Skip to content
LIVE
The Executives BriefThe Executives BriefBeta

Congress demands answers as US troops' location data still hits the market

Senator Wyden and Rep. Harrigan ask the DoD Inspector General to investigate why commercial location data from military facilities remains available despite new ad-ID controls.

ByKhalid Al-HarbiBusiness Desk, The Executives Brief
·3 min read
Congress demands answers as US troops' location data still hits the market
Executive summary

Senator Ron Wyden (D-OR) and Rep. Pat Harrigan (R-NC) asked the Defense Department Inspector General to investigate why purchased location data can still track US military personnel. The move follows partial adoption of ad-identifier controls across military branches, leaving data brokers and foreign ad-tech firms as a continuing threat.

US troops' location data is still showing up in commercial data sales, and Congress is demanding to know why. Senator Ron Wyden (D-OR) and Representative Pat Harrigan (R-NC) on Friday asked the Defense Department Inspector General to investigate why policies meant to stop the tracking of military personnel have only partially worked.

The request follows a May letter in which Wyden, Harrigan, and a bipartisan group of 12 other members of Congress detailed how commercially purchased location data, often captured by mobile apps and advertising SDKs, can identify where US military personnel gather and target those locations. The lawmakers noted that the DoD has been aware of this threat since at least 2016. They urged Defense Department CIO Kirsten A. Davies to take steps to mitigate the risk, including turning off advertising identifiers on DoD smartphones and issuing a policy requiring the disabling of advertising identifiers on all personal devices brought into DoD facilities or overseas.

Since then, several military branches have blocked advertising identifiers on government-issued devices. According to the new letter, the Army, Air Force, Navy, Marine Corps, and Special Operations Command confirm that they now disable advertising IDs on government-issued devices to protect personnel. But that has not entirely eliminated the availability of location data tied to US military personnel. Citing ongoing reports, Wyden and Harrigan want to know why location data pinpointing the movement of troops continues to be available. "We commend these service branches for implementing this cybersecurity defensive best practice on government devices," they wrote. "However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions."

The two lawmakers speculate about three possible reasons DoD policies have fallen short. One is that some parts of the DoD turned off their advertising identifiers only as recently as July. Another is that disabling ad identifiers may no longer be sufficient to limit the availability of location data. The third is that the location data is coming entirely from the personal devices of DoD personnel and contractors.

Zach Edwards, staff threat researcher at Infoblox, told The Register that it is good to hear all military branches have disabled advertising IDs on their phones because it will make members of the military and their families safer, especially those serving in combat zones overseas. "This change will essentially ensure that military device location data isn't being included in bulk data sales being done by numerous vendors," he said. But he also criticized Google and Apple for not effectively reforming mobile advertising IDs, even after it has been well documented that they are the primary piece of data used by data brokers to connect people's mobile phone location data for bulk sales.

Mobile advertising identifiers, or MAIDs, serve as join keys for tracking people, Edwards explained. They can link different datasets. "So one core benefit is that military data won't be available for sale via data brokers, who will sell to literally anyone with a pulse and a credit card," said Edwards. "But the other slightly less obvious benefit is that this MAID was also being broadcast to all ad systems participating in the auctions." That broadcast matters because ad tech companies in Russia and China have likely been getting MAID data from programmatic ad tech auctions involving members of the military, Edwards said. While states like California, Vermont, Texas, and Oregon have data broker registries, he is unaware of any Russian or Chinese ad tech vendors who have registered. Those companies, he said, partner with Western publishers and mobile apps to collect data anyway. "Companies in those countries have an obligation to share it with the state without any ability to appeal or provide any external notice," he added.

The investigation request is a reminder that the commercial data market does not distinguish between a consumer and a soldier. For executives, the episode underscores how mobile advertising infrastructure can become a national security liability. Boards and chief information security officers should ask whether their own data supply chains are feeding the same brokers and ad auctions that put troops at risk. The DoD's partial fix also shows that device-level controls are not a silver bullet when personal devices and third-party SDKs remain in the picture. The Inspector General's findings could reshape how both government and the private sector approach data minimization, ad identifier policies, and vendor due diligence.

Executive ActionsLocked

This story's Key Insights and Take-aways are locked.

Create a free account to unlock Executive Actions for one credit.

Register to Unlock

Always free for Executives Club members. Join the Club

More in Business