Adversaries have used commercially available location data to target American forces in active combat areas. The confirmation came in an April 14 letter from US Central Command. It marks the first official Pentagon acknowledgment of this specific threat in a live theater.
Senator Ron Wyden shared the document with reporters. The Oregon Democrat, joined by a bipartisan group of lawmakers, sent a pointed letter to Pentagon officials on May 28. They demanded answers. They highlighted years of ignored warnings.
“Commercial location data can be used to identify where US troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes,” the Centcom letter stated, according to Reuters.
Short. Direct. And alarming.
The reports arrived through standard threat channels. Centcom used them to refine force protection steps across its area, which stretches from the Middle East to Central Asia. Personal phones remain permitted for troops in these zones. Guidance exists on disabling location services. Yet that guidance carries a caveat. Disabling geolocation does not always eliminate the flow of data from commercial products. Users must dig through privacy settings. They must layer additional safeguards. Even then gaps persist.
Government-issued devices fare somewhat better. The Pentagon’s Defense Information Systems Agency configures them to block mobile advertising identifiers. Still, some residual data slips through. Officials now work to remove user-editable options entirely. Progress feels slow against a threat that has been visible for years.
Lawmakers expressed sharp frustration in their correspondence. “DoD has known about this serious threat for over a decade, but has failed to adopt commonsense cyber defenses,” they wrote. The group, which includes former Army Special Forces officer Rep. Pat Harrigan, pressed for concrete measures. Disable ad IDs on all military devices. Turn off location sharing automatically in forward areas. Shift away from browsers like Chrome that harvest data by design.
Harrigan pulled no punches. Browsers like Chrome “are built from the ground up to collect and share user data,” he said. Every day such tools stay on government devices hands adversaries another weapon.
Google pushed back. Chrome offers “industry leading security,” the company told Reuters. It has long called for national privacy legislation to constrain data brokers.
The adtech machinery runs on a simple transaction. Apps and websites collect location signals from phones. They feed that information into vast marketplaces. Data brokers aggregate, clean, and resell it. Buyers range from marketers to, apparently, foreign intelligence services. The entire chain operates legally in most cases. Anonymization claims crumble under scrutiny. Patterns reveal individuals. Patterns reveal units.
This vulnerability is not new. In 2016 a US defense contractor spotted special operations forces movements by sifting commercial data. Phones left US bases, traveled through transit countries, and clustered at a derelict Syrian factory used as a staging point. The Wall Street Journal first detailed the episode. Analysts could reconstruct operations without access to classified networks.
More recent probes delivered similar shocks. In 2024, WIRED, Bayerischer Rundfunk, and Netzpolitik.org analyzed billions of location points from a single broker. They mapped precise movements of US military and intelligence personnel across German bases, including sites believed to house nuclear weapons. The reporting laid bare how cheaply and easily outsiders could track American forces abroad. (WIRED)
Fitness apps provided an even earlier warning. Strava’s 2018 global heatmap exposed patrol routes and base perimeters in conflict zones because soldiers used the service during routine exercise. The Guardian covered the lapse. Nathan Ruser, an analyst, called out the obvious operational security failure. Bases stood out in bright relief against empty desert.
But the problem runs deeper than fitness trackers or careless social posts. Everyday phone behavior generates streams of coordinates. Apps request permissions. Many users grant them without thought. Advertising IDs tie data together across apps. Brokers buy in bulk. The resulting datasets expose routines, meeting points, and anomalies that signal military activity.
The Persistent Gap Between Knowledge and Action
Military leaders have sounded alarms for some time. Gen. Eric Smith, commandant of the Marine Corps, released a stark video in early 2025. A Marine escapes enemy contact, ducks into an abandoned structure, and texts his location for help. The message is intercepted. Reinforcements arrive only to face a strike that kills several. “Our adversaries are always watching, waiting to exploit any mistake,” the accompanying post read. “Every text, post, and interaction can place your unit at risk.”
Smith returned to the theme later. “The character of war continues to change. The proliferation of technology has made signature management essential on the battlefield.” Another general put it more bluntly at a Washington event: your cellphone gets you killed.
Ukraine offers a live case study. Russian forces have repeatedly located Ukrainian units through cellphone signals, social media, and commercial data. Kyiv has struck back using similar methods against Russian positions. Moscow responded with bans on personal phones near the front. Compliance remains uneven. The pattern repeats. Convenience collides with survival.
Centcom’s admission arrives at a moment of heightened tension in its theater. US forces monitor Iranian activity around the Strait of Hormuz. Any edge given to adversaries through open data streams carries immediate consequences. Missiles, drones, roadside bombs. The letter listed them plainly.
Lawmakers want faster movement. They argue the Defense Department possesses the technical means. It could enforce stricter device configurations. It could restrict app stores on forward devices. It could train personnel relentlessly on digital hygiene. Yet bureaucratic inertia persists. Personal phones stay in pockets. Data keeps flowing.
The surveillance economy shows no signs of shrinking. Revenue from targeted advertising underwrites much of the internet. Location remains among the most valuable signals. Regulators have begun to scrutinize brokers, but national security implications lag behind privacy concerns. Wyden made the connection explicit. It is time to treat the adtech industry as a national security threat.
Cheap fixes exist. The NSA has advised for years that users disable location services when possible, grant minimal permissions, and understand residual risks. Military guidance echoes these steps. Implementation at scale proves harder. Troops need communication. Families expect contact. Operational necessity meets personal habit.
So the data trade continues. Brokers sell. Adversaries buy. Patterns emerge on screens half a world away. A cluster of phones at an unremarkable building. Repeated movements along a supply route. Sudden gatherings at odd hours. Each signal feeds targeting decisions.
Pentagon officials said they would reply directly to the lawmakers. Details remain scarce. The threat reports stay classified. Yet the public record now contains an uncomfortable truth. Commercial data, gathered for ads, now shapes battlefield calculus. American forces stand exposed not by enemy spies in the wire but by the phones in their pockets.
And the fixes, though known, remain only partially applied. That gap invites further incidents. It invites further letters. It invites harder questions about whether the military can truly insulate its people from a data economy that never sleeps.


WebProNews is an iEntry Publication