Full Breakdown
US Troops Targeted Through Commercial Location Data: Emerging Security Threat
5/28/2026, 11:53:04 PM
The Threat Unveiled
U.S. Central Command (Centcom) confirmed that it has “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater.” The disclosure, relayed in a letter from Senator Ron Wyden, marks the first official acknowledgment that U.S. forces in an active war zone—particularly the Gulf region where they confront Iranian forces—are being tracked via commercially sourced geolocation information.
From Adtech to the Battlefield: Historical Context
Location data is harvested from smartphones and other devices by apps, then sold to data brokers that supply digital advertisers. In 2016 a U.S. defense contractor used such data to trace special-operations forces from U.S. bases to a staging site in Syria. More recently, journalists from *Wired* and two German outlets accessed billions of coordinates from a broker to map movements at or near 11 U.S. military and intelligence sites in Germany, illustrating how the advertising economy can expose operational patterns.
Principal Actors
- Senator Ron Wyden (Oregon, Democrat) – co-author of the congressional letter.
- Representative Pat Harrigan (North Carolina, Republican, former Special Forces officer) – co-signatory urging technical safeguards.
- U.S. Central Command – issuer of the threat reports.
- Alphabet’s Google – developer of the Chrome browser, respondent to the concerns.
- Interactive Advertising Bureau (IAB) and Association of National Advertisers (ANA) – industry groups contacted for comment but did not respond.
- Data brokers – entities that aggregate and sell location information to advertisers.
Quantifying the Exposure
- “Billions of coordinates” were analyzed by journalists to reveal personnel movements.
- The data covered “11 U.S. military and intelligence sites in Germany.”
- Centcom reported “multiple threat reports” without specifying incident counts.
- The adtech trade has been active since at least 2016, when a contractor first leveraged location data for targeting.
Government and Corporate Responses
Senator Wyden urged that “it’s time to start treating the adtech industry as a national security threat.” Representative Harrigan recommended disabling unique advertising IDs on military devices, automatically turning off location sharing on field smartphones, and steering personnel away from Google Chrome toward privacy-focused browsers. Google countered that Chrome provides “industry-leading security” and that the company has “long advocated for stronger rules and safeguards against data brokers.”
Dissent and Industry Pushback
The IAB and ANA declined to comment on the allegations. Google’s defense of Chrome’s security contrasts with lawmakers’ view that the browser’s data-collection architecture “is built from the ground up to collect and share user data,” framing it as a potential weapon against troops.
Gaps in the Evidence
Centcom’s statement offered no concrete incident details, and the Pentagon did not respond to media inquiries. Lawmakers were unable to obtain further specifics from military officials, leaving the scale and immediacy of the threat unverified.
Verbatim Quotes
- “Commercial location data can be used to identify where US troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes,” — U.S. Central Command (letter to Reuters)
- “start treating the adtech industry as a national security threat.” — Senator Ron Wyden
- “are built from the ground up to collect and share user data.” — Representative Pat Harrigan
- “every day they remain on government-issued devices is another day we are handing our adversaries a weapon against our own troops.” — Representative Pat Harrigan
- “industry leading security.” — Alphabet’s Google
- “long advocated for stronger rules and safeguards against data brokers.” — Alphabet’s Google
Anticipated Measures
Lawmakers propose technical mitigations—disabling advertising IDs, disabling location services on field devices, and replacing Chrome with privacy-focused browsers. The congressional letter may prompt legislative reviews of data-broker regulations and tighter controls on the use of commercial geolocation data by U.S. forces.
