Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 14, 2026 · 7 min read

Pentagon Kills Ad Tracking IDs on Troops' Phones

Five US military commands turned off the advertising identifier on government issued iPhones, Android phones and Windows machines after reports that foreign adversaries used commercially purchased location data to target American troops in the Middle East.

The identifier your phone hands to advertisers exists to sell you sneakers. The United States military has now classified it, in policy if not in those words, as a targeting aid.

Five commands have now disabled advertising IDs on issued devices. Nobody had to hack anything for this to become necessary. The data was for sale.

Key Takeaways

  • The US Army, Air Force, Navy, Marine Corps and Special Operations Command disabled advertising IDs on government issued iPhones, Android phones and Windows computers across the federal military enterprise network.
  • The Air Force implemented its change in July 2026; the other four commands acted earlier in the year.
  • Senator Ron Wyden, the senior Democrat on the Senate Intelligence Committee, raised the issue in 2026 after reports that foreign adversaries targeted US troops in the Middle East using commercially obtained location data.
  • The stated rationale is anonymity in a crowd: disabling the advertising ID makes a person far harder to pick out, because their location data blends in with everyone else whose ID is also off.
  • Wyden warned that personal phones carried onto bases by troops and contractors still expose service members and facilities, and that gap remains unclosed.
A smartphone lying face down on folded military issue canvas gear in natural daylight

What Exactly Did the Military Change?

It switched off one field: the resettable advertising identifier that operating systems expose to apps. According to TechCrunch's reporting, the change covers issued iPhones, Android handsets and Windows computers across the federal military enterprise network.

The trigger was not a risk assessment. It was reporting that adversaries had already used purchased location data against American troops in the Middle East. Wyden pressed the services, and the services moved.

Note what the fix is not. No new encryption, no new hardware, no classified countermeasure. A setting any civilian can toggle in fifteen seconds was, until this year, on by default on the phones of deployed service members.

What Is an Advertising ID?

An advertising ID is a stable string your operating system hands to every app so advertisers can recognise you across apps without touching a hardware serial number. Android calls it the Google Advertising ID, or GAID, documented by Google Play's developer policy. Apple calls it the IDFA, gated behind the App Tracking Transparency prompt described in Apple's support documentation. Windows ships its own advertising ID for Microsoft Store apps.

The word that matters is stable. Your IP address changes when you switch networks. Your advertising ID does not change when you walk from a barracks onto a flight line, or when you close one app and open another. That persistence turns disconnected coordinates into a route, and a route into a routine. Google's documentation is precise about deletion: apps that ask afterwards receive a string of zeros. The device stops emitting a name for itself.

How Does an Ad ID Become a Targeting File?

Through ordinary ad auctions and the brokers downstream of them. When an app loads an ad slot it broadcasts a bid request holding the advertising ID, coordinates, device model and app name to many bidders at once. The winner serves an ad. The losers keep the data. EFF measured the collection end of that pipeline when it found that four widely embedded Android ad libraries send precise location by default.

The military specific version of this has been documented repeatedly, and the pattern has not improved. In November 2020 Motherboard reported that location data from ordinary apps including Muslim Pro reached US military buyers through the broker X-Mode. In November 2023, Duke University's Sanford School showed in Data Brokers and the Sale of Data on US Military Personnel that brokers would sell records on active duty personnel, filtered by proximity to installations, for cents each, with at least one seller offering to skip vetting if payment came by wire.

Then came the sharpest case. A November 2024 joint investigation by WIRED, Bayerischer Rundfunk and netzpolitik.org analysed a free sample from the Florida broker Datastream Group. At Ramstein Air Base alone, the reporters counted 164,000 location points from as many as 1,275 devices. That is roughly 129 pings per device, from a sample that cost nothing, at a base tied to the US nuclear mission. The Electronic Privacy Information Center keeps a running file on data broker threats to national security for the same reason.

Why Blending Into the Crowd Is the Real Defense

Read the official rationale closely: disabling the advertising ID makes the person far more difficult to identify, because their location data blends in with everyone else whose ID is also disabled. That is a statement about crowd size, not secrecy.

It carries a corollary most coverage skipped. A soldier who deletes their advertising ID on a base where everyone else keeps theirs becomes the one anomalous device in the dataset, and anomalies are easy to follow. The defense only works at scale, which is why this arrived as an enterprise wide configuration rather than a security awareness slide. Privacy here behaves less like a lock and more like a herd.

The same arithmetic governs civilians: every person who deletes their ID enlarges the pool of unnamed devices. The Committee to Protect Journalists made the identical argument from the other direction when it showed how ad tech location data exposes reporters and their sources.

What Does Disabling It Not Fix?

A great deal, and honesty about the gaps is the difference between a control and a talisman.

  • IP based geolocation continues. Every server your device contacts still sees an address that resolves to a city, often to a specific network.
  • SDKs still collect. An ad library inside an app can read coordinates whenever the app holds location permission, whatever the ad ID state, as EFF's teardown of four Android ad libraries demonstrated.
  • Bid requests still leak. Device model, OS version, screen dimensions, language and IP still go out to every bidder, and that combination alone often links sessions.
  • Historical files do not disappear. Years of coordinates already sit in broker inventories, and no setting changed today retracts them.
  • Personal devices are untouched. This policy covers issued hardware only.

That last one is Wyden's open warning. Troops and contractors carry their own phones onto bases daily, running the same weather apps and ad libraries as everyone else, and no state data broker law reaches a foreign buyer working through an offshore intermediary.

The Same Idea, Pointed at Your Inbox

An email tracking pixel is the inbox version of a persistent identifier, and the comparison holds at the mechanism level rather than the threat level. A sender embeds a tiny image whose URL carries a unique code tied to your address. Loading it reports when you opened the message, the IP you opened it from, and your mail client. Like an advertising ID, it is stable across messages, which is what turns single opens into a profile.

Be honest about the difference in stakes. Nobody is targeting a mailing list subscriber with a drone. But the crowd argument transfers exactly: when opens stop reporting, a sender cannot tell your silence from anyone else's, and the profile degrades for everyone who blocks. Gblock does that one narrow job in Gmail, and nothing at all about the location pipeline above. To see what is already in your mail, our guide to blocking email tracking on iPhone and Android walks through the mobile settings that matter.

What You Can Do on Your Own Phone

The military's control is free and takes under a minute.

  • Android: Settings, then Privacy, then Ads, then Delete advertising ID. Apps that ask afterwards get zeros, per Google's developer documentation.
  • iOS: Settings, then Privacy and Security, then Tracking, and switch off Allow Apps to Request to Track. That zeroes the IDFA for every app at once.
  • Windows: Settings, then Privacy and security, then General, and turn off the advertising ID.
  • Audit location permissions. Anything that is not a map should be set to Never or to approximate location. Weather and utility apps are the classic carriers.
  • Block remote images and pixels in the mail account you actually read.

What to Watch Next

Watch whether the personal device gap gets closed, because it is the larger surface and the harder political problem. Watch, too, the contradiction Wyden keeps pointing at: US agencies have acknowledged buying the same commercial location data for their own use, without warrants. A government that treats bought location data as a battlefield threat on Monday and a lawful acquisition channel on Tuesday will eventually have to pick one. Until it does, the honest summary is the one TechCrunch's report leaves you with: the Pentagon fixed this for its own phones, and left yours alone.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.