Spyware on Rental Computers: Lessons from the FTC Crackdown
How the FTC’s action against rent-to-own spyware reshaped privacy expectations and compliance duties.
Rent-to-own computers are marketed as an easy way to gain access to technology without paying the full price upfront. Yet a series of enforcement actions by the U.S. Federal Trade Commission (FTC) revealed that, for many consumers, the real cost was their privacy. Hidden surveillance tools were embedded in rental machines, secretly capturing sensitive information and even images from inside people’s homes.
This article explains what happened in the FTC’s spyware cases involving rent-to-own computers, the privacy risks they exposed, and what both consumers and businesses can learn from these events. It does not replicate any particular source, but instead synthesizes public information and legal principles into an original, practical overview.
The Rise of Spyware in Rent-to-Own Business Models
Rent-to-own companies typically provide computers and other electronics under contracts that allow consumers to use products immediately and pay over time. From a business standpoint, one major concern is the risk that devices are lost, stolen, or not returned when payments stop. To address this, some firms turned to remote monitoring and tracking software.
One widely used solution was a software package installed on rental computers that could:
- Identify and disable a device if payments were delinquent.
- Report the physical location of the computer.
- Allow staff to remotely view activity on the machine in certain configurations.
Tracking a device for inventory protection is one thing; secretly monitoring people’s activities at home is another. The crucial legal and ethical issue was not the existence of tracking software itself, but how far that tracking went, and whether consumers were informed and had a meaningful chance to consent.
What the FTC Found: Covert Surveillance in the Home
According to FTC complaints and public statements, seven rent-to-own companies and a software design firm used monitoring features that crossed the line from asset protection into covert spying. The surveillance capabilities included:
- Keystroke logging – capturing everything a user typed, including passwords and private messages.
- Screenshot capture – recording images of whatever was on the computer screen, such as email, bank accounts, and medical portals.
- Webcam activation – remotely turning on the device’s camera and taking pictures of whoever was in front of the computer, inside their home.
These tools were reportedly controlled through a feature sometimes called “Detective Mode.” Once activated, it could send data back to the software provider and the rental store at frequent intervals, without obvious signs to the user that surveillance was occurring. Investigations revealed that intimate images had been captured, including photos of children, partially clothed individuals, and couples engaged in private activities.
Beyond the images, the software collected a broad range of data:
- Usernames and passwords for email, social media, and banking accounts.
- Social Security numbers and financial records such as bank statements and credit card information.
- Medical records and communications with healthcare providers.
In many cases, consumers had no idea that any of this was possible. There were no clear disclosures, no meaningful consent mechanisms, and no way for renters to monitor or control the surveillance functions on their own devices.
Legal Framework: How the FTC Approached the Case
The FTC enforces federal law against unfair and deceptive acts and practices in commerce under Section 5 of the FTC Act. In the rent-to-own spyware cases, the Commission alleged that secretly spying on consumers through rented computers was both unfair and deceptive.
| Legal Concept | How It Applied |
|---|---|
| Deception | Consumers were not clearly told that monitoring software could log keys, take screenshots, or activate webcams. The undisclosed surveillance contradicted reasonable expectations. |
| Unfairness | Secret collection of highly sensitive personal and financial data created substantial harm that consumers could not reasonably avoid and that was not outweighed by any legitimate benefit. |
| Aiding and Abetting | The software developer was accused of providing the tools and services that enabled rental stores to carry out the unlawful monitoring. |
The FTC’s complaint described a pattern of conduct: a software design firm created and marketed monitoring technology to rent-to-own businesses, which then used it to conduct covert surveillance of customers. The Commission viewed the combination of hidden webcam activation, keystroke logging, and screenshot capture as a particularly serious intrusion into the sanctity of the home.
Terms of the FTC Settlements
The cases were resolved through proposed consent orders and later final orders that imposed significant restrictions on the companies involved. According to the FTC, the settlements included several key elements:
- Ban on certain monitoring software: The software company and rental stores were barred from using surveillance tools like “Detective Mode” or similar programs designed to capture sensitive data or webcam images without proper notice and consent.
- Restrictions on geolocation tracking: Location-tracking functions could not be activated without the informed consent of the renter and clear notice to anyone using the computer.
- Prohibition on deceptive data collection: Companies were forbidden from using fake registration screens or other deceptive interfaces to trick users into revealing personal information.
- Limits on using improperly obtained data: Rent-to-own stores could not rely on data gathered through surveillance tools for debt collection or other account-related actions.
- Duties for the software provider: The developer was barred from providing others with technologies or services that facilitate similar illegal surveillance in the future.
- Long-term recordkeeping and compliance: The orders required detailed recordkeeping so the FTC could monitor compliance for up to 20 years.
Separate FTC actions against individual rent-to-own chains reinforced the broader message: companies that use technology to monitor customers without consent risk substantial enforcement consequences, including reputational damage and long-term oversight by regulators.
Privacy Risks Highlighted by the Case
The spyware incidents exposed several categories of privacy risk that are especially relevant in a world where more devices are connected and remotely managed.
1. Surveillance in the Home Environment
Webcams and microphones transform computers into potential surveillance devices. When remotely controlled without the user’s knowledge, they can capture highly personal scenes and conversations occurring in private spaces. The FTC’s findings showed that rental companies had, in effect, the ability to look into people’s homes through their screens.
2. Collection of Highly Sensitive Data
Keystroke logs and screenshots are not limited to routine browsing. They can include:
- Online banking credentials and transaction details.
- Tax information and government benefits portals.
- Medical records accessed through patient platforms.
Compromise of such data can lead to identity theft, financial fraud, and exposure of health information, all of which carry legal, economic, and emotional consequences for affected individuals.
3. Asymmetry of Power and Knowledge
In rent-to-own arrangements, consumers may feel they have little bargaining power or technological expertise. If monitoring tools are hidden or described vaguely, renters cannot reasonably assess the risks or negotiate different terms. The FTC case emphasized the importance of transparency and informed consent in restoring some balance to this relationship.
Guidance for Consumers Using Rent-to-Own Computers
While the FTC settlements addressed specific companies and a particular software product, the underlying privacy issues are broader. Consumers considering rent-to-own computers or other remotely managed devices can take practical steps to protect themselves.
- Ask directly about monitoring: Before signing any contract, ask the store whether any tracking or monitoring software is installed, what it does, and when it is activated.
- Read disclosures carefully: Look for terms related to “remote management,” “monitoring,” “location tracking,” or “security software.” Vague language should be clarified in writing.
- Check system settings: After receiving the computer, review installed applications, startup programs, and security tools. If something is unclear, request documentation from the provider.
- Use dedicated devices for sensitive tasks: If possible, avoid using a rental computer for online banking, tax filing, or accessing medical records. Reserve those activities for devices you own and control.
- Cover the webcam when not in use: A simple camera cover or piece of tape can reduce the risk of visual surveillance, even if software is secretly installed.
If you suspect that a rental computer may be spying on you without consent, you can report the issue to consumer protection agencies. The FTC encourages consumers to file complaints online or by phone when they encounter technology-related privacy problems.
Compliance Lessons for Businesses and Software Providers
The rent-to-own spyware cases carry important lessons for companies that rely on remote monitoring technologies—whether for asset protection, security, or product support.
1. Clearly Separate Security from Surveillance
Businesses may have legitimate reasons to track devices for theft prevention or to remotely disable hardware that is not returned. However, these purposes must be narrowly defined and carefully implemented. Functions that collect personal content, capture images, or log keystrokes typically go beyond what is necessary for asset protection and raise serious fairness and deception concerns.
2. Build Privacy and Transparency into Design
Software providers should incorporate privacy by design principles: limit data collection to what is needed, minimize retention, and provide clear, accessible explanations of monitoring features. Fake registration screens or confusing interfaces that trick users into revealing information are prime examples of practices regulators will scrutinize and often condemn.
3. Obtain Meaningful Consent
Consent cannot be buried in fine print or implied from technical jargon. For high-risk features such as webcam access or geolocation tracking, businesses should use explicit, separate consent flows and make it easy for users to see when monitoring is active. This is consistent with evolving global privacy norms and regulatory expectations.
4. Vet Third-Party Tools and Vendors
Companies that rely on third-party software are not insulated from liability. The FTC’s orders underscored that software suppliers can be held responsible for enabling unlawful surveillance, and that client companies can be accountable for how they deploy those tools. Due diligence, contractual safeguards, and ongoing audits of vendor practices are essential.
Frequently Asked Questions (FAQs)
Is it ever legal for a rent-to-own company to track a computer?
Yes, tracking a device’s location or disabling it for security or asset recovery purposes can be lawful if it is clearly disclosed, reasonably limited, and implemented with appropriate safeguards. The FTC’s settlements allowed certain tracking functions to continue, provided consumers were informed and gave consent.
What made the spyware in these cases unlawful?
The FTC alleged that the rent-to-own companies and the software provider secretly collected powerful personal data and images without notice or consent. The combination of hidden webcam activation, keystroke logging, and screenshot capture in the home went beyond any legitimate business need and was considered both unfair and deceptive.
Did the companies face financial penalties?
Some settlements focused primarily on behavioral remedies—banning certain practices, restricting data use, and imposing long-term compliance obligations rather than large monetary penalties. However, enforcement actions and subsequent scrutiny can carry substantial reputational and operational costs.
Are similar issues possible with other connected devices?
Yes. The same kinds of risks arise with smartphones, tablets, smart TVs, and Internet of Things devices when companies deploy undisclosed monitoring tools. The core principles from the FTC’s actions—transparency, consent, and limits on data collection—apply broadly across device categories.
How can I report suspected spyware on a rented device?
Consumers in the United States can contact the FTC and state attorneys general to file complaints about undisclosed monitoring or spyware on rented devices. The FTC provides online complaint forms and contact information for reporting suspected unfair or deceptive practices.
References
- Software let rent-to-own companies spy on customers — Los Angeles Times. 2012-09-25. https://www.latimes.com/business/la-xpm-2012-sep-25-la-fi-tn-designerware-pc-rental-agent-20120925-story.html
- FTC Halts Computer Spying — Federal Trade Commission. 2012-09-25. https://www.ftc.gov/news-events/news/press-releases/2012/09/ftc-halts-computer-spying
- Rent-to-Own Laptops Secretly Photographed Users Having Sex — Wired. 2012-09-25. https://www.wired.com/2012/09/laptop-rental-spyware-scandal/
- FTC, Rent-to-Own Stores Settle Charges of Spying on Consumers via Rented Computers — Ifrah Law. 2013-11-04. https://www.ifrahlaw.com/ftc-beat/ftc-rent-to-own-stores-settle-charges-of-spying-on-consumers-via-rented-computers/
- Think Twice About Rent-to-Own Computers — Call 12 for Action / YouTube (local news segment summarizing FTC claims). 2012. https://www.youtube.com/watch?v=8aGkeiqUXdQ
- Aaron’s Rent-To-Own Settles FTC Computer Spying Charges — IPWatchdog. 2013-10-22. https://ipwatchdog.com/2013/10/22/aarons-rent-to-own-settles-ftc-computer-spying-charges/
Read full bio of medha deb





