Every modern smartphone carries a pseudo-anonymous serial number for advertisers. That is essentially what a Mobile Advertising ID (MAID) is—a resettable identifier assigned by Android or iOS that ties app activity, behavior, and location into one tidy device profile. Every time an app serves an ad, that ID and approximate coordinates travel through a chain of exchanges and data brokers. Foreign buyers—including actors reportedly linked to Iran—legally purchased this data to track U.S. devices in Iraqi Kurdistan. No hacking required. Just a credit card and a broker account. Governments have also deployed a surveillance app for similarly targeted monitoring operations.
U.S. Central Command confirmed it had “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater.” That statement marked the first official acknowledgment that the surveillance economy behind targeted advertising was being used to help plot missile and drone strikes against American forces.
Branch by Branch: What the Military Actually Changed
Each service branch moved on its own timeline after CENTCOM confirmed the threat—and the gaps between them are telling.
- Air Force disabled advertising identifiers on computers and phones roughly two months before the September 2026 disclosures
- SOCOM said it had “recently” disabled advertising IDs on Windows devices
- Army blocked IDs on Windows computers since before 2021; Android and Apple devices followed by at least February 2026. Personnel are also advised to avoid public USB charger stations, which carry their own device-security risks
- Army and Navy both confirmed disabling IDs to Senator Ron Wyden (D-Ore.), though neither offered clear timelines
- The Pentagon said it would respond to Wyden and Representative Pat Harrigan (R-N.C.) directly, without further elaboration
“Should not be able to pull out a credit card and buy information that helps them track American troops.” — Representative Pat Harrigan (R-N.C.), as reported by Reuters
Turning Off the Tracker Is a Start. The Data Market Is Still Open.
Disabling ad identifiers closes one door, but the underlying data broker market and alternative tracking methods remain largely intact.
Armed with years of NSA and CISA guidance to disable MAIDs, the DoD still managed to disable only personalized ad settings—leaving the underlying advertising IDs transmitting in the background. That distinction, reportedly, cost real time and real safety. Deployed personnel in the Middle East were reportedly ordered to surrender personal phones after videos posted online helped adversaries triangulate base locations—the modern equivalent of accidentally leaving a marked map on a café table, except the café is TikTok and the map updates in real time.
Wyden and Harrigan’s May 28 letter to Pentagon CIO Kirsten Davies pushed three demands:
- Disable MAIDs on military phones
- Replace Google Chrome with privacy-protective browsers
- Enroll service members in data-broker opt-out programs
Privacy expert Zach Edwards called disabling MAIDs “definitely a positive thing” but cautioned that troops can still be secretly tracking users through app correlations and network metadata. Commercial location data, according to Senator Wyden, “can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes”—a threat compounded by the fact that Iran-linked hackers are simultaneously escalating digital attacks on critical infrastructure.
The fix on military devices is underway. The data broker market that made it possible, however, remains open for business—and the same infrastructure powering personalized ads on any given smartphone is still selling to whoever can afford a subscription.





























