US Military Disables Ad Tracking on Troops’ Devices

The Pentagon turns off advertising IDs on millions of devices to protect service members from location tracking by adversaries.

By Central
The U.S. military disables ad tracking on government-issued devices to prevent hostile states from locating troops.
Highlights
  • The Pentagon disabled advertising identifiers on millions of military devices to block location tracking by foreign adversaries.
  • Senator Ron Wyden pressed the military after reports that hostile states used commercial location data to target U.S. forces.
  • The policy covers iOS, Android, and Windows devices across all major military branches including the Air Force and Army.

The U.S. Department of Defense has disabled advertising tracking on millions of government-issued phones, tablets, and computers used by service members across the Army, Navy, Air Force, Marine Corps, and Special Operations Command. The sweeping security measure, confirmed in a letter shared with Senator Ron Wyden, represents one of the most aggressive moves by any government to sever the link between commercial data markets and military operations. By turning off the unique advertising identifiers embedded in iOS, Android, and Windows devices, the Pentagon is attempting to erase a digital trail that hostile states have weaponized to locate and target American troops on the battlefield and at home stations.

The policy shift comes after years of mounting evidence that the global data broker industry routinely sells location information harvested from ordinary smartphone apps—games, weather tools, fitness trackers, social media platforms—to anyone willing to pay. Senator Wyden, the senior Democrat on the Senate Intelligence Committee and a longtime privacy advocate, had pressed military leaders earlier this year following reports that unnamed foreign adversaries were using commercially obtained location data to target U.S. forces operating in the Middle East. The Pentagon’s response, documented in letters obtained by Reuters and published in full on DocumentCloud, confirms that every major branch of the military has now implemented the change. The Air Force made its move in July 2025, while other branches had already rolled out protections earlier in the year.

The core technical mechanism at play is the advertising identifier, sometimes called an advertising ID or ad tracking ID. On iPhones, it is the Identifier for Advertisers (IDFA); on Android devices, it is the Google Advertising ID (GAID); on Windows, Microsoft uses a similar identifier. These strings of alphanumeric characters are designed to allow app developers and advertising networks to build profiles of users, track their behavior across different apps, and serve targeted advertisements. Crucially, they are intended to persist across installs and resets, making them a powerful tool for linking data points to a single individual or device. When the advertising ID is disabled—either by the user turning off the “Allow Apps to Request to Track” setting or, as the military has done, via enterprise device management policies—the identifier is replaced with a string of zeros. Location data shared by apps, which normally includes the ad ID, then becomes nearly impossible to tie back to a specific person or device. The location data still exists, but it is no longer attributable to an identifiable military phone.

This distinction is critical to understanding the national security threat. When a soldier checks the weather on a military-issued iPhone, the app may request location data to provide a local forecast. That data, combined with the advertising ID, is routinely shared with third-party analytics companies and data brokers. Brokers then aggregate and resell that information on the open market, often in bulk packages that include millions of device records. If an adversary—such as a foreign intelligence service, a terrorist organization, or a state-sponsored hacking group—buys that data, it can identify high-value targets by cross-referencing location clusters near sensitive military facilities, forward operating bases, or convoy routes. The advertising ID functions as the key that unlocks a person’s identity. By disabling that key, the military makes all data emanating from its devices far less valuable for hostile tracking.

The move is not without precedent. In 2018, Vermont became the first state to pass a law cracking down on data brokers, and in subsequent years, multiple federal agencies have acknowledged the dangers of the commercial location data market. But no prior action has been as systematic as the Pentagon’s current directive, which applies to all devices managed across the federal military enterprise network. The scale is enormous: hundreds of thousands of phones, tablets, and laptops used by active-duty personnel, reservists, and civilian employees.

How Ad Tracking Enabled the Targeting of U.S. Forces

The decision to disable tracking on government-issued devices flows directly from a series of investigative reports and Congressional inquiries that exposed a deeply troubling supply chain. Senator Wyden’s earlier letter to military leaders, sent in May 2025, detailed how adversaries had weaponized commercially available location data to target U.S. troops in the Middle East. While the Pentagon has not publicly named the adversaries, national security analysts have long warned that actors such as the Iranian Islamic Revolutionary Guard Corps, Hezbollah, and various proxy militias have the technical capability and financial resources to purchase data from brokers operating in jurisdictions with lax privacy laws.

The mechanism is straightforward. An app on a soldier’s phone collects location coordinates and sends them to an analytics firm. That firm sells the data to a broker. The broker packages it with other data and sells access to a third-party, which could be a foreign intelligence service. If the data includes the advertising ID, the broker can correlate that device with other data points—app usage, Wi-Fi network names, battery level, carrier information—to build a detailed behavioral profile. Over time, the foreign intelligence service can identify that the device regularly appears at a U.S. base in Qatar or a staging area in Kuwait. Once the adversary knows the device is military-affiliated, it can monitor its movements to plan attacks, ambushes, or surveillance operations.

This is not a theoretical risk. In 2020, a widely cited investigation by the investigative journalism outlet The Intercept revealed that a data broker was selling location data from Muslim prayer apps, which could be used to track the movements of military personnel who used the app. More recently, researchers have shown that a single app—such as a flashlight tool or a simple game—can generate enough location data to pinpoint a user’s home address, workplace, and daily commute. For deployed troops, the dangers multiply exponentially.

What is the advertising ID and why does disabling it protect troops?

The advertising ID is a unique, resettable identifier assigned by the operating system to each device for the purpose of ad targeting and measurement. When a user enables “Limit Ad Tracking” on iOS or opts out of ad personalization on Android, the OS returns a string of zeros instead of the real ID. Apps and ad networks can still collect location data, but without a persistent identifier, they cannot link that data to a specific device across multiple apps or over time. For a military adversary attempting to build a profile, the absence of a unique ID means the location data becomes anonymized at scale. The adversary would see thousands of pings from devices in the same area without any way to distinguish which one belongs to a service member. The data still has commercial value for showing aggregate foot traffic patterns, but it loses its intelligence value.

This is exactly what the Pentagon wants. By disabling the advertising ID across its entire fleet of government-issued devices, it ensures that any location data leaked from its systems is disconnected from the individual soldier, sailor, airman, or Marine. The security improvement is enormous, and it comes at zero cost to the military—no new hardware, no software upgrades, just a configuration change managed through existing enterprise mobile device management systems.

Why the Pentagon’s Move Is Both Welcome and Insufficient

Senator Wyden, while commending the military for acting on his concerns, has been careful to point out that the policy only covers government-issued devices. The personal smartphones and laptops that troops and contractors bring onto bases represent a much larger and largely unregulated exposure. Defense Department policy generally restricts the use of personal devices in classified areas, but many troops use personal phones for communication, entertainment, and navigation while off duty. If a soldier brings a personal iPhone onto a base and connects to the base’s unclassified Wi-Fi network, apps on that phone can still collect location data and share it with data brokers. The military has no direct authority to disable advertising IDs on personally owned devices, and any attempt to do so would raise serious privacy and legal concerns.

Furthermore, the Pentagon’s action applies specifically to the advertising identifier, but it does not address other forms of device tracking. For example, cellular networks themselves can triangulate a phone’s location based on signal strength to nearby towers. Wi-Fi fingerprinting—the collection of surrounding Wi-Fi network names and signal strengths—is increasingly used for indoor location tracking. Bluetooth beacons can also reveal a device’s presence. The advertising ID is a powerful and widely used tracking tool, but it is not the only one. Adversaries with sufficient resources can still attempt to track military personnel through network-level surveillance, intercepted communications, or compromised physical infrastructure.

The letter from the military branches to Wyden also underscores a deeper irony: while the Pentagon is protecting its own personnel from commercially available location data, other parts of the U.S. government are actively purchasing and using that same data for domestic surveillance. The U.S. intelligence community and the FBI have both confirmed that they buy location data from commercial brokers without a warrant, arguing that such purchases do not constitute a Fourth Amendment search because the data was voluntarily shared with a third party. In 2024, the National Security Agency acknowledged that it buys Americans’ internet browsing records from data brokers, and in March 2026, Senator Wyden revealed that the FBI under Director Kash Patel was continuing to purchase location data to track U.S. citizens. The Pentagon’s decision to disable ad tracking on troops’ devices implicitly acknowledges that these commercial data markets are fundamentally insecure. Yet the same government that is securing its soldiers from foreign exploitation of those markets is simultaneously funding them to surveil its own citizens.

The Data Broker Industry: A Black Market in Plain Sight

To understand the scale of the problem, one must look at the data broker ecosystem. Companies like Kochava, Near Intelligence, X-Mode (now part of Digital Envoy), and countless smaller firms collect location data from hundreds of millions of devices worldwide. They obtain it through SDKs embedded in apps, through partnerships with telecom carriers, and by scraping public Wi-Fi networks. They then sell access to that data for a wide range of purposes: retail analytics, foot traffic modeling, investment research, and—critically—government surveillance. The market is largely unregulated at the federal level, though states like Vermont, California, and Illinois have passed laws requiring data brokers to register and disclose their practices. At the European level, the General Data Protection Regulation (GDPR) imposes strict limits, but many brokers operate out of jurisdictions with minimal oversight.

What makes location data particularly dangerous for military personnel is its granularity and persistence. A location data point typically includes latitude and longitude coordinates, a timestamp, a device identifier, and sometimes altitude and speed. A single data point is just a dot on a map; a sequence of data points over hours or days creates a detailed movement pattern. Patterns reveal routines, habits, and associations. An adversary monitoring a location data feed will not need to hack the Pentagon’s classified networks—they simply need to buy the data from a broker who collected it from an innocent flashlight app on a soldier’s phone. This is often called “signal intelligence without the signal,” because the data is commercially available, not intercepted.

The targeting reports that prompted Wyden’s investigation were apparently specific enough to convince the Pentagon to act quickly. The fact that the Air Force implemented its changes only in July 2025, months after other branches, suggests a rolling deployment rather than an immediate emergency response. But the existence of a concrete threat, rather than a theoretical vulnerability, was the catalyst.

What This Means for Service Members, Contractors, and the Defense Ecosystem

For the average service member using a government-issued device, the practical effect is minimal. They will still be able to use apps, browse the web, and communicate. They may notice that targeted advertisements become less relevant—a small price for operational security. Behind the scenes, enterprise administrators will have enforced a policy that prevents the device’s advertising ID from being shared. On iPhones, this is typically done through a mobile device management (MDM) profile that forces the “Allow Apps to Request to Track” setting to off. On Android devices, the Google Advertising ID is similarly restricted. On Windows, Microsoft’s advertising ID is disabled via Group Policy or Intune. The changes are transparent to the user.

Contractors, who often work alongside active-duty personnel and may carry both government-issued and personal devices, represent a more complex challenge. The Pentagon’s policy does not cover contractor-owned devices unless those devices are managed by the military’s network. Many contractors use their own phones for work, and those phones remain vulnerable. Senator Wyden has specifically warned that “the personal devices of troops and contractors brought onto military bases could still expose service members and facilities to attacks.” The military cannot force a civilian contractor to disable ad tracking on their personal phone, but it can restrict which devices are allowed to connect to base networks and enforce policies that prohibit location-sharing apps in certain areas. Some bases already require personal phones to be placed in lockers or Faraday pouches while inside sensitive buildings.

The broader defense ecosystem also includes military families, civilian employees, and support staff who live and work on bases. Their devices, too, emit location data that can be correlated with base perimeter data. An adversary could identify a pattern of phones that show up at a base every day, then follow those phones when they leave to identify off-base residences, schools, and shopping habits. This kind of social network analysis, combined with location data, is a standard technique in intelligence tradecraft. Dismantling the advertising ID on military-issued devices removes one easy vector, but it does not solve the problem of personal devices.

The Global Context: A Watershed Moment for Military Data Privacy

The United States is not the first country to recognize the risks. The Netherlands has reportedly warned its military personnel about the dangers of fitness trackers and smartphone apps, and several NATO allies have issued guidance on disabling location services. But the Pentagon’s action is the most sweeping so far, covering the largest military force and the widest array of devices. It sets a precedent that other defense ministries around the world may follow. If the U.S. military—one of the most technologically advanced and well-funded organizations on earth—cannot trust the commercial data ecosystem to protect its people, then no military can. The implicit admission is a devastating indictment of the data broker industry.

It also raises questions about the export of this practice. American defense contractors sell technology to allied nations that often comes bundled with mobile device management capabilities. It is likely that the U.S. government will now require those contractors to include advertising ID disabling as a standard security feature in all systems sold abroad. Similarly, the U.S. State Department and foreign military sales programs may incorporate this as a recommended or required policy for partner nations.

Meanwhile, the clock is ticking on the commercial availability of the very data the military is trying to hide. Data brokers are not going out of business; they are simply losing one stream of highly valuable data. But as long as Americans—including military family members, veterans, and contractors—carry personal smartphones with ad tracking enabled, the data brokers will continue to collect location information that can be exploited. The military can protect its own devices, but it cannot protect the data environment as a whole.

The next logical step, and one that Senator Wyden has already pushed, would be federal legislation to regulate the sale of location data. Bills like the Fourth Amendment Is Not For Sale Act and the Location Privacy Protection Act have been introduced in Congress but have stalled amid industry opposition and jurisdictional disputes. The Pentagon’s action may give new momentum to those efforts. If the department responsible for national security is telling the American people that location data is so dangerous it must be blocked on military phones, it becomes harder for lawmakers to argue that the same data should be freely available for purchase by anyone, including the FBI.

The ultimate irony is that the FBI and intelligence agencies are among the biggest customers of the data broker market. They buy the same data that the Pentagon is trying to suppress. This internal contradiction—a government that simultaneously blocks and buys a dangerous product—cannot persist indefinitely. Either the commercial location data market will be regulated to eliminate the national security threat, or the threat will continue to grow, forcing ever more extreme defensive measures. The Pentagon has chosen a sensible tactical fix. But the deeper strategic problem remains unresolved, and until Congress acts, the data brokers will continue to serve as a vulnerability that adversaries can exploit faster than the military can patch.

For now, the service member who picks up a government iPhone or a Windows laptop can operate with slightly greater confidence that their position is not being broadcast to the highest bidder. That is a meaningful victory in the ongoing battle to protect lives. It is also a reminder that in an era of ubiquitous digital surveillance, the most basic privacy controls are often the most powerful weapons.

Share This Article