Skip to content

Is CCleaner safe? The record, with dates

The 2017 supply-chain compromise, the Jumpshot shutdown, bundled installer offers, and what CCleaner does fine today. The factual record, dated.

JH Jack Holmes 4 min read

People search this question for a reason. CCleaner is one of the most downloaded Windows utilities ever made, and it also carries a history that keeps the question alive. Here is that record, with dates, followed by what we think it teaches.

One disclosure first. We make eclean, a competing Windows maintenance app. Judge this post against the sources, not our word.

The short answer

CCleaner today is a functioning junk cleaner from a large security company, and there has been no known compromise of it since 2017. The reasons for caution are historical, but they are real history, and they involve the product, its installer, and its owner.

September 2017: the supply-chain compromise

On July 19, 2017, Avast acquired Piriform, the London company behind CCleaner. Unknown to both companies, attackers were already inside Piriform's network. Avast's later investigation found they had entered via TeamViewer in March 2017.

On August 15, 2017, Piriform shipped CCleaner 5.33.6162 with a backdoor compiled into it, signed with a valid Piriform certificate. Every affected download was the genuine product from the genuine vendor. Cisco Talos detected the malicious traffic on September 13, 2017, and the compromise was disclosed on September 18, 2017.

By Avast's count, about 2.27 million users ran the backdoored build. The first stage collected machine information. A second-stage payload was then delivered to roughly 40 computers inside major technology companies, which investigators read as targeted espionage using CCleaner's install base as the delivery vehicle.

Avast and Piriform pushed clean updates, worked with law enforcement, and published detailed investigation updates. The response was competent. The lesson stands anyway. The compromise was invisible to users, because the malicious build looked exactly like the trustworthy one.

August 2018: the monitoring version

In late July 2018, CCleaner 5.45 shipped with expanded "Active Monitoring" analytics. Users found that disabling monitoring did not stick across restarts, that closing the app minimized it to the tray instead of quitting, and that the free version offered no working opt-out from data collection.

After public backlash, Avast pulled 5.45 within days and rolled users back to 5.44, promising separate controls for cleaning alerts and analytics. The rollback was the right call. It was also a self-inflicted wound. The behavior arrived in a changelog line that read only "added more detailed reporting for bug fixes and product improvements".

January 2020: Jumpshot

On January 30, 2020, Avast shut down Jumpshot, its analytics subsidiary, after a joint Motherboard and PCMag investigation showed Jumpshot had been selling detailed user browsing data to large corporate customers. In February 2024, the FTC fined Avast 16.5 million dollars over the practice and banned it from selling browsing data.

To be precise, the products named as feeding Jumpshot were Avast and AVG antivirus products and browser extensions, not CCleaner itself. It belongs in this record because Avast owned CCleaner throughout, and the episode describes how CCleaner's owner treated user data when it thought nobody was reading the contracts.

The installer

Separately from the incidents, CCleaner's free installer has at various times shipped bundled offers, such as Google Chrome or Avast products, sometimes pre-selected. This is common in free Windows software and it is disclosed on the way through, but it means the installer has historically asked for more attention than the download button suggests.

What CCleaner does fine today

Fairness requires the other side. CCleaner's core cleaning works and has for two decades. It clears browser and application clutter, shows you the files before removal in Custom Clean, and the free tier remains genuinely usable for that job. Since September 2022 it has been owned by Gen Digital, the company formed from the merger of NortonLifeLock and Avast, with mature security engineering behind it. The 2017 attackers were also caught by outside researchers within weeks, which is better than many supply-chain victims managed.

If you use CCleaner today for junk cleaning, download it from the official site, read the installer screens, and skip the registry cleaner. Used that way, it is not dangerous.

What the record teaches

The 2017 compromise is the instructive part. Reputation did not protect anyone. The backdoored build came from the most trusted name in the category, correctly signed. Reputation is a statement about the past, and it fails silently.

What holds up better is verifiable behavior. A cleaner should show you what it will remove before it removes it, explain each change, keep an undo, and give you ways to check its claims from outside the app. Those properties do not prevent every attack, but they shrink what you have to take on faith, and they tell you how a vendor thinks about your machine.

That standard is what we build eclean against, and we ask you to apply it to us too. Our eclean vs CCleaner comparison states plainly where CCleaner is fine, and our trust center collects the evidence we can offer for our own claims. Verify, in every case, rather than trust.

See the writing put to work.

eclean is free on Windows 10 and 11, and it explains every change before making it.

Download eclean