For years, a smartphone's advertising identifier has been presented as a detail of the app economy: a technical string that allows advertisers to recognize a device, measure campaigns, and build profiles. The United States Department of Defense, however, is treating it as an operational security issue. The Army, Air Force, Navy, Marine Corps, and Special Operations Command have disabled ad tracking on government devices — iPhones, Android phones, and Windows computers — following warnings about the use of commercial location data to track military personnel.

The move, revealed in letters shared with Senator Ron Wyden and reported by Reuters and TechCrunch, comes after U.S. Central Command acknowledged that hostile actors have used commercially purchased location data to surveil U.S. service members in the Middle East. It is not a vulnerability in the traditional sense: no one necessarily needs to hack a phone, install malware, or bypass a password. The data originates from ordinary apps, passes through ad systems and brokers, and can be bought on the open market.

When ad targeting becomes intelligence

The mechanics of the ad-tech ecosystem generate an enormous volume of signals. Apps integrating advertising SDKs can collect identifiers, IP addresses, device information, and, when permitted, location data. These data points are aggregated, shared, and resold. Individually, they may seem insignificant; observed over time, they can reveal where a person sleeps, where they work, which bases they frequent, and which other devices they travel with.

To an advertiser, it is segmentation. To an intelligence service, it can become a map. A cluster of devices that regularly appears inside a military facility and then moves to another area can reveal sensitive patterns without needing to immediately know the owners' names. If a persistent identifier is tied to that cluster, the correlation work becomes even simpler.

The Pentagon addresses the most immediate layer

Disabling the advertising ID does not eliminate data collection, but it reduces one of the primary elements used to link different observations to the same device. The armed forces applied the change to federally managed devices. According to the cited communications, some branches had already begun implementation in previous months, and the Air Force completed further modifications in July.

It is a relatively simple measure compared to other cybersecurity interventions, and for this very reason, it shows how evident the problem had become. Military organizations spend billions on encryption, secure networks, and classified systems; yet part of personnel's locations could be inferred through commercial infrastructure built to sell advertising.

The problem of personal devices remains open

Wyden welcomed the decision but pointed out a substantial limitation: the personal phones of military personnel and contractors are not controlled in the same way. A private device brought onto a base can continue to generate data through applications, brokers, and commercial services. Even if the government phone is configured correctly, the presence of other devices in the same location can piece together part of the picture.

This is why the issue cannot be resolved merely by changing a setting. Rules governing the collection and sale of location data, limits on brokers, and operational procedures in sensitive areas are needed. In some extreme contexts, the solution can be physical: not bringing certain devices to places where their mere presence creates information.

A contradiction for the American government itself

The affair contains a significant institutional contradiction. While the Dipartimento della Difesa acknowledges the risk stemming from the commercial data market, intelligence agencies and the FBI have confirmed in the past that they purchase information originating from the same ecosystem for investigative or intelligence activities. For years, the ability to buy data that would be harder to obtain through traditional tools has created a gray area between the private market and public surveillance.

This makes the debate more complex than a simple standoff between “government” and “advertising”. The same market can be useful to an American agency and dangerous when exploited by an adversary. Once data is commercially available, however, it is difficult to ensure that only intended actors can acquire it.

Modern security also depends on app business models

The lesson is also important for enterprises and civilian infrastructure. An organization can secure servers and accounts yet continue to leak information through its employees' devices. Managers, engineers, officials, or data center staff can generate patterns useful to anyone seeking to understand shifts, movements, and relationships.

This does not mean that every piece of advertising data is a military threat. It means that the distinction between “harmless data” and “sensitive data” depends on context. An isolated coordinate is worth little; millions of coordinates linked over time can map out a routine with surprising precision.

Apple and Google have curtailed tracking, but the market has not disappeared

In recent years, mobile operating systems have introduced stricter controls on advertising identifiers and location permissions. Apple made cross-app tracking subject to explicit consent, while Android has progressively restricted various forms of identification. However, the market has developed alternative attribution and correlation methods, and countless applications continue to collect data legitimately once a user grants permission.

Because of this, the Pentagon's decision is defense in depth, not a definitive solution. It reduces a risk surface, but it cannot neutralize every identification technique. Security requires combining device configuration, app control, personnel training, and upstream market rules.

Commercial data has become strategic infrastructure

The most important shift is cultural. The United States is recognizing that the data economy does not only create individual privacy issues. It can produce national security consequences. If a foreign government can legally purchase information that makes it possible to track military personnel, the traditional line between a cyberattack and a commercial purchase loses its meaning.

From this perspective, turning off advertising identifiers on government devices is almost the easiest step. The hard part will be deciding whether and how to rein in an industry where the very same information is sold to advertisers, analysts, investigators, and brokers who can, in turn, resell it. The Pentagon has reduced the exposure of its phones. The bigger policy issue is understanding why such sensitive information was available for purchase in the first place.

Sources