The U.S. Department of Defense disabled mobile advertising identifiers on government-managed iPhones, Android devices, and Windows computers used by the Army, Air Force, Navy, Marine Corps, and U.S. Special Operations Command. The action followed reports that foreign adversaries could buy commercially brokered app-location data and use identifiers such as Apple’s IDFA and Google’s GAID to identify and track U.S. personnel, including forces deployed in the Middle East; the Air Force implemented its controls in July 2026.
The controls reduce tracking risk on managed government equipment but do not protect personal phones brought onto bases or carried by troops and contractors, nor do they eliminate exposure through social media and other commercial data sources. U.S. Central Command had warned that adversaries could exploit such data, while Senator Ron Wyden and Representative Pat Harrigan called for a Pentagon inspector-general review of military safeguards; Wyden also noted that U.S. intelligence agencies and the FBI purchase commercially available location data without warrants.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
The U.S. Navy reportedly told personnel to clean up their social-media profiles because adversaries could exploit the information for open-source intelligence.
U.S. troops in Jordan were reportedly told their personal devices would be confiscated to prevent adversaries from accessing reactions, photographs, and footage on the phones.
The U.S. Air Force deployed controls disabling or restricting advertising identifiers on its government-managed devices.
U.S. Central Command reportedly warned of multiple threat reports involving adversaries exploiting commercially available location data to track U.S. forces.
Senator Ron Wyden and Representative Pat Harrigan asked the Pentagon inspector general to investigate whether the armed forces had adequately mitigated risks from commercially traded location data.
The Department of Defense reportedly disabled advertising identifiers on government-managed iPhones, Android devices, and Windows computers used by military personnel, following concerns that commercially brokered location data could help adversaries track troops. The measure covered the Army, Air Force, Navy, Marine Corps, and U.S. Special Operations Command.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
bitdefender.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.