The metaverse: Privacy and information security risks

Héctor Laiz-Ibanez, Cristina Mendaña Cuervo, Juan Luis Carús Candás · International Journal of Information Management Data Insights · 2025

• The metaverse, powered by technologies such as Virtual Reality (VR), Augmented Reality (AR), Artificial Intelligence (AI), the Internet of Things (IoT), and blockchain, offers transformative potential but also introduces multifaceted privacy and security risks. • Diverse threats in the metaverse, from data breaches to surveillance capitalism, have significant impacts on individual privacy and societal stability. • The need for comprehensive security solutions across all metaverse components is highlighted, emphasizing the vulnerabilities of AI and IoT technologies. • Stakeholders like healthcare providers, educators, regulators and technologists play a pivotal role in implementing robust privacy and security measures. • Strategies for risk mitigation include standardization, user education, holistic security approaches, privacy by design, regulatory oversight, AI and IoT security, and continual research and innovation. The advent of the metaverse—a convergence of physical and virtual realities catalyzed by a spectrum of emerging technologies—heralds a new epoch in the digital era. As the metaverse unfolds its immense potential, it simultaneously reveals unprecedented privacy and information security risks. Understanding these risks is paramount, as the pose significant implications for user safety, data integrity, and the overall trustworthiness of the metaverse. Consequently, this paper conducts a Systematic Literature Review (SLR) to meticulously analyze these emerging risks. Utilizing the Population, Intervention, Comparison, Outcomes, Context (PICOC) method, the review examines 735 articles from four databases, distilling essential insights from 35 key studies. The review identifies major challenges, including vulnerabilities in AI and IoT integration, threats from surveillance capitalism, and insufficient user education on privacy risks. To address these issues, the study proposes strategies such as holistic security frameworks, privacy-first design principles, and multi-stakeholder collaboration. These findings provide actionable insights for navigating the intricate dynamics of the metaverse, fostering a secure and privacy-conscious digital ecosystem. The study’s contributions aim to guide academic discourse, inform industry practices, and influence future policy development. The contributions from this research are intended to stimulate further academic discourse and influence future practices and policy in the context of the metaverse.

Read the paper · More papers on PaperTik