Branches report disabling a commercial tracking mechanism
WASHINGTON — Multiple U.S. military branches say they have disabled advertising identifiers on at least some government-issued phones and computers after lawmakers warned that commercially available location data could expose the movements of American personnel.
Reuters reported Friday that the Air Force told Sen. Ron Wyden it disabled the identifiers on computers and mobile phones approximately two months ago. U.S. Special Operations Command said it had recently disabled them on Windows devices. Similar responses from the Army and Navy said advertising IDs had been disabled, although the Navy did not provide a public implementation date.
The Army told Reuters that advertising identifiers had been blocked on Windows computers since before 2021 and disabled by default on Android and Apple mobile devices since at least February 2026. Those timelines show that the changes were not one simultaneous Pentagon-wide switch flipped Friday.
Read the source: Reuters: Military branches disable advertising identifiers on government devices ↗
Why an advertising ID can become a security risk
A mobile advertising ID is a device-specific identifier used to measure and personalize advertising across applications. When combined with location signals and other technical information, it can help data brokers or purchasers connect a device to patterns of movement.
U.S. Central Command told Congress in April that it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater, according to a May 28 bipartisan congressional release. Public documents do not identify every alleged actor, device, data seller or operational consequence.
The disclosure therefore establishes that military officials received threat reports; it does not publicly prove that a particular missile or drone strike succeeded because of an advertising identifier. Classified operational evidence, if it exists, has not been released for independent review.
Read the source: Sen. Ron Wyden: Bipartisan May 28 letter and CENTCOM threat-report disclosure ↗
The protection is meaningful but incomplete
Disabling an advertising ID can reduce routine cross-app tracking and bulk-data collection tied to that identifier. The Cybersecurity and Infrastructure Security Agency separately advises users to disable device advertising IDs, manage app permissions and deny applications access to data they do not need.
It is not a universal invisibility switch. Privacy researchers told Reuters that devices may still be tracked through app data, network information, location permissions or combinations of technical characteristics. Personal phones carried near sensitive facilities can also create exposure beyond the controls applied to government equipment.
The new branch responses do not establish that every military device, operating system, contractor device or personal phone used by a service member is covered by the same policy. They also do not show whether previously collected commercial data was deleted or remains available for sale.
Read the source: CISA: Guidance to disable advertising IDs and limit digital footprints ↗
Lawmakers seek an investigation
Wyden, an Oregon Democrat, and Rep. Pat Harrigan, a North Carolina Republican and former Army Special Forces officer, asked the Pentagon on Friday to investigate whether the military adequately countered the location-data threat. The request is bipartisan, but it is not itself a finding that a military official violated the law.
The Pentagon told Reuters that it would respond directly to the lawmakers. The Air Force and Special Operations Command declined additional comment, and Reuters said the Navy did not respond to a request for comment beyond its written disclosure.
Protecting troops should not depend on whether an adversary can afford a data-broker subscription. The Pentagon should publish an unclassified accounting of which device categories are covered, when each safeguard took effect and what gaps remain—without revealing operational details that could endanger personnel.
What remains unknown
The public record does not establish how many personnel were tracked, which data brokers supplied information, whether any attack caused casualties through commercial location data or how consistently the new settings are enforced across the services.
It also remains unclear whether the Pentagon will impose broader restrictions on personal phones or require additional controls on browsers, applications and contractors. What’s the Scoop With Broach will update this report if the Defense Department releases its response or an inspector general opens a publicly documented review.
Sources and further reading
Reuters: Military branches disable advertising identifiers on government devices ↗
Sen. Ron Wyden: Bipartisan May 28 letter and CENTCOM threat-report disclosure ↗
CISA: Guidance to disable advertising IDs and limit digital footprints ↗
DVIDS: Washington National Guard mobile-device training photograph and public-domain status ↗
