US Military Location Data Still Leaking Despite Ad ID Ban, Lawmakers Demand Probe

Senator Wyden and Representative Harrigan ask DoD Inspector General to investigate why purchased location data continues to expose troop movements

edit
By LineZotpaper
Published
Read Time2 min
A bipartisan pair of lawmakers has asked the Pentagon's watchdog to investigate why commercially purchased location data still exposes US military personnel to tracking and targeting, despite efforts by all service branches to disable advertising identifiers on government-issued devices.

Senator Ron Wyden (D-OR) and Representative Pat Harrigan (R-NC) have called on the Defense Department Inspector General to investigate why policies meant to stop the flow of location data from US military personnel have not fully succeeded. In a letter sent Friday, the lawmakers said that while all branches of the military have now disabled advertising IDs on government-issued devices, ongoing reports indicate that location data pinpointing troops' movements remains available for purchase.

In May, Wyden, Harrigan, and a bipartisan group of 12 other members of Congress warned that commercially purchased location data—often captured by mobile apps and advertising SDKs—can be used to identify where US military personnel gather and to target those locations. The DoD has been aware of the threat since at least 2016.

According to the letter, the Army, Air Force, Navy, Marine Corps, and Special Operations Command have all confirmed they now disable advertising identifiers on government-issued devices. "We commend these service branches for implementing this cybersecurity defensive best practice on government devices," the lawmakers wrote. "However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions."

The letter speculates about three possible explanations for the policy's failure: some parts of the DoD may have only turned off their advertising identifiers as recently as July; disabling ad identifiers may no longer be sufficient to limit location data availability; or the location data is coming entirely from personal devices of DoD personnel and contractors.

Zach Edwards, staff threat researcher at Infoblox, told The Register that disabling advertising IDs is a positive step that will make service members and their families safer. He noted that mobile advertising identifiers (MAIDs) serve as join keys for tracking people across datasets. "This change will essentially ensure that military device location data isn't being included in bulk data sales being done by numerous vendors," Edwards said. He added that while states like California, Vermont, Texas, and Oregon have data broker registries, he is unaware of any Russian or Chinese ad tech vendors who have registered, and those companies partner with Western publishers and mobile apps to collect data anyway.

§

Analysis

Why This Matters

  • The continued availability of location data on US military personnel creates a direct operational security risk, potentially allowing adversaries to track troop movements and target bases or personnel overseas.
  • The failure of self-regulatory measures like disabling advertising IDs raises questions about whether stronger government action is needed to control the commercial data broker industry.
  • The investigation could lead to new policies governing personal devices of military personnel and contractors, affecting millions of Americans working with the DoD.

Background

The US military has known since at least 2016 that commercially purchased location data from mobile apps and advertising networks could be used to track and target service members. In May 2026, a bipartisan group of lawmakers pressed the DoD to take action, including turning off advertising identifiers on government phones and issuing policies for personal devices in DoD facilities. All service branches have since implemented ad ID bans on government-issued devices, but the data continues to be available, suggesting personal devices or other mechanisms are still leaking location information.

Key Perspectives

[Lawmakers (Wyden, Harrigan, and bipartisan group)]: Believe the DoD has not gone far enough and needs an inspector general investigation to identify the gap. They suggest personal devices of personnel and contractors may be the source. [DoD Service Branches]: Have complied with the request to disable advertising IDs on government-issued devices but have not fully stopped location data leakage. [Privacy and Security Researchers (like Infoblox's Zach Edwards)]: Welcome the change as a necessary step but argue that Apple and Google have not done enough to reform mobile advertising identifiers, which remain the primary tool for data brokers to link and sell location data.

What to Watch

  • The DoD Inspector General's decision on whether to launch the investigation and its scope.
  • Whether the DoD extends policies to personal devices of personnel and contractors, as the lawmakers have urged.
  • Potential action by Apple and Google to further limit the use of advertising identifiers as join keys for location data.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.