At least four U.S. military organizations have disabled advertising identifiers on government devices after Central Command received multiple reports that adversaries used commercial location data to target or surveil personnel in the Middle East. The Army, Navy, Air Force and U.S. Special Operations Command described their countermeasures Friday, according to Reuters. The changes close one route into the advertising ecosystem but leave trails created by apps, personal phones and network signals.

The Air Force said it switched off advertising identifiers on computers and mobile phones about two months ago. Special Operations Command recently did so on Windows devices. The Army said its Windows block predates 2021, while managed Apple and Android devices had identifiers disabled by default since at least February 2026. The Navy said its secure application environment disables them on government equipment but did not specify when that safeguard began.

The disclosures mark a shift from hypothetical exposure to reported battlefield use. In April, Central Command told Congress it had received “multiple threat reports” about adversaries exploiting commercial location information during Operation Epic Fury. A bipartisan group of 14 lawmakers said a consumer-data market had become a force-protection problem. Their warning described data capable of revealing where troops gather and how they move.

How an advertising tool becomes targeting data

A mobile advertising identifier is a resettable string that lets apps and advertising companies recognize a device without displaying its owner’s name. Combined with coordinates and timestamps gathered by apps or advertising exchanges, it can become a persistent movement map. A buyer observing the same device at a barracks, operations center and residence may infer its owner and workplace. Aggregating devices can expose shift changes, entry points and unusual deployments.

The scale is not theoretical. A joint investigation by WIRED and German outlets examined 3.6 billion coordinates associated with up to 11 million advertising identifiers over 59 days. Reporters found data from as many as 12,313 devices near 11 military and intelligence locations in Germany. The Grafenwöhr training area alone produced more than 191,000 signals linked to up to 1,257 devices, illustrating how bulk points disclose routines.

Turning off an identifier limits links across the advertising supply chain, but it controls one signal rather than making a device invisible. Apps may collect location through operating-system permissions, and brokers can combine network addresses, device characteristics and account information. Personal phones may sit outside managed settings. Privacy technologist Zach Edwards said the action should limit inclusion in bulk data sales, while more complex correlation and triangulation remain possible.

Policies existed before the latest threat reports

The Pentagon has warned about mobile risk for years. Its 2023 mobile policy says apps can jeopardize missions without a user’s knowledge. It restricts geolocation-capable apps in operational areas, permits managed systems to enforce controls and directs components to deploy mobile-threat defenses. Yet the framework focuses on government information and applications, while advertising identifiers create metadata that appears mundane until purchased and analyzed at scale.

Federal auditors identified the same structural gap. The Government Accountability Office found that public, stolen and brokered data can form profiles threatening military operations and personnel. Its assessment said the Defense Department had not established department-wide responsibility for managing that exposure or a comprehensive process for measuring risk. Disabling identifiers shows action but does not answer the governance problem the auditors described.

The services moved on different timelines and described different device classes. Windows controls did not necessarily cover managed mobile operating systems; a secure container does not govern every personal handset. The disclosures do not establish whether one baseline applies across the force. They also leave unanswered whether restrictions were technically verified, whether older identifiers remain in broker archives and whether personnel receive consistent instructions before deployment.

Commanders have considered stricter measures. In July, Central Command’s chief warned that troop photos and videos could help Iran assess strikes in near real time. Some personnel in Jordan were told phones might be confiscated, sources told Reuters. Visible content differs from hidden metadata, but both expose the tension between useful communications and information that can shorten an adversary’s targeting cycle.

Regulators have treated military locations as sensitive

Civilian regulators have already documented how location information escapes its original commercial purpose. In a 2024 case, the Federal Trade Commission alleged that Mobilewalla collected data from real-time advertising auctions and used it for purposes beyond placing ads. The resulting order prohibited selling or using sensitive location data associated with military installations, health clinics, religious organizations and other protected places. The case demonstrated that the risk can originate within ordinary advertising infrastructure, not only with specialist surveillance vendors.

In May 2026, the FTC announced a proposed settlement barring Kochava and a subsidiary from selling sensitive location information without affirmative consent. The agency said the company’s data covered hundreds of millions of devices and could trace individual movements. That settlement strengthened safeguards at one broker, but enforcement actions operate company by company. They cannot guarantee that an identifier already circulating through intermediaries has disappeared or that every seller recognizes a military site as sensitive.

The Justice Department’s Data Security Program provides a national-security backstop. Effective since April 2025, it restricts transactions giving countries of concern access to bulk sensitive or government-related information. The rule covers precise geolocation and treats specified government locations differently from ordinary bulk thresholds. The Central Command reports still show how buyers, resellers and collection paths can cross borders without an obvious handoff to a named foreign government.

What the new safeguard does not cover

The immediate priority is verifying every managed endpoint. Centralized tools can disable identifiers, restrict app permissions and flag noncompliant configurations, but effectiveness depends on inventory accuracy. The department must know which phones, tablets and computers are in use, including contractor devices or approved personal-device partitions. A default setting can be defeated by legacy hardware, software updates or local exceptions unless administrators continuously test it.

Personal devices are the larger unresolved exposure. A service member can switch off personalized advertising, review application permissions and avoid posting from an operational location, but individual discipline cannot substitute for institutional controls. Family members, civilian workers and contractors may generate overlapping patterns around the same installation. A determined analyst does not need to identify every phone; changes in the volume and timing of signals near a base can indicate deployments even when individual identifiers are difficult to attribute.

The test is whether targeting becomes harder

The Pentagon inspector general now has a clear question: whether years of warnings became controls before reported adversary use, and whether the settings reduce exposure. Evidence should include configuration logs, compliance rates, red-team attempts to reconstruct troop movements and the time from threat report to defensive change. The review should distinguish official equipment from personal devices, because success on a managed handset can coexist with vulnerability around it.

Congress faces a parallel choice over the commercial market. Targeted rules and enforcement have restricted sales around some sensitive places and to certain foreign adversaries, but the underlying economy still rewards collecting precise behavioral data. A comprehensive answer would require clearer limits on collection, retention and resale, alongside penalties that follow data through intermediaries. Without that, the military may keep hardening devices while adversaries search for the next unprotected signal from apps, vehicles, wearables or relatives.

Disabling advertising identifiers is a practical and overdue step because it removes a widely used handle from government equipment. It is also an admission that consumer tracking technology has entered the battlespace. The lasting measure of success will not be how many settings were changed, but whether hostile buyers can still purchase enough commercial data to map American personnel, predict their routines or refine an attack. On that standard, Friday’s disclosures mark the beginning of a force-protection program, not its completion.