MarTech Vendors Secretly Sell Your Data to Competitors

MarTech Vendors Secretly Sell Your Data to Competitors

Milena Traikovich is a highly regarded expert in demand generation and forensic marketing analytics, known for her ability to peel back the layers of complex advertising technologies. With years of experience helping high-growth businesses optimize their lead quality, she has developed a specialized eye for the technical underpinnings that many marketers overlook. Her work focuses on the intersection of performance optimization and data integrity, ensuring that the tools companies use to grow are not actually working against them. Today, she shares her insights into the widespread use of deceptive code in marketing software and the hidden risks of modern AI-driven data integrations.

In this discussion, we explore the alarming prevalence of “defeat devices” in marketing software that actively hide tracking behaviors from compliance auditors. Milena outlines how typical CRM and marketing automation integrations often provide vendors with unnecessary and intrusive access to internal communications and sales pipelines. We delve into the concept of data laundering, where vendors take proprietary company information and sell it back to competitors under the guise of intent data. Finally, the conversation highlights the security failures inherent in new AI Model Context Protocols and the financial consequences of subsidizing a competitor’s customer acquisition through unvetted data sharing.

How have you seen marketing software vendors use deceptive code to bypass compliance checks and auditing tools?

It is genuinely disturbing to see the lengths some software vendors go to hide their tracking activities, often employing what we call “defeat devices” within their source code. This is very similar to the Volkswagen Dieselgate scandal, where the software was specifically designed to detect when it was being tested and change its behavior accordingly. In my forensic analysis, I have seen code that checks for signs of automated analysis or compliance auditing and immediately disables its tracking functionality to appear harmless. When the software detects a normal visitor, it switches back and executes the de-anonymization code as expected. After reviewing over 700 vendors, it is clear that this isn’t an isolated incident; practically no one in the ABM or intent data space is completely clean of these types of deceptive practices. It feels as though the floodgates have opened, and we are now dealing with a marketplace where software is built to actively deceive the very people meant to keep it in check.

Why is the standard practice of connecting CRMs and internal communications to marketing tools creating such a massive security risk?

The risk is massive because most marketing departments view these integrations as simple administrative tasks rather than critical security decisions. When you connect a third-party tool to your CRM or marketing automation platform, you are often granting that vendor full visibility into every byte of your sales pipelines, service tickets, and even private internal emails. There is no logical reason why an intent data provider needs access to your internal communications to provide their service, yet they demand it anyway. They take all of this data, launder it through their own internal aggregation machines, and then have the audacity to sell it right back to your competitors. It creates a scenario where your most sensitive internal data is being used to build commercial products that directly benefit your rivals, all because we treat these vendors as partners instead of potential adversaries.

What is the underlying reason that even experienced marketers and sales professionals often fail to see these operational red flags?

The unfortunate truth is that for most marketing and sales professionals, the technical depth required to spot these red flags is simply not part of their daily discipline. They are looking for results and high-quality leads, so they don’t think to ask, “Gosh, this thing is interacting with my data, I wonder what it is doing in the background?” Most lack the technical expertise to perform a forensic analysis of browser code or network traffic to see if a vendor is being honest about their data collection. This creates a huge operational security failure point because there is a total lack of informed consent regarding how internal communications are handled. People feel like their data is private, but in reality, they are operating in an environment where vendors have full visibility into the very heart of their company. It is a sensory blind spot that vendors are all too happy to exploit for their own commercial gain.

How do newer AI integrations like Model Context Protocols further expose a company’s proprietary data to outside parties?

AI and Model Context Protocols (MCP) represent a new frontier of risk because they allow systems to exchange data and instructions with almost no human oversight at all. When you install an MCP, you are essentially connecting your internal systems directly to someone else’s computer, which can lead to rapid and invisible data exfiltration. If you do not know exactly what instructions an MCP is giving to the AI model, you have no way of knowing if it is passing your proprietary information back to the vendor. We’ve already seen cases where AI agents were prompted to ask the model what else it was working on, effectively harvesting data from other users without any meaningful consent. It turns a tool meant for efficiency into a “Soylent Green” scenario where the product is actually made of your own data, repackaged and sold back to you as a service.

What were the implications of the recent controversy where a major platform changed its terms to automatically opt customers into data enrichment?

The HubSpot incident was a major wake-up call because it demonstrated how easily a company can change its terms to treat one customer’s data as a resource for everyone else. By automatically opting in all of their customers to a system that took enrichment data from one company to supplement another company’s records, they fundamentally broke the trust of their user base. It highlights a predatory business model where your first-party data is harvested to build commercial intent products that are then marketed to the entire industry. While the company eventually reversed the change after a massive backlash, it shows that “informed consent” is often buried deep in the fine print of terms and conditions. Many people are only now starting to realize that the intent data they are buying is often just their own data being circulated through the market in a different wrapper.

In what ways does this lack of data ownership ultimately hurt a company’s bottom line and its marketing metrics?

The financial fallout of this data leakage is often seen in marketing dashboards that simply stop making sense or start providing misleading information. When your internal data is being used to feed the commercial products of your competitors, you are essentially subsidizing their customer acquisition costs while your own costs go through the roof. Your attribution models start lying to you because the data they rely on is being manipulated or shared in ways you don’t control, making it impossible to see the true ROI of your campaigns. It creates a frustrating cycle where you are spending more money to acquire customers because your competitors now have an unfair advantage fueled by your own proprietary insights. Ultimately, it erodes the competitive edge that first-party data is supposed to provide, leaving you paying premium prices for the very data that you originally owned.

What is your forecast for the future of intent data and marketing privacy?

I believe we are entering an era of radical transparency where companies will no longer be able to hide behind opaque “black box” integrations and deceptive code. As forensic analysis becomes more common, we will see a massive shift toward “clean” analytics platforms that prioritize data sovereignty over the convenience of easy de-anonymization. Marketers will be forced to become much more technically savvy, treating every software integration as a high-stakes security decision rather than a routine task. We will likely see the rise of more stringent regulations that prohibit the laundering of CRM data, which will eventually collapse the current “Soylent Green” model of intent data. The companies that survive and thrive will be those that take ownership of their data and demand total visibility into how their vendors are interacting with their internal systems.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later