• CENTCOM confirms adversaries exploited commercial location data to target U.S. forces, prompting new controls.
  • Advertising IDs on DoD-issued smartphones remain enabled, with DISA testing a fix.
  • Lawmakers press for broader restrictions on personal devices and data brokers.

A Shift from Warnings to Action

The U.S. military has started disabling advertising identifiers on many phones and computers, responding to confirmed threat reports that commercial location data was used to surveil or target American troops in the Middle East. In an April 14 response to Congress, U.S. Central Command (CENTCOM) acknowledged receiving “multiple threat reports” of adversaries exploiting such data during Operation Epic Fury—the first official DoD confirmation that commercial data was being weaponized against U.S. forces in an active conflict.

By May, CENTCOM gained administrative power to disable location sharing on smartphones it manages. However, the advertising ID—a device-level identifier used across the ad-tech ecosystem—was still not disabled on DoD-issued devices. The Defense Information Systems Agency is testing a capability to do that, but time is of the essence.

The Risk Remains Incomplete

Even as controls tightened, gaps persist. In August, reporters found publicly viewable Strava activity at several Middle East military locations, despite stricter rules. That information can reveal routines, exercise sites, and personnel concentrations—data that could be exploited. The exposure isn't limited to GPS; apps, identifiers, Wi-Fi signals, and IP addresses all contribute to a potential surveillance picture.

A Dec. 4, 2025 policy directed personnel to disable unnecessary geolocation functions and limit public sharing, with restrictions raised to the highest level ahead of the Feb. 28 Iran-war escalation. But enforcement is tough, especially on personal devices.

“The remaining exposure is not limited to phones’ location switches,” said a defense official familiar with the matter, speaking on condition of anonymity. “We can't control every app or every wearable, but we're trying.”

Broader Industry Implications

This isn't just a Pentagon problem. Apple (AAPL) and Google (GOOG) assign advertising identifiers that enable cross-app tracking—pressure may grow for enterprise-friendly defaults. Ad-tech firms and data brokers face national-security scrutiny that could reduce data supply and raise compliance costs. Fitness apps like Strava are under renewed pressure to protect sensitive locations.

Economically, the episode highlights how cheap commercial data can substitute for expensive intelligence collection. The Justice Department’s Data Security Program restricts access to bulk sensitive U.S. personal data by countries of concern, but precise geolocation data linked to government sites is particularly sensitive. Expect more aggressive enforcement and reduced monetization of location data.

“We're seeing a shift where data that was once a commercial asset is now viewed as national-security infrastructure,” said a data-broker industry analyst. That's leading to increased spending on privacy-preserving enterprise tech, like mobile-device management and anti-tracking browsers.

Political and International Context

Congressional concern is bipartisan. Sens. Ron Wyden and Martin Heinrich and Rep. Pat Harrigan have pressed the DoD chief information officer to disable advertising IDs on official smartphones and require personnel to disable them on personal devices taken onto facilities or deployments. They've also called for replacing tracking-oriented browsers with privacy-focused alternatives.

Internationally, this is tied to force protection in the Middle East and the Iran conflict. Commercial data lets adversaries conduct surveillance without hacking or satellite assets—lowering the barrier to intelligence collection. The broader federal policy includes the DOJ Data Security Program, launched to restrict certain data transactions with countries of concern.

“The fundamental security lesson is that a phone needn't be hacked to create risk,” said a former intelligence officer. “If an adversary can buy enough location-linked records, the line between consumer tracking and espionage collapses.”

Historical Echoes

The problem isn't new. In 2016, a contractor showed JSOC officials how commercial phone-location data could track devices from special-ops bases. In 2018, Strava's heat map exposed military installations, prompting restrictions. More recently, journalists used a free broker sample to identify devices near German bases. What's different now is CENTCOM’s formal acknowledgment of real-world exploitation.

For service members, tighter controls may improve safety but limit normal phone use. For consumers, the episode strengthens the argument that granular location data reveals sensitive behavior. Privacy advocates and security experts agree on the threat but debate the fix—opt-outs, broker rules, or broader limits on collection.

Outlook

Expect the Pentagon to accelerate technical changes, especially disabling advertising IDs on DoD phones. Commanders may impose stricter deployment rules for personal devices, wearables, and social media. The major challenge is enforcement, as recent Strava findings show policy alone doesn't guarantee security.

Long-term, the most consequential outcome could be reclassifying location data as a strategically controlled asset—bringing more aggressive enforcement, stronger data minimization, and greater scrutiny of foreign access. That could spur demand for secure-by-default consumer tech and maybe legislative efforts to fund the DOJ program.

“We're moving toward a world where data brokers must treat precise location like munitions,” said a congressional aide. “The stakes are too high to leave it to market forces.”