Adversaries Track U.S. Troops in War Zones With Bought Phone Data

The Pentagon has confirmed adversaries are using purchased commercial location data to target U.S. troops in active war zones. Lawmakers demand immediate fixes including disabling ad IDs and switching browsers. This first official acknowledgment exposes years of inaction on a known threat. The surveillance economy now directly shapes combat risks.
Adversaries Track U.S. Troops in War Zones With Bought Phone Data
Written by Dave Ritchie

The Pentagon has confirmed what privacy advocates and some lawmakers have warned about for years. Foreign adversaries now use commercially bought location data to target American service members deployed in active conflict zones. The revelation marks the first official acknowledgment that such tracking has moved from theoretical risk to documented battlefield reality.

According to a letter from U.S. Central Command shared with Reuters, the command “has received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater.” Sent April 14, the message offered few specifics. Yet its implications landed hard in Washington. Centcom oversees operations across the Middle East, including tense waters near the Strait of Hormuz where U.S. forces face Iranian threats.

So the data that powers targeted ads on phones has become a tool for missile strikes, drone attacks and roadside bombs. Short. Direct. And now confirmed.

A bipartisan group of 14 lawmakers seized on the disclosure. Led by Sen. Ron Wyden, D-Ore., and Rep. Pat Harrigan, R-N.C., a former Army Special Forces officer, they sent a pointed letter to Defense Department Chief Information Officer Kirsten Davies on May 28. They charged that the Pentagon “has not taken basic steps to protect U.S. military personnel from the serious counterintelligence and force protection threat posed by the collection and sale of personal information, including cell phone location data, by data brokers.” The full letter, available via Wyden’s office, lays out the case in stark terms.

“Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes,” the lawmakers wrote. Wyden added in a statement that the time had come to treat the adtech industry as a national security threat. But the frustration runs deeper. DoD has known about these dangers for over a decade. Action has lagged.

Evidence stretches back to 2016. A defense contractor briefed officials at Joint Special Operations Command on how commercial phone location data could reveal troop movements. The contractor demonstrated tracking special operations forces from U.S. bases all the way to a sensitive staging post in Syria. The Wall Street Journal first reported the account in 2021. Similar patterns emerged again in 2024. Journalists from Wired and two German outlets obtained billions of location coordinates from a data broker. They mapped movements around 11 U.S. military and intelligence sites in Germany with striking precision. The story, published by Wired, showed how easily such data exposed patterns of life even off base.

Earlier examples hit closer to home for the military. The fitness app Strava inadvertently revealed base locations and patrol routes in 2017 through its public heat maps. Reports from Defense One at the time called it the opening chapter in a losing war against data leakage. The Pentagon responded with a 2018 directive banning geolocation features in operational areas. Yet implementation has been uneven at best.

Fast forward to the current crisis. USCENTCOM confirmed in responses to Congress that advertising identifiers remain active on many government-issued phones. The unique ad ID assigned by iOS and Android lets data brokers link movements across apps and time. The National Security Agency and Cybersecurity and Infrastructure Security Agency have recommended disabling it. The military only began testing full disablement recently. Location sharing controls rolled out in May 2026 for some devices. Too little. Too late for troops already in theater.

The lawmakers’ letter lists concrete fixes. Disable advertising IDs on all DoD-issued smartphones. Require personnel to do the same on personal devices taken overseas or onto bases. Remove Google Chrome and similar data-hungry browsers from government devices. Replace them with privacy-focused alternatives that include ad blocking and Global Privacy Control. Coordinate with state agencies, such as California’s privacy regulator, to opt service members out of data broker sales. The suggestions draw from existing federal guidance the Pentagon has largely ignored.

Rep. Harrigan put it bluntly. Browsers like Chrome “are built from the ground up to collect and share user data,” he said. Every day they stay on military devices hands adversaries another weapon. Google responded that Chrome offers industry-leading security and that the company has pushed for stronger national privacy rules to rein in data brokers.

Data flows through a messy web. Apps collect location from phones. They sell it to brokers who aggregate, resell and repackage the information, sometimes through chains of intermediaries. Buyers include advertisers. But also governments and private intelligence firms. Prices can be nominal. One broker offered billions of data points for free to journalists. Adversaries need not hack phones. They simply purchase the data on the open market.

This trade has drawn scrutiny before. In 2021, Vice’s Motherboard revealed the Defense Intelligence Agency bought domestic location data without warrants. The Pentagon itself has purchased such information from brokers, including data tied to Muslim prayer and dating apps. Officials told the Wall Street Journal they had policies to balance operational needs with protection. Those policies, marked as controlled unclassified information, failed to prevent the current threats according to the congressional letter.

And the risks extend beyond immediate targeting. Pattern-of-life analysis lets enemies map routines, identify leaders, detect shifts in force posture. Counterintelligence operatives can spot potential recruits or sources. The data reveals who visits certain buildings at odd hours. Who travels together. Who sleeps where. In a hot conflict zone, that knowledge translates into lethal advantage.

Lawmakers pressed for answers by June 26. Among their questions: Does DoD require vendors to bar collection or sale of data from personnel? What happened to recommendations in a 2025 Army Cyber Institute report titled “Tracking The Trackers”? How has the department used authorities under the 2017 National Defense Authorization Act to protect high-risk personnel? The letter also asks whether funding continues for research at the Digital Force Protection Lab at West Point and the Threat Systems Management Office at Redstone Arsenal.

The Pentagon told Reuters it would reply directly to the lawmakers. No public response has emerged since the May 28 letter. Meanwhile, the threat reports continue to flow through Centcom’s Threat Fusion Cell. Assessments have gone out to force protection teams. Command policy letter 25-10 sets escalating restrictions tied to force protection condition levels. FPCON Delta measures went into effect in late February. Yet the underlying data economy remains untouched.

Other recent coverage adds weight. Nextgov detailed the bipartisan push and the slow rollout of even basic controls. Stars and Stripes reported the first confirmation of targeting in an active war zone and lawmakers’ demands for stronger safeguards. The story has rippled across defense circles. Discussions on X in recent days have mixed alarm with familiar calls for faster policy shifts and criticism of delayed action.

But fixes exist. They are not complex. Disabling an ad ID takes minutes on most devices. Group policy can enforce it at scale. Privacy browsers are available today. States have created deletion portals that could cover thousands of service members. The military simply needs to treat commercial surveillance with the urgency it reserves for traditional signals intelligence threats.

Until then, every smartphone carried into theater doubles as a potential beacon. Adversaries don’t need sophisticated malware. They buy the data. And U.S. troops pay the price in operational security. The battlefield has changed. The Pentagon’s policies have not kept pace.

Subscribe for Updates

InfoSecPro Newsletter

News and updates in information security.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us