The United States military, operator of the most expensive war machine in human history, has only recently gotten around to disabling the same advertising trackers that every halfway-decent IT department has been warning about for years. According to letters released Friday by Senator Ron Wyden and statements given to Reuters, commercially available location data sold by the ad industry has been used to track and target American troops deployed to the Middle East. The Army's mobile devices only had ad tracking disabled by default starting in February 2026. The enemy, apparently, did not wait for that update.

What Exactly Is Going On Here

Mobile advertising IDs, known as MAIDs, are unique identifiers baked into your phone that follow you across apps and log your physical location. Every time a soldier with an unprotected device opened a random app in or near a base in the Middle East, that location data was potentially entering a commercial pipeline that anyone with a credit card could access. We are not talking about classified intelligence. We are talking about the same data ecosystem that decides which sneaker ads to show you.

Data brokers, companies that hoover up personal information and resell it to paying customers, have made this kind of tracking banal and cheap. Representative Pat Harrigan, a North Carolina Republican, put it plainly in a letter to the Pentagon on Friday: US enemies "should not be able to pull out a credit card and buy information that helps them track American troops." Hard to argue with that. Somehow it still needed to be said in 2026.

The Guardian and Reuters both report that in July, some deployed personnel in the Middle East were told they might have to surrender their phones entirely after military officials concluded that soldiers posting mobile videos to the internet were helping Iran identify and target American bases. The phones were not hacked. The phones were just doing exactly what phones do.

The Timeline Is Not Flattering

Here is what Wyden's letters reveal about when each branch actually got around to fixing this. The Air Force disabled advertising identifiers on computers and mobile phones two months ago. Special Operations Command said it had "recently" disabled them on Windows devices, which is the kind of precise, confidence-inspiring language you want from an elite fighting force. The Army told Reuters that ad IDs tied to mobile devices had been disabled since earlier this year.

The Army also clarified in a statement that advertising IDs had been blocked on Windows computers "since before 2021," but that Android and Apple mobile devices only had tracking disabled by default "since at least February 2026." So the desktop version of this problem got addressed half a decade ago. The pocket-sized computer that every deployed service member carries everywhere took until this year. The Navy did not return messages seeking comment, which tracks.

Wyden, an Oregon Democrat who has been pushing the Pentagon on this for months, said in a statement that the military's efforts "have not been effective at neutralizing this threat." That is a senator being diplomatic. What the timeline actually shows is a bureaucratic shrug toward a known, documented, commercially-exploitable vulnerability affecting people in active war zones.

The Part Where Disabling the Tracker Doesn't Fully Fix It

If you were hoping the story ended with "and then they turned off the trackers and everything was fine," hold on. Zach Edwards, co-founder of the privacy ad tech company Decryptads, told The Guardian that disabling MAIDs is "definitely a positive thing" and will stop location data from being swept up in bulk data sales. But he also cautioned that personnel could still be tracked through apps in other ways, for example by triangulating technical device details with network data or location information.

In other words, the advertising industry has built a surveillance infrastructure so thorough and redundant that turning off one identifier is necessary but not sufficient. The pipes run in multiple directions. The data finds a way out. This is the system that runs quietly underneath every free app, every mobile game, every weather widget on every phone in every pocket of every person including, as it turns out, soldiers deployed to places where people are actively trying to kill them.

What Happens Next

Wyden and Harrigan sent a joint letter to the Pentagon on Friday requesting an investigation into whether the military has properly countered the dangers of the commercial location data trade. The Pentagon responded by email saying it would respond to the lawmakers directly, which means precisely nothing yet.

This is not the first time Wyden has had to drag the national security establishment toward taking data privacy seriously, and it almost certainly will not be the last. The senator has spent years flagging the ways the commercial data broker industry creates risks that look nothing like traditional espionage but function exactly like it. No hack required. No mole required. Just a subscription.

The Dingo Take

You are supposed to believe that the most technologically sophisticated military on earth, the one with stealth bombers and satellite constellations and a budget that exceeds the GDP of most countries, was until very recently leaving its deployed personnel exposed to a threat that privacy researchers have been shouting about in public for years. Not a sophisticated zero-day exploit. Not a state-sponsored cyberattack requiring nation-state resources. A data broker. The kind of company that also sells your purchasing habits to insurance companies and your political preferences to campaigns.

The ad tech industry built a global tracking apparatus so normalized and so deeply embedded in how the internet works that even the US military forgot to opt out. Or did not bother. Or decided it was someone else's problem until Reuters started reporting that Iranian forces might be using Foursquare-adjacent data to figure out where to point rockets. At some point the line between "we failed to anticipate this" and "we knew and did not care enough to act" gets uncomfortably thin.

Wyden's been waving this flag for years. The Pentagon has been sending polite non-responses. Meanwhile the data kept flowing, the brokers kept selling, and whoever wanted to know where American troops were sleeping could apparently just pay for the information like they were buying a mailing list. The trackers are off now, mostly, on some devices, probably. Sleep tight.

Sources