Smartphone lying face-up on a dark wooden surface with the screen off
Photo via Unsplash

TL;DR: On May 21, 2026, the FTC announced a $930,000 settlement with Cox Media Group, MindSift, and 1010 Digital Works for selling an "Active Listening" service they claimed used AI to listen through consumers' smart devices and target ads based on what people said out loud. The service did not listen to anything. It did not use voice data at all. The companies were reselling email lists from other data brokers at a markup and calling it AI-powered surveillance. The myth that your phone is eavesdropping on you is one of the most persistent on the internet. This case proves the companies that claimed they could do it were lying. The real surveillance is happening. It just does not need your microphone.

What the FTC Found

On May 21, 2026, the Federal Trade Commission announced proposed consent agreements with three companies. Cox Media Group (CMG), a Georgia-based media and marketing firm, paid $880,000. Two smaller partners, MindSift LLC in New Hampshire and 1010 Digital Works LLC in Wisconsin, each paid $25,000. The total: $930,000 [1].

The Commission voted 2-0 to issue the proposed administrative complaints. The director of the FTC's Bureau of Consumer Protection, Christopher Mufarrige, put it bluntly: "Not only did the product these companies marketed not do what they claimed it did, but they also misled potential customers by claiming consumers had opted into this service when it's clear they did not" [1].

The companies sold small businesses a service branded "Active Listening." The pitch: an algorithm listens to conversations near smart devices in real time, picks out keywords like "I need a new roof" or "my back hurts," and serves targeted ads to the people who said them. Small businesses paid a premium for what looked like the holy grail of local advertising. Reach the consumer at the exact moment they want what you sell.

None of that happened.

What the Product Actually Was

According to the FTC complaints, the Active Listening service "did not, in fact, listen in on consumers' conversations or use voice data at all." It also did not accurately place ads in the geographic areas customers asked for [1].

What it did: resell email lists obtained from other data brokers at a significant markup. The service was a relabeled version of the same ad targeting inventory that any small business could buy from a data broker directly, for a fraction of the price, with none of the eavesdropping branding.

The companies also claimed that consumers had "opted in" to having their conversations monitored. The way they supposedly opted in: clicking through the mandatory terms-of-service agreement that every app requires you to accept before you can use it [1].

The FTC rejected that argument directly. Clicking through a ToS that says "we may collect data" does not constitute opt-in consent to having a microphone in your home activated, audio recorded, voice data analyzed, and that data used to serve you targeted ads. Even if the technology had worked as advertised, the consent mechanism would have violated Section 5 of the FTC Act [1].

Why the Phone-Listening Myth Will Not Die

Walk into any living room and someone will tell you their phone is listening. They will have a story. They talked about a topic they had never searched for, and minutes later they saw an ad for it. It feels like proof. The coincidence is too perfect to be random.

It is not proof. The reason the coincidence feels uncanny is that targeted advertising works extremely well for other reasons. Ad networks know what your friends and family search for, what websites you have visited, what apps you have installed, where you physically go, and what other people who look like your demographic profile are interested in this week. The targeting is so precise that the "right ad at the right time" effect shows up constantly. It just is not coming from your microphone.

Confirmation bias finishes the job. You mention a topic once and forget. The ad shows up a week later, and you remember. You do not remember the thousand times you mentioned something and saw no related ad. The hits confirm the theory. The misses go unrecorded.

This FTC case is striking because it shows the same myth migrating up the supply chain. The people who believe their phone is listening are being told the same thing by companies that want to sell them the eavesdropping service. Both the belief and the product are fake. Both are still profitable.

What the Real Surveillance Actually Looks Like

The unsettling truth: you do not need a microphone to be comprehensively tracked. The real surveillance infrastructure is older, more boring, and far more effective than any alleged phone eavesdropping.

Data brokers collect location data from the apps on your phone, the SDKs embedded in those apps, and the real-time bidding auctions that run every time an ad loads on a webpage or in an app. The Mobilewalla FTC settlement in December 2024 made harvesting location data from RTB bid requests explicitly illegal, even when the broker did not win the auction. Kochava was banned in May 2026 from selling sensitive location data without affirmative express consent. The pattern: location from your phone, sold to whoever pays, used to build profiles that know where you sleep, work, pray, and visit the doctor [2].

Your email address, tied to your real name, your purchase history, your browsing history, and your location, is for sale on the data broker market right now. The FTC has identified more than 4,000 data broker companies operating in the United States. Vermont's data broker registry, the only state that requires registration, lists over 500. The FTC has taken action against six of them in the past 18 months [2].

Email lists are not as exciting as audio surveillance, but they are the actual product. Cox Media was not selling eavesdropping. It was selling the email list version of the same surveillance. The branding was fake, but the surveillance was real.

What This Settlement Actually Does

The $930,000 fine is small money. CMG is owned by Apollo Global Management, a private equity firm with hundreds of billions in assets under management. The fine is a rounding error. The money goes to refunds for small businesses that bought the fake service, not to consumers who were the supposed target of the surveillance [1].

The substantive part of the settlement is the conduct ban. Each of the three companies is prohibited from making any misrepresentation about three specific things going forward: the qualities or features of its advertising or marketing services, the collection and use of voice data and whether consumers have consented to it, and the geographic targeting capabilities of its advertising services [1][3].

That is a useful but narrow ban. It bars the next fake Active Listening pitch. It does not bar the next fake surveillance product with a different name. It does not touch the underlying data broker market that supplied the email lists. It does not impose any obligation to identify or refund consumers who were profiled by the email list resales. The companies continue to operate.

What You Can Do

Your phone probably is not listening to you. The data broker industry is still tracking you in ways that are just as effective and a lot less theatrical.

  • Kill the data broker pipeline. Your advertising ID is the key that links all those profile fragments together. On iPhone: Settings, Privacy and Security, Tracking, toggle off "Allow Apps to Request to Track." On Android: Settings, Privacy, Ads, Delete advertising ID.
  • Block real-time bidding leakage. Every ad auction in every app and webpage broadcasts your location, your device ID, and the sites you are on to dozens of bidders. Firefox or Brave with uBlock Origin blocks most of them. This is also the lever that closed the Mobilewalla loophole: a bid request that never gets sent cannot leak data.
  • Use the California Delete Act if you live in California. One form, one submission, every registered data broker in the state has to delete your data. Over 215,000 people have signed up as of May 2026 [2].
  • Check Vermont's registry. Vermont requires data brokers to register publicly. Search the list at the Vermont Secretary of State's website to see which brokers might have your data, then opt out of each one directly.
  • Stop worrying about the microphone. Start worrying about the auction. If you want to talk to your phone about something private, do it. The microphone is not the threat. The profile is.

The Bigger Picture

Cox Media, MindSift, and 1010 Digital Works did not get caught doing what the FTC accused them of doing. They got caught claiming to do it. The "Active Listening" service did not work because it was never a listening service. It was a markup on email lists with a scary AI pitch attached.

The pitch sold because the audience was already primed. People believe their phones are listening. So a company that promises to monetize that listening gets meetings, gets press coverage, gets small business customers willing to pay above-market rates. The myth makes the fraud easier to commit. The fraud reinforces the myth.

Meanwhile, the actual data broker market keeps operating. The FTC has hit six of the largest location data brokers in 18 months. That is real progress. The settlement announced May 21 does not add to that count. It documents a different kind of harm: a surveillance product that never existed, sold to businesses that did not know they were buying a fake.

The phone is not listening. The data broker is reading.

References

  1. FTC: "FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million to Settle Charges They Deceived Customers About 'Active Listening' AI-Powered Marketing Service" (May 21, 2026)
  2. State of Surveillance: "FTC Goes After Companies That Track Your Every Move" (May 28, 2026) - covers the FTC enforcement wave including Kochava, Mobilewalla, Gravy Analytics, and the same CMG settlement
  3. Hunton Privacy Blog: "FTC Announces Settlements With Three Marketing Firms Over Allegations of Deceptive Statements About Active Listening AI-Powered Services" (June 1, 2026)
  4. Wayback Machine snapshot of the FTC press release (June 2, 2026) - for verification of the press release content