EU Rules Expose Google Search Queries to Hackers

Google warns that proposed EU regulations could expose search queries to hackers and fuel cybercrime across the bloc.

By Central
Heather Adkins, Google's security chief, cautions that sharing search data under the DMA could lead to de-anonymization and fraud.
Highlights
  • Google’s security chief warns that sharing search query data could allow attackers to de-anonymize users.
  • Proposed Android interoperability measures could lead to a rapid increase in fraud across the EU.
  • Competitors and researchers argue that privacy risks have been overstated and that data sharing is critical for competition.

Google’s top security executives are warning that proposed European Commission regulations intended to open its search data and Android operating system to competitors could inadvertently expose users’ search queries to hackers and fuel a rise in cybercrime across the EU. The warnings come as officials prepare to make final decisions next month on two cases under the European Union’s Digital Markets Act (DMA), the landmark competition framework adopted in late 2022 to force Big Tech gatekeepers to open their dominant platforms to rivals.

How the Digital Markets Act Could Expose Google Search Data

The European Commission has proposed that Google share anonymized search data with competitors on terms that match the data the company collects for itself. This includes any query input users type into Google Search, associated click data, and ranking results. The goal is to give rival search engines and AI services access to a dataset that has been exclusively controlled by Google for years, with the aim of fostering competition and reducing reliance on a small number of tech giants.

Separately, the Commission is pushing for greater interoperability with Google’s Android operating system. Both proposals are currently under public consultation, with final decisions expected by July 27.

Google’s Security Chief Warns of Fraud and De-Anonymization Risks

Heather Adkins, Google’s vice president of security engineering and a founding member of its security team, has raised specific concerns about the practical implications of the proposed changes. On the Android side, Adkins predicts a rapid increase in fraud if the interoperability measures are implemented as currently described. “If implemented as described today, I think within a short period of time on Android, we’d see a significant increase in fraud in the EU,” Adkins said. “The fraudsters are creative and informed. Past implementation date, I would give it maybe weeks before we began to see an increase in fraud in Europe.”

Regarding Google Search, Adkins warned that sharing granular search query data—even in anonymized form—could allow bad actors to de-anonymize users. The concern is that small companies receiving this data could become prime targets for criminal hackers, potentially exposing sensitive personal information derived from what people type into Google.

Competitors and Researchers Push Back on Privacy Concerns

Not all stakeholders share Google’s alarm. Some competitors, independent researchers, and academics who have participated in the public consultations argue that the privacy and security risks have been overstated. They point out that the DMA already requires data to be anonymized and that there are established technical safeguards to prevent abuse. The Knight-Georgetown Institute’s executive director, Alissa Cooper, noted that search query data is a unique dataset that no competitor can realistically replicate, making its sharing a critical lever for competition.

The European Commission declined to respond directly to Google’s security concerns but has emphasized that the DMA includes provisions to protect privacy and security. The agency is expected to issue its final rulings next month, which will determine the exact scope of the data-sharing and interoperability obligations.

What the Proposed Changes Mean for Users

If the proposals go through as currently drafted, users in the EU could see their search queries—including sensitive searches related to health, finances, or personal life—shared with third-party search engines and AI services. While the data is intended to be anonymized, Google’s security team argues that the volume and specificity of query data make re-identification feasible for determined adversaries. On Android, increased interoperability could open new vectors for malware and fraud, potentially affecting millions of devices.

What Affected Users Should Do Now

For users concerned about the privacy and security implications of these proposed changes, the most effective course of action is to adopt defense-in-depth practices. Use a reputable VPN service with a verified no-logs policy and AES-256 encryption when searching online to add a layer of traffic protection. Enable two-factor authentication on all accounts, particularly your Google account, and monitor account activity for unauthorized access. Consider using a zero-knowledge password manager to generate and store strong, unique credentials. For Android users, avoid sideloading apps from untrusted sources and keep your device’s security patches up to date. These measures will not only mitigate risks associated with potential data exposure but also strengthen your overall digital security posture against an evolving threat landscape.

Share This Article