e4mXplains: Could advertising data become a national-security risk in India?

US military is disabling mobile advertising IDs after reports that commercial location data was used to track personnel in the Middle East; exposes how ad targeting infra can be a surveillance tool

e4m by Shantanu David
Published: Sep 7, 2026 8:58 AM  | 8 min read
Advertising Data: A New National Security Concern for India
  • e4m Twitter
  • The US military has disabled advertising identifiers on government-issued smartphones and computers due to concerns that commercial location data could be exploited to surveil American personnel in the Middle East.
  • This decision follows reports from US Central Command indicating that adversaries were using location data to target US troops, raising risks of attacks and counterintelligence operations.
  • Mobile advertising IDs, which are intended for advertising purposes, can inadvertently reveal patterns of movement and location when linked with other data, leading to potential security vulnerabilities.
  • The situation highlights broader implications for national security, as similar risks exist in other countries, including India, where the government has recognized the dangers posed by commercially collected app data.

A technology designed to help advertisers recognise a smartphone is now being treated as a battlefield security risk.

The US military has disabled advertising identifiers across a range of government-issued smartphones and computers after reports that commercially available location data had been exploited to target or surveil American personnel in the Middle East.

According to Reuters, the US Air Force disabled advertising identifiers on computers and mobile phones in July, while US Special Operations Command said it had recently done so on Windows devices. The US Army said advertising IDs had been disabled on Windows computers since before 2021 and by default on Android and Apple mobile devices since at least February 2026.

The move follows an April disclosure by US Central Command, or CENTCOM, that it had received multiple threat reports concerning adversaries exploiting commercial location data to target or surveil US personnel during operations in the Middle East. US lawmakers warned that such information could reveal where troops congregate and establish their “pattern of life”, potentially aiding missile, drone or roadside-bomb attacks as well as counterintelligence operations.

But how does information collected for advertising get anywhere near a battlefield?

What is a mobile advertising ID?

A mobile advertising ID, or MAID, is essentially a device-level identifier intended for advertising.

On Android, Google provides an Advertising ID that is unique to a device but can be reset or deleted by the user. Google says it allows developers and advertising systems to monetise apps and can be used to personalise advertising. Apps targeting newer Android versions must specifically declare permission to access it.

Apple has its own Identifier for Advertisers, or IDFA. Since iOS 14.5, apps generally need permission through Apple’s App Tracking Transparency framework before they can access it or track a user across other companies’ apps and websites. Apple explicitly includes sharing user or device data with data brokers within its definition of tracking.

The identifier is not, by itself, a GPS tracker.

The problem emerges when a persistent identifier is associated with other information — particularly precise location data generated by apps.

A weather app, navigation service, retail app or another application may legitimately request location access. Advertising and analytics software embedded inside apps can also participate in the flow of data. Once observations of the same device can be repeatedly linked to the same identifier, a series of anonymous-looking location points can begin to form a recognisable pattern.

Home. Workplace. Gym. Airport. Military installation.

The person's name may not even be necessary for some forms of surveillance. The pattern itself can be valuable.

How does advertising infrastructure enter the picture?

Much of digital advertising operates through automated auctions.

When an app or website has an advertising slot available, information about the impression is transmitted through the advertising ecosystem so advertisers can decide whether, and how much, to bid.

That ecosystem has historically generated enormous quantities of device and behavioural information.

A US Federal Trade Commission case against data broker Mobilewalla illustrates how the pipeline can be exploited. The FTC alleged that Mobilewalla collected information from real-time bidding advertising exchanges even when it did not win the advertising auction.

Between January 2018 and June 2020, according to the regulator, the company collected more than 500 million unique advertising identifiers paired with precise location data. The FTC alleged that this information could identify individual devices and reveal visits to sensitive locations. Its eventual order specifically restricted the sale or use of location information relating to places including health clinics, religious organisations and military installations.

In another case, the FTC said location broker X-Mode/Outlogic obtained precise location data from apps containing its software development kit, from its own apps and from other data brokers and aggregators. That location information was associated with mobile advertising IDs and sold or licensed to clients.

The adtech system therefore does not have to be designed as a surveillance network to produce information useful for surveillance.

Data created to answer a marketing question  (is this person near a store, and should we show them an ad?) can potentially answer another question entirely: where does this device go every day?

Why switch off the advertising ID?

Removing or disabling the identifier breaks one of the easiest ways of repeatedly associating observations with the same device.

Google allows Android users to delete their advertising ID, after which attempts to access it return a string of zeros. Apple similarly prevents apps from accessing the IDFA when tracking permission has not been granted.

That is why the US military's action matters.

It does not, however, make a smartphone invisible.

Media reported that privacy specialists cautioned that people may still potentially be tracked by combining technical device characteristics, network information and location signals. Personal phones carried onto bases are another obvious complication: a defence organisation can configure an official handset but has much less control over every consumer device entering a sensitive location.

The military response is therefore less a complete solution than an acknowledgement of the underlying problem: ordinary commercial data can acquire extraordinary value when the person carrying the phone is sensitive enough.

The military risks created by seemingly mundane consumer data are not new. In 2017, fitness platform Strava published a global heat map built from more than a billion activities uploaded by runners and cyclists. Researchers soon noticed that in sparsely populated parts of countries such as Syria and Afghanistan, concentrations of activity could inadvertently reveal the locations and even internal layouts of military installations.

The concern was not simply that a base could be identified. Repeated running and cycling routes could also expose patterns of life, where personnel congregated, how they moved around an installation and which routes they used regularly. The US Department of Defense subsequently warned that such data could expose military locations and potentially be used to target individuals, and later restricted the use of geolocation features on devices in designated operational areas.

The Strava episode differs from the current advertising-data concern: Strava involved fitness data aggregated into a publicly accessible heat map, while the present risk involves commercially available location data that can be linked to persistent device identifiers. But the underlying lesson is the same. Data does not need to contain a soldier’s name, rank or unit to become useful intelligence. Repeated location signals can be enough to reveal who is where, when they are there and how they move.

Why does this matter for India?

There is currently no public evidence comparable to the CENTCOM disclosure showing that Indian military personnel are being targeted through commercially purchased advertising location data.

But the technological mechanism is not uniquely American.

Android's Advertising ID and Apple's advertising architecture operate in India too, while apps, advertising SDKs, programmatic advertising systems and consumer location permissions form part of the same global mobile ecosystem.

More importantly, the Indian government has already publicly recognised the broader national-security danger posed by commercially collected app data.

When India blocked 118 mobile applications in September 2020, MeitY said it had received reports of apps “stealing and surreptitiously transmitting users’ data” to servers outside India. It warned that the compilation, mining and profiling of such data by elements hostile to India could threaten national security and defence.

The government made the point even more explicitly in a February 2024 parliamentary response. MeitY said certain apps could steal and transmit both user data and “real-time activity”, which could then be collated, analysed, profiled and mined by hostile elements for activities detrimental to national security and defence.

India has since notified the Digital Personal Data Protection Rules, 2025, alongside the DPDP Act. The framework requires lawful processing of personal data and is built around principles including consent, transparency, purpose limitation and data minimisation.

However, implementation remains phased. The November 2025 notification gives different provisions staggered commencement dates, with several major rules coming into force only 18 months after notification. The government has said that during this transition, existing data-protection requirements under the IT Act and SPDI Rules continue to apply.

That makes the American episode relevant to India's advertising industry for a reason that goes beyond privacy compliance.

Advertisers usually think about location data in terms of relevance, attribution, footfall measurement and audience segmentation. Regulators tend to approach it through consent and consumer privacy.

The US military case shows a third dimension.

The same dataset can change character depending on who is buying it, who is being observed and what inference the buyer wants to make.

A cluster of phones around a shopping mall is an advertising audience.

A cluster of phones repeatedly appearing at a sensitive installation can be something else entirely.

And that is the uncomfortable lesson for adtech: data does not necessarily remain confined to the purpose for which the industry first found it useful.

Published On: Sep 7, 2026 8:58 AM