Am I the Target?
The Enemy Doesn't Need to Hack Your Phone — They Can Buy Your Location
For decades, the military has worried about spies, intercepted communications, careless conversations, photography around sensitive areas, and people telling the world things they probably shouldn't. Every generation of military personnel has received some version of the same warning: seemingly harmless information can become extremely useful when it gets into the wrong hands.

About Challenge Coin Nation
We at Challenge Coin Nation are a veteran founded company and are honored to be able to continue serving our brothers and sisters in arms all over the world. We sell many different military themed items, but challenge coins are our specialty. Below is just one of our great coins.

Now there is another OPSEC problem to add to the list: advertising.
On September 4, Reuters reported that several parts of the U.S. military have disabled advertising identifiers on government computers and mobile devices amid concerns that commercially available location information can be used to track American military personnel. Yes, advertising identifiers. The same enormous advertising industry that wants to figure out whether you might be interested in buying a new truck, ordering a pizza, or replacing the boots you searched for last week can generate data that has potentially serious military value.
According to U.S. Central Command, this isn't merely a theoretical vulnerability. Earlier this year, CENTCOM told Congress that it had received multiple threat reports involving adversaries exploiting commercially available location data to target or surveil U.S. personnel in theater. In other words, this has moved beyond somebody at the Pentagon asking, "Could this possibly happen?" The military says it has received reports indicating that it is happening.
Welcome to OPSEC in the 21st century.
You Don't Have to Post Your Location Anymore
Most military people understand the basic social-media problem. Don't post a picture of something classified. Don't announce movements. Don't put sensitive information on Facebook. Don't take a picture on the flightline with something in the background that shouldn't be there. Don't tell the entire world that your unit is leaving next Tuesday and everybody will be gone for six months. We've been beating those lessons into military personnel for years.

But commercial location data creates a much stranger problem because you don't necessarily have to post anything. Smartphones and applications routinely generate information about the devices using them. One piece of that ecosystem is the Mobile Advertising ID, or MAID, a unique identifier designed to allow advertisers and advertising companies to recognize a device without necessarily knowing the person's name.
That distinction sounds reassuring until you think about it. An intelligence service may not initially care whether a particular phone belongs to Staff Sergeant Jones. It may care much more that the same device spends every weekday at a particular military installation, sleeps every night at a particular apartment complex, and has suddenly started appearing at another military installation thousands of miles away.
Combine identifiers with location information collected by apps and other services, aggregate enough of it, and patterns begin to emerge. Where does this device spend the night? Where does it go every morning? Where does it spend the workday? Where does it travel? What other devices regularly appear around it? And perhaps most importantly from a military standpoint, where did a whole bunch of those devices suddenly go at the same time?
That is where an advertising problem becomes an intelligence problem.
Imagine a Maintenance Squadron's Phones
Consider a completely hypothetical example. A few hundred military members normally work at an airbase in the United States. Their phones establish predictable patterns over months or years. Then a large percentage of those devices disappear from their normal locations. A short time later, a similar collection of devices begins appearing regularly around an airfield somewhere else in the world.
Nobody posted a deployment announcement. Nobody uploaded a picture of an airplane. Nobody discussed the movement on Facebook. Nobody stood outside the front gate holding a sign saying, "Hey, everybody, our unit deployed here." As far as the people carrying those phones are concerned, nobody violated an OPSEC briefing.
But the pattern itself potentially tells a story.
Now imagine what happens if an adversary combines that commercial information with satellite imagery, aircraft tracking, social media, news reports and traditional intelligence. Maybe commercial satellite imagery shows additional aircraft on the ramp. Maybe transportation aircraft have been arriving more frequently. Maybe hotel reservations near the installation suddenly changed. Maybe family members back home are talking about deployments on social media. Each piece by itself may mean almost nothing. Put enough pieces together and the picture starts getting clearer.
Maintainers should understand this concept particularly well because troubleshooting airplanes works exactly the same way. One indication may not tell you much. Five indications pointing in the same direction probably do. Intelligence analysts do essentially the same thing with information.
We Already Know How Powerful This Data Can Be
If that hypothetical maintenance squadron example sounds far-fetched, consider what researchers and journalists have already demonstrated using commercially available information.
A 2026 congressional letter to the Department of Defense cited a particularly remarkable example from 2024. An international group of journalists obtained a free sample of commercial location data containing approximately 3 billion data points from 11 million mobile devices. According to the lawmakers, the journalists were able to identify 12,313 devices that appeared to spend time at or near at least 11 military sites in Germany. They could also track movements away from those installations.
Think about that for a moment. They weren't the NSA. They didn't hack the Pentagon. They didn't penetrate a classified military network. They were journalists examining a sample of commercially available data.
If journalists can do that as an investigation intended to demonstrate a security problem, it isn't difficult to understand why a foreign intelligence service might find the same type of information interesting.
The Pentagon Says This Has Already Become a Threat
On April 14, 2026, U.S. Central Command provided Congress with a written response stating that it had received multiple threat reports concerning adversaries exploiting commercial location information to target or surveil U.S. personnel in theater during Operation Epic Fury in the Middle East.
That disclosure prompted a bipartisan group of lawmakers to push the Department of Defense for stronger protections. Their concern was straightforward: commercial location information can reveal where American personnel congregate and establish what intelligence analysts call a "pattern of life." That information could potentially support surveillance, counterintelligence efforts, or attacks involving missiles, drones and other weapons.
Now the services are taking additional action. Reuters reported on September 4 that the Air Force disabled advertising identifiers on computers and mobile phones roughly two months ago. U.S. Special Operations Command recently disabled them on Windows devices. The Army said advertising identifiers have been blocked on its Windows computers for years and disabled by default on Android and Apple mobile devices since at least February.
That's a pretty remarkable development when you think about it. The Department of Defense isn't trying to stop somebody from breaking through a firewall and hacking into a classified network. It's trying to reduce information leaking through the commercial advertising ecosystem.
We've Seen Versions of This Before
This isn't the first time consumer technology has accidentally created a military intelligence problem. Fitness trackers provided one of the best-known examples.
In 2018, researchers examining a global heat map published by fitness company Strava discovered that exercise routes could reveal activity around military installations and other sensitive locations. The individual data points weren't particularly interesting. Someone went jogging. Big deal. But when enough people carrying GPS-enabled devices repeatedly ran the same routes around isolated facilities, suddenly those glowing lines on a map could reveal locations and activity that weren't supposed to attract much attention.
The Pentagon took the issue seriously enough to review the security implications and advise military personnel and DoD civilians to use strict privacy settings on wearable devices.
The lesson from that episode wasn't that jogging is an OPSEC violation. The lesson was that enormous collections of seemingly insignificant information can reveal things nobody intended to reveal.
Commercial location data takes that problem to another level.
OPSEC Has Always Been About Putting Pieces Together
Anyone who served probably remembers some version of the classic OPSEC lesson. The enemy doesn't necessarily need you to hand them the entire operations plan. Maybe one person mentions a deployment. Someone else mentions the date. Another person posts a photograph. A spouse talks about when everyone is coming home. Somebody else identifies the unit. Each piece by itself might seem harmless. Put the pieces together and suddenly you've revealed something important.
Commercial data changes who is providing some of those pieces. Your phone can do it for you.
That doesn't mean every smartphone is constantly broadcasting its owner's exact position to every advertiser on Earth. The commercial data ecosystem is more complicated than that, and modern phones include privacy controls intended to limit tracking. But the fundamental vulnerability remains: enormous quantities of information about people's behavior are collected because that information has commercial value.
Advertisers want to understand people. Where do they go? What stores do they visit? What are they interested in? What are they likely to buy? Those questions are valuable because better information allows companies to target advertising more effectively.
An intelligence service may look at the exact same data and ask entirely different questions.
Government Phones Are Only Part of the Problem
Disabling advertising identifiers on government devices makes sense, but it doesn't make the larger problem disappear. Military personnel carry personally owned phones. So do civilian employees, contractors and visitors. Family members live around military installations. Everyone carries smart devices loaded with applications that may request location permissions for perfectly legitimate reasons.
Telling military personnel to simply leave their phones at home sounds easy until you remember how deeply phones are embedded in everyday life. People use them for navigation, banking, authentication, airline tickets, communication, entertainment and about a thousand other things. The military itself increasingly relies on mobile technology.
An adversary also doesn't necessarily need to identify individual people for the information to be useful. If the objective is determining whether activity at a particular installation has increased dramatically, the number and movement of devices may be more important than the names of the people carrying them.
Sometimes the pattern is the intelligence.
The Cheapest Intelligence Collection Program Ever
There is something almost absurd about this situation. Nations spend billions of dollars developing reconnaissance satellites, signals-intelligence systems, surveillance aircraft and cyber capabilities. They train spies, build listening stations and develop sophisticated tools intended to discover what other countries are doing.
Meanwhile, enormous amounts of information about where ordinary people go and what they do are generated by an industry whose primary objective is figuring out which advertisement you're most likely to click.
An adversary doesn't necessarily have to break into the Pentagon to obtain useful information. In some circumstances, commercially available data can simply be purchased.
That's what makes this problem fundamentally different from traditional cybersecurity. You can build a very good firewall around a military network. It's much harder to build a firewall around information that was intentionally collected outside that network and distributed as part of a legitimate commercial business.
From "Loose Lips Sink Ships" to "Turn Off Your Advertising ID"
During World War II, Americans were warned that careless conversations could provide useful information to the enemy. During the Cold War, military installations worried about photography, spies and communications security. Then came the internet, followed by social media, fitness trackers and smartphones. Now we're worried about the advertising industry inadvertently producing information that can be exploited for intelligence purposes.
The technology changes, but the basic OPSEC principle doesn't. An adversary doesn't care whether information was classified when they obtained it. They care whether it is useful.
Sometimes the most useful information isn't a secret document, a hacked network or a photograph of an airplane. Sometimes it's thousands—or billions—of completely ordinary pieces of information that reveal a pattern when somebody knows how to put them together.
For maintainers, maybe the easiest way to think about it is the same way we've always approached troubleshooting. One clue usually doesn't solve the problem. You gather indications, compare them, eliminate possibilities and eventually the pieces point you toward the answer.
Unfortunately, the other guy knows how to troubleshoot too.
So the next time an app desperately wants permission to know your precise location so it can provide a "better experience," there might be another question worth asking:
Who else might eventually get to experience that data?
Shop for more aircraft flags and military gifts at these pages:
Challenge Coin Nation Stock Morale Patches
Leave a comment