Tracker Leak Puts U.S Troops in Crosshairs

The Pentagon shut off advertising IDs on military devices because commercial phone data was helping enemies find U.S. troops.

Story Snapshot

  • Military branches disabled ad identifiers on phones and computers used by troops.
  • Central Command warned that brokers’ location data helps target U.S. personnel.
  • Congress pressed for stronger safeguards beyond device settings.
  • Ad-tech markets can reveal patterns of life around bases and missions.

What changed on military devices and why it matters

Military officials told Senator Ron Wyden that the Air Force, Army, and United States Special Operations Command disabled advertising identifiers on service-issued devices. The Air Force moved about two months before the letters were released. The Army acted earlier this year. United States Special Operations Command blocked them on Windows devices. These steps aim to reduce the steady stream of location data that ad-tech systems collect and resell, which can expose troop movements and routine patterns.

U.S. Central Command warned earlier this year that adversaries were exploiting commercial location data to track, monitor, or even target U.S. forces. The command said this data can show where troops gather and how they move. That insight supports missile and drone targeting and helps plan roadside bomb attacks. The warning pushed lawmakers to demand tighter rules, fewer permissions for apps, and less exposure to ad-driven tracking on government devices.

The risk comes from the ad market, not just one app

The danger flows from how the mobile advertising system works. Many apps share a phone’s unique ad ID and location with ad networks. Data brokers then buy, blend, and sell that data to anyone with a credit card. Investigations showed this pipeline can map life inside and around military sites with shocking detail. One analysis traced 3.6 billion location points tied to up to 11 million ad IDs in a single month in Germany, enough to study base routines and commutes.

Turning off ad IDs cuts a major link in that chain. It reduces the signals that apps and brokers use to stitch a person’s movements together across time and place. That helps protect patrol routes, staging areas, medical visits, and off-base housing from pattern-of-life tracking. It lowers the chance that foreign intelligence services can buy a cheap map of American targets from a public marketplace built for selling sneakers and streaming subscriptions, not battlefield secrets.

Lawmakers back the move but want stronger shields

Senator Wyden and Representative Pat Harrigan pushed for a Pentagon review of safeguards across the force. They cited the Central Command warning and the risk that device settings alone may not block all data flows. Their ask was simple: standardize protections, clamp down on app permissions, and treat ad-tech like a live surveillance threat, because it is one. That posture aligns with common-sense security and the duty to give warfighters every advantage.

Device controls help, but policy must match. Units need default-deny app stores for government devices, strict controls on location sharing, and rapid patching. Leaders should train troops to separate personal and duty phones and to keep personal devices off networks near sensitive activity. Contracting officers should ban software development kits known to leak data. These are practical, low-cost steps that fit a conservative focus on discipline, standards, and results.

The next fight: stopping backdoors in the data supply chain

Ad-tech thrives on identity links that survive when one door closes. If an app cannot grab an ad ID, it may try to use Wi‑Fi identifiers, Bluetooth beacons, or device fingerprints. Brokers can also link movement patterns without a single ID by clustering time and location. That is why this fix must be part of a layered plan: block trackers at the device, filter traffic at the network edge, and audit apps before they touch a government phone or laptop.

Congress can tighten the screws further. It can bar federal vendors and contractors from selling or buying location data tied to government facilities. It can fund mobile threat defense tools that flag silent data exfiltration. It can require clear logs so commanders see which apps try to track and when. The Pentagon’s move closes a major gap. The job now is to lock the other doors that ad-tech left open and keep America’s troops off an enemy’s shopping list.

Sources:

taskandpurpose.com, reuters.com