Dark patterns are deceptive user experiences that take advantage of people’s habits of using websites and apps to trick them into doing something they did not intend to do.

Dr Harry Brignull, an UX designer, coined the term on July 28, 2010, with the registration of the domain darkpatterns.org (now deceptive.design), a site devoted to naming and shaming deceptive user interfaces.

Brignull identified 12 categories of dark patterns:

  • Friend spam happens when someone asks for your contacts under false and good pretenses but then sends spam to them, claiming it’s from you
  • Forced continuity occurs when your free trial ends, and you get charged, so it is a hurdle for you to cancel
  • Ads disguised as different kinds of content or navigation within the website, so you click on them
  • Confirmshaming, which is an act of guilting the user into opting in for something by shaming them into compliance
  • Bait-and-switch is when you set out to do one thing for a given outcome, but a different and undesirable effect happens instead
  • Hidden costs, which make something appear cheaper only so at the last step of the checkout process, you are told of the additional charges
  • Roach motels, which are designed to make it very easy for you to get into a certain situation, but then hard to get out of it, like a subscription
  • Privacy zuckering, named after the Meta CEO, is used to trick you into publicly sharing more information about yourself than you want
  • Misdirection, which intentionally focuses your attention on one thing to distract you from something else
  • Price comparison prevention is when the retailer makes it hard to compare prices of items, so you cannot make an informed decision – thankfully, this is mostly outdated now.

Each of the above practices have now become recognized by various legislative bodies. For example, European Data Protection Board, which published a special guidelines of using dark patterns in social media platforms.

You may also like:


  • PHI and PII

    HIPAA violations and fines: What healthcare organizations need to know

    Quick summary HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew.  What this guide covers: HIPAA violation…

  • The EDPB’s new data anonymization guidelines: what they mean for your analytics data

    Removing names, cookies and IP addresses is no longer enough to anonymize data. Here’s what the 2026 EDPB framework actually requires for anonymous data collection, what’s still unresolved, and how to configure your analytics to stay compliant while keeping the full view of traffic marketers rely on.