US Military Disables Ad Tracking on Troops Phones After Foreign Location Attacks

TL;DR
- The US military is now requiring ad tracking IDs to be disabled on service members' phones after a Senate inquiry confirmed foreign adversaries were buying commercial location data to track troops.
- Intelligence officials say brokers selling precise GPS data from apps and ads created a backdoor for Russia, China, and others to monitor movements around bases in the US and overseas without hacking.
- The move signals a major shift in Pentagon cybersecurity policy, with new device controls, broker restrictions, and bipartisan privacy legislation expected next.
A Wake-Up Call From Capitol Hill
The Pentagon's decision did not come out of nowhere. It followed a direct inquiry from Sen. Ron Wyden, who has spent years warning about the national security risks of the unregulated data broker market.
In a letter to Defense Secretary Pete Hegseth this summer, Wyden asked whether foreign intelligence services were exploiting commercially available smartphone location data to monitor US forces. The Pentagon's written response, later made public by Wyden's office, confirmed the worst fears: yes, adversaries had obtained and used that data.
Within days of that confirmation, Army and Air Force leadership began issuing new guidance to disable advertising tracking across both government-issued and personal devices used by service members. The move marks one of the most aggressive steps the military has taken to cut off the flow of personal data at the source.
For privacy advocates, it was vindication. For military commanders, it was an emergency fix to a vulnerability they had long underestimated.
How Ad Tracking Turned Troops Into Targets
Every iPhone and Android phone has an advertising ID - a unique identifier that lets advertisers track behavior across apps. Even when you are not using GPS navigation, weather apps, games, fitness trackers, and shopping apps constantly ping your location and tie it to that ID.
Data brokers like Gravy Analytics, Venntel, and others vacuum up that information, package billions of location points, and sell access to anyone willing to pay, with little vetting. Until recently, US law enforcement and military agencies were themselves among the buyers.
What Wyden's probe revealed is that foreign adversaries figured out the same trick. Instead of hacking military networks, intelligence services from Russia, China, and other countries could simply buy the same commercial datasets on the open market and filter for devices that regularly slept at US bases, transited through conflict zones, or gathered at sensitive sites.
Officials say this technique was used to identify troop rotations in Eastern Europe, monitor logistics hubs supporting Ukraine, and track personnel movements around bases in the Middle East and the Pacific. In some cases, the data was precise enough to follow individual service members to their homes, bars, and family residences.
The Gravy Analytics Breach That Exposed Everything
The threat became impossible to ignore after the massive hack of location data broker Gravy Analytics in early 2025. Hackers stole terabytes of historical location data covering millions of phones worldwide and posted samples online.
Security researchers who analyzed the leak found location trails leading straight into the Pentagon, Naval Station Norfolk, Ramstein Air Base in Germany, and forward operating sites in the Middle East. Journalists were able to trace movements of military and intelligence personnel with alarming ease.
That breach proved two things: the data was being collected on troops at scale, and it was not secure. If a criminal hacker could steal it, a well-resourced foreign intelligence agency could buy it or steal it just as easily.
Pentagon officials privately acknowledged the leak accelerated internal reviews that culminated in this month's ad-tracking shutdown.
What The Military Is Doing Now
The new Pentagon guidance is simple but sweeping.
On government-furnished devices, advertising IDs will now be disabled by default through mobile device management tools, and apps will be blocked from requesting tracking permission. Location services will be restricted to mission-essential apps only.
For personal devices - which most troops use daily for both work and life - service members are being ordered to turn on Limit Ad Tracking on iPhones and Delete Advertising ID on Androids, reset existing IDs, deny location permissions to non-essential apps, and disable location history.
The Navy has added the steps to cybersecurity training, while the Army included it in pre-deployment checklists. Commanders in high-risk theaters in Poland, South Korea, and the Red Sea region have reportedly issued even stricter rules, including bans on fitness apps, dating apps, and connected car features that leak location.
Crucially, the military is no longer just telling troops to be careful. It is treating ad tech as an active attack surface.
Why Data Brokers Are At The Center Of The Storm
This scandal goes far beyond one phone setting. It has reignited the debate over America's multi-billion-dollar data broker industry, which operates with almost no federal oversight.
Privacy experts say the military's move is an admission that self-regulation has failed. Any app developer can embed a software development kit that harvests location, sell it upstream, and within hours that data can end up in a broker database accessible to foreign cutouts.
Wyden and other lawmakers argue this is a loophole in national security law: the US strictly controls exports of fighter jets and chips, but allows precise, real-time location data on soldiers to be sold globally for pennies.
The Pentagon has now said it supports new restrictions on sales of sensitive location data to high-risk countries and is reviewing its own contracts with brokers. In 2024 the military claimed it stopped purchasing commercial location data for intelligence purposes without a warrant, but the new revelations show adversaries never stopped.
What Comes Next For Military Cybersecurity And Privacy
Disabling ad tracking is a first step, not a fix. Cybersecurity officials say troops remain exposed through connected cars, smartwatches, family members' phones, and foreign-owned apps.
Expect three big shifts in the coming months:
First, Pentagon-wide mobile security reform. The Department of Defense is expected to roll out a unified zero-trust mobile policy, with automated enforcement of privacy settings, approved app lists, and continuous monitoring for location leaks.
Second, legislation. Wyden's bipartisan bill to ban data brokers from selling Americans' sensitive location and health data to foreign adversaries, stalled for years, now has new momentum. House Armed Services Committee members have also proposed banning service members' data from the open market entirely.
Third, pressure on Apple, Google, and app stores. The military wants tech companies to make ad IDs opt-in only and to crack down on location-harvesting SDKs. Privacy advocates say iOS and Android reforms in recent years helped, but brokers adapted by using fingerprinting and other workarounds.
The bottom line is stark: in modern warfare, your phone can betray you faster than any spy. The US military finally acted to turn off one of the brightest beacons - but the data broker economy that lit it up is still running.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!