In late 2024, journalists working with German news outlets asked an American data broker for a free sample.
What they received was 3.6 billion location coordinates, some separated by milliseconds, covering roughly eleven million mobile advertising identifiers in Germany over a two-month period. It was a sales demonstration. Free samples are normal in this industry because the data is abundant and the margin is in the subscription.
From that sample they identified up to 12,313 devices that spent time at or near at least eleven American military and intelligence sites. Inside one air base where nuclear weapons are reportedly stored in underground bunkers, they counted 38,474 location signals from as many as 189 devices. They followed others through an armoured-vehicle training area. They tracked service members off base to barracks, workplaces, restaurants, supermarkets and bars, and they could see entry points, security practices and what appeared to be guard schedules.
No law was broken in obtaining it. The reporters were offered a sample because that is how the industry sells.
In May 2026 the Department of Defense confirmed to United States senators what the implication had always been: that adversaries have used commercially available location data to target American service members in war zones, with Central Command reporting multiple threat reports concerning adversary exploitation of commercial location data to target or surveil personnel in theatre.
The location data market is the second half of the tracking apparatus, and it does something ADS-B cannot. An aircraft transmits because a safety mandate requires it. A person transmits because they installed a weather app.
How the location data actually escapes
The mechanism is the part almost nobody understands, including, apparently, many of the companies whose products are the source.
When an application displays an advertisement, it does not sell that space to one buyer. It runs an auction, in milliseconds, called real-time bidding. A bid request goes out describing the opportunity: device make and model, IP address, and in many cases precise location if the application has been granted location permission, along with other technical details.
That request is broadcast to everyone eligible to bid. One of them wins and places an ad.
All of them received the data.
That single structural fact is the entire story. The bid stream is not a transaction between two parties, it is a disclosure to every participant, and participation is not restricted to anybody with an actual interest in buying advertising.
The Federal Trade Commission established this as a legal finding rather than a technical allegation. In its December 2024 action against Mobilewalla, the Commission found that when the company bid for advertising space through a real-time bidding auction, it collected and retained the information in the bid request even when it did not have the winning bid. The order requires it to stop using data from those exchanges for anything other than actually bidding on ad space.
Bidding was the cost of entry. The data was the product, and a participant willing to lose every auction collects the same information as one that wins.
The breach that proved the granularity
Claims about this market were persistently dismissed as overstated until a hacker settled the question.
Gravy Analytics, a major location data broker and parent of a subsidiary selling to government customers, disclosed a security incident discovered on 4 January 2025, with attackers claiming root access to its servers and control of the cloud storage holding its data.
The leaked material contained millions of location coordinates and the names of thousands of mobile applications. The list included dating apps, fitness apps, photo editors, games, transit apps, weather services, prayer apps and pregnancy apps.
The significant finding was not the volume. It was the sourcing. The presence of those particular applications confirmed that the data had been obtained through real-time bidding rather than through tracking code deliberately embedded by the developers, which means the applications generating the data were not knowing participants. The developer of a puzzle game had become a sensor in a global collection network without being told.
The company’s own public position says exactly that, and says it as a defence. It states that it does not track smartphone user locations, does not collect location data directly from individuals or from application publishers, and that the data it uses is already commercially available, collected via smartphone apps, purchased at scale by brokers or aggregators, and then licensed onward.
Every clause of that is probably true, and it describes a system in which nobody in the chain believes they are the party doing the surveillance.
Nobody is responsible and everybody is in the chain
Trace the path and the diffusion of responsibility is total.
The user granted location permission to an application, usually for a function that genuinely needed it. The developer integrated an advertising network to fund a free product and frequently has no visibility into what the network transmits. The advertising exchange broadcasts the bid request because that is what an auction requires. Participants in the auction retain what they receive. Aggregators purchase and combine. Brokers license onward. Analytics firms enrich the result against other datasets. Governments and researchers and anybody with a credit card buy the output.
At no point does a party in that chain take a decision that looks like deciding to conduct surveillance. The user agreed to share location with an app. The broker bought lawfully available data. The buyer purchased a commercial product.
That is the same structural property this entire subject keeps producing, arriving in a different industry. A flag relocates legal identity, a corporate layer relocates the responsible person, and a data supply chain relocates the decision until there is no point at which anybody chose the outcome.
The regulator’s own framing captured it. A commissioner’s statement in the Mobilewalla matter observed that brokers purchasing sensitive information cannot avoid liability by turning a blind eye.
Why location data matters at an airfield
The application to this subject is direct and it inverts the principal weakness of aircraft tracking.
ADS-B coverage is a function of volunteer receiver density, which follows population and hobbyist interest, which means the corridor running from the Gulf through Libya and Chad into Darfur is well observed at its endpoints and effectively blind across the middle. The desert has no plane spotters.
The desert has phones.
A cargo flight into a remote airfield involves a flight crew who sleep somewhere, eat somewhere, and carry handsets. Ground handlers. Fuel truck drivers. Security personnel. Local fixers. Officials. Anybody with a smartphone running an ad-supported application in a place with mobile data coverage is generating bid requests, and bid requests contain coordinates.
The granularity demonstrated in the German investigation is the relevant benchmark. Not merely that a device was at a base, but entry points, movement patterns, timings and the rhythm of shifts, derived from signals some of which were separated by milliseconds.
Applied to a logistics node, that is a record of when aircraft are serviced, where crews are quartered, which buildings are occupied, how many people arrive with a delivery, and whether the pattern changes before a particular flight. The satellite imagery that documented hangars appearing at a desert airfield shows what was built. Location data would show who was there while it was being built.
And it is purchasable. The German reporters got theirs as a free sample, which is the detail that should govern any assessment of how hard this is to obtain.
What it does to the people in this trade
The crews who staff this industry were historically protected by obscurity rather than by any security practice. A pilot flying irregular cargo was a name on a crew list in a jurisdiction nobody would query, living between hotels, with no institution tracking him.
Location data removes that. A device reveals a residence by where it spends nights, an employer by where it spends days, and a social network by co-location with other devices. Deanonymisation from pattern alone is straightforward: in the leaked Gravy material, analysts traced a person from New York to their home in Tennessee.
For an operator, the consequences compound. A crew’s movements connect an airframe to a company, a company to an office, an office to a set of individuals, and individuals to the people they meet. The corporate opacity that defeats a subpoena does not defeat a co-location analysis, because the structure was designed to hide ownership on paper and nobody designed it to hide the human beings from a dataset that did not exist when it was built. A free zone entity has no pattern of life. The people who run it do.
The American military discovered the same thing about itself and has been struggling with it since 2018, when a fitness application published an aggregate activity map that outlined installations nobody had announced.
The government-purchase problem
There is a legal dimension that explains why this market has institutional customers rather than merely commercial ones.
American constitutional law treats government acquisition of historical cell site location information as a search requiring a warrant. The data broker route raises a separate question, because an agency buying a commercially available product is not compelling anybody to produce anything.
Agencies took that position explicitly. In 2021 the Defense Intelligence Agency told Congress it was purchasing commercially available phone location data, including on Americans, without a warrant, on the basis that the data was already sold commercially.
Legislative responses have been introduced. The Fourth Amendment Is Not For Sale Act, which would bar government acquisition of information that would otherwise require a warrant, passed the House of Representatives in April 2024 and has not been enacted.
The result is a market with three categories of buyer. Advertisers, who are the nominal customers. Governments, who are large customers purchasing what they could not compel. And anybody else, because a dataset offered as a free sample to a journalist is a dataset offered to anybody who asks convincingly.
That third category is the one that matters, because it includes every party in the trade.
The counterintelligence inversion
The point that makes this genuinely dangerous rather than merely intrusive is that it does not discriminate.
Senators pressing the Department of Defense noted that commercial location data can identify where troops congregate and establish their pattern of life, which can be exploited to target attacks including missiles, drones and roadside bombs, as well as for counterintelligence purposes. The Pentagon’s confirmation that this has occurred in a war zone converts a privacy argument into a casualty argument.
The German reporting found material beyond operational detail: data on service members’ children, and devices visiting brothels, which is coercion material rather than targeting material.
And the same dataset works against the investigators. A journalist tracing an airlift carries a phone. A United Nations panel member visiting an airfield carries a phone. An NGO researcher documenting an atrocity carries a phone. The analytical capability that exposed the Chad corridor is available, at the same price, to the parties operating it.
That symmetry is unusual in this subject. Most of the techniques in this trade favour one side. The data market favours whoever is paying attention, and attention is cheap. That cuts against the structural advantage this trade has always relied on, which is that watching is expensive and operating is not.
What cannot be fixed easily
The structural obstacles to solving this deserve stating, because the obvious remedies are weaker than they appear.
Banning sales to foreign adversaries addresses a route rather than a mechanism, and a dataset sold to an intermediary in a permissive jurisdiction reaches the end buyer anyway, which is the identical registry-shopping problem that governs everything else in this field.
Device-level controls help and are partial. Restricting advertising identifiers reduces persistent tracking and does not eliminate location in bid requests, and users who need a functioning phone grant permissions.
Organisational policy is the practical mitigation and it is hard to enforce. Telling personnel not to use location-enabled applications works in proportion to compliance, and compliance across a large population approaches zero.
And the enforcement record shows the shape of the problem. The Commission has acted against Kochava, X-Mode and Outlogic, InMarket, Mobilewalla, and Gravy Analytics and Venntel across four years. Those are significant actions against named companies in a market with a great many participants, most of which are not American and none of which depend on the particular firms that were sanctioned.
Naming a broker removes a broker. It does not remove the bid stream, any more than designating a shell company removes the registry that will form the next one.
The 2016 precedent nobody acted on
This was demonstrated a decade before it became a scandal, which is the part that makes the current reaction hard to credit as surprise.
As early as 2016, an American defence contractor was able to use commercially available location data to track special operations forces from their bases in the United States to a sensitive staging post in Syria. That account was disclosed publicly years later.
Think about what that demonstration involved. Not a hack, not a leak, not an insider. A contractor bought a commercial product and used it to follow some of the most protected personnel in the American military across continents to a location that was not supposed to be known.
In 2018 the aggregate activity map published by a fitness application outlined installations in several countries, prompting policy restrictions on fitness trackers. In 2019 a newspaper investigation showed how easily commercial location data identified individuals including public officials. In 2021 reporting established that defence and intelligence agencies were purchasing the data. In 2024 journalists tracked personnel at eleven sites in an allied country.
In 2026 the Department of Defense confirmed to Congress that adversaries are exploiting it operationally, and senators wrote that their efforts to obtain further information about the reported targeting had been unsuccessful.
Ten years, a steady escalation of public demonstrations, each one more specific than the last, and the market is intact. That is not an institutional failure to notice. It is an institutional failure to act on something noticed repeatedly, which is the pattern this whole field keeps producing and which the aviation side of it established fifty years ago.
The claims that do not hold up
An audit, because this subject attracts both dismissal and apocalypse.
Location data is anonymous is the industry’s position and it fails to pattern analysis, since a device that sleeps at one address and works at another has identified a person.
You consented to this describes a permission granted to an application for a stated purpose and not an understanding that the coordinates would be broadcast to every participant in an advertising auction.
App developers are selling your location is frequently false. The breach analysis indicates the data was extracted through bid streams, which means developers were not knowing participants.
It is only used for advertising is contradicted by government purchases, by the German investigation, and by the Pentagon’s own confirmation of adversary exploitation.
The government needs a warrant is true for compelled production and has not been true for commercial purchase, which is the loophole the pending legislation addresses.
Turning off location services solves it is partial. Coarse location is inferable from network addresses, and applications with legitimate location functions still transmit.
The FTC has fixed this overstates five enforcement actions in a global market.
This is a privacy issue is too narrow. The Department of Defense has told Congress it is a force protection and counterintelligence issue, which is a different category of harm.
What the data market is actually telling us
The finding is that the surveillance infrastructure covering the places this investigation cares about was not built by any state, and it was not built for surveillance.
It was built to sell advertising. The precision exists because advertisers pay more for precision. The coverage is global because smartphones are global. The retention is indefinite because storage is cheap. The resale is permitted because nothing prohibited it. And the output is purchasable because the business model is selling it.
Which produces an arrangement that would have been impossible to construct deliberately. A government proposing to track eleven million phones in an allied country, at millisecond resolution, including inside a nuclear weapons facility, would face objections at every stage. An advertising network did it as a byproduct and offered the result as a free sample.
For the ghost-plane economy, this closes a gap that eighty years of corporate structure had kept open. The flags, the registries, the free zone companies and the settlement mechanisms were all designed to break the link between an activity and a responsible person, and they work, because they were built against investigators who follow documents.
They were not built against a dataset that records where the people were.
A hacker broke into a data broker and the files named Candy Crush. Somewhere in that market is a record of everybody who was on a particular ramp on a particular night, and the only reason nobody has drawn it is that nobody has yet paid for the right slice.

Leave a Reply