sees only that you connect to a VPN; call records and cell-site data are unaffected No help against account-level requests No protection Not applicable
Tor Breaks source-IP correlation; once you log in it is still you Carrier sees only that you use Tor No help against account-level requests No protection Not applicable
Ad ID and permissions off Reduces cross-app linkage Not applicable Not applicable Not applicable Not applicable
Account layering Cuts some linkage Not applicable Raises the cost of correlation No protection Raises the cost of linking a public identity to other activity
Staying updated Not applicable Not applicable Not applicable Raises cost; no help against zero-days Not applicable
Disclosure timing for public information Reduces what the platform side can collect Not applicable Not applicable Not applicable The only measure that works at this layer

The layer you defend has to match the layer you actually face. The framework for deciding that is in threat modeling.

This page will age

Both capability and law keep moving, and the facial-recognition legislative track and individual spyware cases change fastest. Everything here reflects the state at the time of verification, and every claim carries a date. If something no longer matches reality, please report it in the community Matrix room.

Where to go from here


  1. Detecting and countering misuse of AI: September 2026 — Anthropic, 10 September 2026. 154 pages, covering abuse cases detected and disrupted between December 2025 and August 2026. Page numbers in this section refer to the report PDF. Attribution and confidence levels are Anthropic's own. Verified 2026-09. 

  2. From "Heavy Purchasers" of Pregnancy Tests to the Depression-Prone: We Found 650,000 Ways Advertisers Label You — The Markup, 8 June 2023. The reporting is based on the audience-segment list of the ad exchange Xandr, drawn from close to a hundred data suppliers. Segment names are quoted as they appear in that list. Verified 2026-08. 

  3. Ministry of Justice statistics (Taiwan): 16,663 retrieval-order applications in 2025, covering 147,422 phone lines. The same page allows switching between 2021 and 2025. Verified 2026-08. 

  4. Meta announced in January 2022 that, effective 19 January that year, it would remove detailed targeting options relating to health, race, political affiliation, religion, and sexual orientation. Verified 2026-08. 

  5. Taiwan's Regulations on Telecom Enterprises Handling Agency Inquiries into Communication Records, Article 5, as amended 15 June 2017: three months for local, six months for domestic long-distance, international, and mobile. Verified 2026-08. 

  6. Taiwan's Communication Security and Surveillance Act. The interception threshold is Article 5. Retrieval of communication records is Article 11-1, paragraphs 2 and 3, and the exception permitting retrieval without a court order is paragraph 4. Verified 2026-08. 

  7. Article 15 of Taiwan's Communication Security and Surveillance Act. The executing agency must report after surveillance ends and the court notifies the person surveilled; deferral requires stated grounds, reassessment every three months, and notice once the grounds lapse. Verified 2026-08. 

  8. Police agency takes M-Police facial matching offline pending regulatory work — Liberty Times, December 2021 (in Chinese). For the human rights analysis, see Privacy issues in public-sector use of facial recognition and CCTV — Taiwan Association for Human Rights. Verified 2026-08; no public announcement of resumption found. 

  9. Inside Pegasus: The evolution of the world's most notorious spyware system — Amnesty International Security Lab. Architecture analysis published 16 July 2026 from internal documents disclosed in WhatsApp's litigation against NSO Group. Verified 2026-08. 

  10. Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus, 3 July 2026, reporting that former MEP Stelios Kouloglou's iPhone was infected with Pegasus at least three times across 2022 and 2023. Verified 2026-08. 

  11. About Lockdown Mode — Apple Support. Apple describes it as an extreme, optional protection that most people will never need, intended for individuals who may be personally targeted by state-level or mercenary spyware. The Android counterpart is Advanced Protection. Verified 2026-08. 

  12. BGH, Beschluss vom 9. Juli 2020 – 2 BGs 468/20 — investigating judge at Germany's Federal Court of Justice (in German). The decision records the interview of 12 January 2020. The two people who handed over their phones were witnesses, and the accused was their daughter. Verified 2026-09. 

  13. BGH, Beschluss vom 20. Januar 2026 – 3 StR 495/25 — Third Criminal Panel of Germany's Federal Court of Justice, on appeal from the Regional Court of Aurich (in German). The account was attached late on 30 March 2022, and the copied range runs from 26 November 2021 to 30 March 2022. The parts set aside cover two counts, the aggregate sentence, and part of the confiscation order. Verified 2026-09. 

  14. Messenger-Überwachung: Immer mehr Polizei überwacht Messenger wie WhatsApp — netzpolitik.org, 2 September 2026 (in German), publishing the full text of a Customs Criminal Office internal directive dated 20 February 2026. The pilot began in late 2023 and entered permanent operation on 1 August 2025. Both the ZKA and the BKA declined to say how often the method is used, citing classification. Verified 2026-09. 

  15. Gemeinsamer Sicherheitshinweis 01/2026: Phishing über Messengerdienste — Germany's Federal Office for the Protection of the Constitution and Federal Office for Information Security, 6 February 2026 (in German). Recommends reviewing an account's linked devices regularly and removing unknown ones immediately, and notes that an attacker linked to a Signal account gains access to the last 45 days of message content. Verified 2026-09.