The U.S. military has disabled advertising tracking on service members’ devices following reports that foreign adversaries exploited commercial location data to identify and target American troops, according to a letter from a U.S. senator reviewed by TechCrunch. The confirmation that the Department of Defense acted to prevent advertising identifiers from being used to track the movements of deployed personnel marks a rare public acknowledgment of an operational security failure linked directly to the commercial data broker industry.
The senator’s correspondence, addressed to a technology company executive, outlines how mobile advertising identifiers and similar tracking mechanisms allowed adversaries to identify the locations of service members, including at sensitive overseas installations. The letter does not specify the date the tracking was disabled, the exact technical measures implemented, the number of service members affected, or the identities of the foreign adversaries involved. It also does not detail the specific incidents that prompted the action.
The disclosure adds to a growing body of evidence that commercially available smartphone location data, often gathered through seemingly innocuous consumer applications and resold through advertising networks, has been weaponized against U.S. military personnel. Investigative reporting in recent years has documented cases in which aggregated movement data from fitness apps, weather applications, and other consumer tools revealed the locations of forward operating bases, patrol routes, and other sensitive military infrastructure.
What happened
The Department of Defense took steps to disable advertising tracking on devices issued to or used by service members after receiving credible reports that the underlying data had been exploited for targeting purposes. The action was confirmed through a senator’s letter directed at a technology executive, suggesting congressional oversight of the issue. The intervention targets mobile advertising identifiers, the persistent pseudonymous labels embedded in smartphone operating systems that allow marketers and their partners to track user behavior across applications and link that activity to precise geographic coordinates.
The senator’s letter does not disclose whether the disabling applies only to government-issued devices or extends to personal phones used by service members, nor does it specify the platforms or operating systems affected.
Why it matters
The episode highlights a long-standing structural gap between the consumer technology ecosystem’s data collection practices and the national security expectations placed on service members. Mobile advertising identifiers are not designed as surveillance tools, but they function as persistent pseudonymous labels that can be cross-referenced with location data and other signals to build detailed movement profiles. When that data flows to third-party brokers, the protective assumptions of an ordinary smartphone user, including the belief that location data is anonymized and used only for commercial purposes, break down against adversaries capable of purchasing or intercepting bulk datasets.
The issue also raises accountability questions for the platforms and brokers that collect and monetize such data. If location information tied to military personnel was accessible through standard advertising channels, it indicates either insufficient vetting of who can purchase location datasets or a failure to recognize the sensitivity of identifying users inside restricted installations. The Department of Defense’s response suggests the vulnerability was treated as actionable once confirmed, but the absence of disclosed timelines leaves open how long the exposure persisted before mitigation.
Background and context
Concerns about the military implications of commercial location data have circulated for nearly a decade. In 2018, fitness tracking company Strava published a global “heatmap” of user exercise routes that inadvertently revealed the outlines of classified U.S. and allied military facilities in Afghanistan, Syria, and other conflict zones. Subsequent reporting documented similar exposures through weather applications, dating apps, and other consumer tools that collect precise geolocation data as part of their core functionality.
Those incidents prompted internal reviews within the Defense Department and contributed to broader policy discussions about the risks posed by aggregated mobile data. A 2020 investigation by the Wall Street Journal found that location data harvested from smartphones was flowing to commercial brokers and, in some cases, ending up in the hands of contractors working for U.S. government agencies. A separate 2022 report by the Office of the Director of National Intelligence concluded that commercially available information, including location data, was being used by foreign intelligence services for targeting purposes, though the assessment did not single out any specific service members or installations.
The advertising technology industry has faced increasing regulatory and legal pressure over its handling of location data. Apple’s 2021 introduction of App Tracking Transparency and subsequent privacy changes by Google altered the flow of identifier data to brokers, but enforcement of existing rules has remained uneven. Several U.S. states have passed or proposed legislation restricting the sale of precise geolocation data, and the Federal Trade Commission has brought actions against brokers accused of selling sensitive location information without adequate safeguards.
Analysts tracking surveillance of trade and military technology supply chains have repeatedly warned that commercial data brokers constitute an underregulated layer of the surveillance economy, with implications extending well beyond targeted advertising. Brokers have been shown to sell data drawn from a wide range of consumer applications, including those used by military personnel, to clients with little or no vetting of intended use.
What to watch next
Several developments will help determine whether the Defense Department’s action resolves the underlying vulnerability or merely narrows one of several exposure paths. Key questions include whether the disabling applies only to government-issued devices or extends to personal phones used by service members in operational settings, and whether the policy covers all major mobile operating systems. The senator’s letter and any forthcoming responses from the technology company named in the correspondence may provide further detail.
Congressional oversight of the commercial data broker industry is also likely to intensify. Lawmakers from both parties have introduced legislation aimed at restricting the sale of sensitive location data, particularly data tied to military personnel, and the latest disclosure could accelerate that work. The Defense Department’s Inspector General and the military services’ operational security commands are likely to conduct their own reviews to determine how long the exposure persisted and whether any service members were harmed as a result.
Industry response will also be a factor. Major platform operators have indicated in past disclosures that they restrict access to certain types of location data, but the effectiveness of those restrictions has been questioned. Future disclosures from technology companies, regulators, or oversight bodies will help clarify whether current safeguards are adequate for the protection of military personnel.
Analysis: The structural problem exposed
The decision to disable ad tracking reflects the long-standing gap between the consumer technology ecosystem’s data collection practices and the national security expectations placed on service members. Advertising identifiers, designed to allow marketers to track user behavior across applications, function as persistent pseudonymous labels that can be linked to precise geographic coordinates. When that data flows to third-party brokers, the protective assumptions of an ordinary smartphone user, including the belief that location data is anonymized and commercially oriented, break down against adversaries capable of purchasing or intercepting bulk datasets.
The episode also raises accountability questions for the platforms and brokers that collect and monetize such data. If location information tied to military personnel was accessible through standard advertising channels, it indicates either insufficient vetting of who can purchase location datasets or a failure to recognize the sensitivity of identifying users inside restricted installations. The Department of Defense’s response suggests the vulnerability was treated as actionable once confirmed, but the absence of disclosed timelines leaves open how long the exposure persisted.
The broader significance extends beyond any single incident. Commercially available data has become a foundational input for both commercial surveillance and intelligence operations, and the boundaries between the two have increasingly eroded. The latest disclosure is likely to intensify scrutiny of the data broker industry, particularly its handling of location data tied to sensitive populations, and could prompt more aggressive regulatory action at both the state and federal levels.
Conclusion
The Department of Defense’s decision to disable advertising tracking on service members’ devices represents a notable acknowledgment that commercial data practices have created operational security risks for U.S. military personnel. The disclosure, conveyed through a senator’s letter to a technology executive, leaves key details unresolved, including the scope of the action, the duration of the exposure, and the identities of the adversaries involved. Those gaps are likely to draw further congressional attention and could accelerate regulatory efforts targeting the commercial data broker industry. The episode underscores the extent to which the surveillance economy built around consumer applications has become intertwined with national security concerns, and the difficulty of reconciling the two.
Sources
– https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/
Source: TechCrunch
Corrections
If you believe this article contains an error, contact Herald Express with the source URL and supporting evidence.
Story synopsis gathered from: TechCrunch — source