Clearing your cookies used to feel like a small act of rebellion. A few clicks, and the trail you'd left across the web went cold — the advertisers lost their thread, and you started fresh. That fail-safe is quietly becoming obsolete, and not because cookies got smarter. Because the tracking moved somewhere you can't reach: into the network connection itself, run by the company that already knows your name, your address, and your phone number.
The clearest example of this shift carries a deliberately forgettable name: Utiq. Understanding what it is, who built it, and why it slips past your usual defenses tells you almost everything about where online tracking is heading in 2026 — and why your delete button stopped mattering.
Who actually built this
Utiq isn't some obscure startup. It launched in March 2023 as a joint venture between four of the most powerful telecom companies on the European continent: Deutsche Telekom, Orange, Telefónica, and Vodafone. Four giants who, between them, already carry an enormous share of Europe's internet traffic, deciding to turn that infrastructure into an advertising identity layer.
The growth has been brisk. By June 2025, Utiq reported reaching 26 telecom operator partners — many of them smaller carriers leasing connections from the big four — and more than 55 million unique ConsentPass tokens in circulation across Germany, Austria, Spain, France, the UK, and Italy. Since then it's added a global CEO and struck an integration deal with The Trade Desk, one of the largest independent ad-tech firms in the world. This is not an experiment winding down. It's an infrastructure scaling up.
How a connection becomes an identity
The mechanics are worth slowing down on, because the cleverness is in what doesn't happen.
When you load a participating website, the site doesn't drop a file onto your device. Instead it checks whether your IP address belongs to a partner ISP. If it does, you see a consent banner asking whether you agree to be identified through your network connection. Click accept, and the site sends a secure request to your carrier.
Your provider then does the part that changes everything. It takes your connection — using your phone number or broadband account ID as the cryptographic seed — and generates a unique, anonymized token called a ConsentPass. From that, Utiq spins out two further encrypted tokens: a MartechPass handed to advertisers and publishers so they can recognize you across different sites, and an AdtechPass used to measure whether an ad led to a sale.
Notice what's absent. No cookie sitting in your browser storage. No file on your hard drive. The identifier never lives on your device at all — it's generated on demand by your carrier and lives on their servers. That single design choice is the whole game.
Why this is harder to shake than a cookie
A cookie, for all its faults, was something you possessed. It sat in your browser, and you could throw it away. A network token flips that relationship entirely, and the consequences stack up in ways that should give anyone pause.
Anchored to your billing identity
A ConsentPass traces back to your phone number or broadband account — your real name, address and contract. You can't clear it, because it was never yours to clear.
The household problem
If the token keys off your home broadband, your partner, your kids and houseguests all surface under one network identity. Individual privacy collapses into a single profile.
It follows you across devices
Because the anchor is the network, not the hardware, switching from laptop to phone on the same connection keeps the tracking thread intact.
There's a darker tail risk, too. Your phone number is never exposed to the websites directly — Utiq protects it with a one-way hash and a cryptographic salt known only to the carrier and Utiq. In theory that makes reversal impossible. In practice, if that hashing were ever compromised, or a carrier leaked the mapping between numbers and tokens, every advertiser holding your tokens could suddenly link your browsing back to your real phone number.
You can wipe every stored trace and the token still rides along with your connection.
The research that undercuts the "privacy-first" pitch
Utiq markets itself hard as a privacy-by-design alternative to American ad-tech, complete with explicit consent and a portal where you can withdraw it. On narrow technical points, that pitch isn't entirely empty. But independent scrutiny tells a less flattering story.
A peer-reviewed study from researchers at the Universitat Politècnica de Catalunya examined the system and reached a blunt conclusion: ConsentPass tokens are functionally similar to third-party cookies, built to identify users consistently over time — and potentially more intrusive, precisely because they're seeded from unique parameters and can't be wiped the way browser cookies can.
The finding that should end the "replacement" framing, though, is this one. Across the 10,000 Utiq-using websites the researchers surveyed, every one of which also deployed additional, more invasive tracking methods alongside it — fingerprinting included. Utiq isn't retiring the old surveillance toolkit. It's being bolted on top of it, one more instrument in an already crowded arsenal.
The consent banner is doing a lot of heavy lifting
Defenders of the system lean on a single word: consent. Nobody gets tracked, the argument goes, unless they tap "accept." A ConsentHub portal even lets you review which companies hold your tokens and revoke them whenever you like.
The problem is that this depends on a version of human behavior that doesn't exist. By 2026, most people treat consent banners as an obstacle between them and the article they came to read. They click through on autopilot, conditioned by years of identical pop-ups engineered to make agreeing effortless and refusing tedious. Tap "Accept All" once, in a hurry, and your carrier is authorized to start broadcasting your network identity.
The portal suffers the same fate. It exists, it works — and almost nobody knows it's there, let alone visits it to audit their tokens. A control that no one uses isn't much of a control. And critically, because the whole exchange happens server-to-server between the website and your ISP, none of the usual cleanup gestures touch it. Opening a private window or clearing your history afterward does nothing, because the authentication never relied on anything stored in your browser to begin with.
Where a VPN genuinely helps — and where it stops short
Here's a piece of good news, and it's worth stating plainly because it's one of the rare clean wins in this story. The entire Utiq flow only fires if your IP address belongs to a partner network. That's the trigger. So if you route your traffic through a VPN, the website sees the VPN server's IP instead of your real one — and the system never recognizes you as a partner customer. The consent dialog doesn't appear, and since consent is never assumed, no token gets generated.
But it's worth being honest about the boundary. A VPN addresses the IP-based trigger for network-level identity. It does nothing about the other tracking the research found running on those same sites — the fingerprinting scripts, the analytics pixels, the conventional surveillance layered alongside Utiq. Hide your IP and you've shut one door while several others stay open. The token problem and the broader tracking problem are related, but they aren't the same problem, and one tool rarely closes both.
Blocking the request before it leaves the page
That's the gap worth closing from a different angle. The network token only gets created if the website's code successfully reaches out to initiate it — the API calls, the background scripts, the endpoints that quietly hand the request off toward the telecom identity infrastructure. No outbound request, no token generation.
This is the layer the Total Adblock App works on. Rather than waiting at the IP level or hoping you'll decline a banner you'll never read carefully, it analyzes the structural requests a page tries to make and identifies the scripts and endpoints tied to these telecom tracking networks. When a site attempts to kick off the token-generation handshake, that connection gets severed before it can complete — so your carrier is never pinged to vouch for your identity in the first place.
The advantage of intervening there is reach. The same script-level filtering that interrupts a network-token request also goes after the fingerprinting and analytics code the researchers found running on every Utiq site they checked. Instead of patching one trigger and leaving the rest live, you're cutting off the broader pipeline at the point where it actually executes: inside the page, before anything reaches a server. And because it runs quietly in the background, your connection keeps working normally — the surveillance gets starved, not your bandwidth.
Taking back the delete button
The shift from cookies to network tokens isn't a technical footnote. It's a change in who holds the off switch. With a cookie, that switch was in your browser, in your hands. With a carrier-anchored identifier tied to your billing name and seeded from your phone number, the switch moved onto someone else's servers — operated by companies that already know more about you than any advertiser ever could.
You don't have to accept that the firm selling you internet access also quietly maps where you go on it. Block the request before it's made, keep the fingerprinting scripts from running alongside it, and the bridge between your connection and your identity simply never gets built. Reclaim control of what leaves your browser, starting today.

