Iran Used Ad Tracking To Hunt American Soldiers: Report
- Get link
- X
- Other Apps
By Dr. Pshtiwan Faraj New Reports Suggest Commercial Ad-Tech and Mobile Network Vulnerabilities Were Exploited to Track American Forces Across the Middle East
The U.S. government has used private ad data to get around the Fourth Amendment. Now foreign enemies are turning it into a weapon.
The Iran war gives a whole new meaning to the phrase "targeted ads." During the war, the U.S. military evacuated many of its bases, moving personnel to hotels and civilian office spaces. A new report in the Financial Times reveals the high-tech ways in which Iran followed them. In at least one place, Iraqi Kurdistan, the Iranian military is suspected of using ad tracking data to figure out which hotels were housing U.S. troops.
"Any government with a halfway decent cyber intelligence program is participating in these [ad data] exchanges, because it's such an immensely valuable source of data," Byron Tau, author of the book that revealed many of these practices, told Reason in 2024. At the time, it was known that the U.S. government used ad data to make an end run around the Fourth Amendment and track Americans without a warrant.
Now it seems that enemy governments have used it to hunt Americans. Iranian-backed militias attacked several hotels in Iraqi Kurdistan with drones, and Iranian forces directly bombed the Crowne Plaza in Bahrain, wounding two Pentagon employees. It's not clear which of these attacks or other attacks on Americans were targeted based on ad data.
Ad tracking is not the only signals intelligence technique Iran reportedly used. Much of the Financial Times report focused on the Signalling System No. 7 (SS7) for communications between countries, which allows telecom companies to find phones roaming outside their country. An Iranian phone company sent a series of SS7 "pings" to Arab countries, and Sen. Ron Wyden (D–Ore.) told the Times that Iran was known by the U.S. Department of Homeland Security to use this technique to find American phones.
And, of course, Iran could lean on less sophisticated spying methods, such as social media posts and old-school informants. People in several Middle Eastern countries told me that it was an open secret which hotels U.S. troops were being billeted in. Arab states and Israel have arrested scores of people for allegedly selling information to Iran.
For years before the war, mobile phones and other devices have been an infamous data security risk for U.S. troops. In 2017, the fitness tech company Strava released a global heatmap of user data, inadvertently revealing the location of military bases and even the specific routes that troops exercised on. (The Pentagon quickly banned fitness apps with geolocation in response.) In 2021, the investigative news outlet Bellingcat found U.S. nuclear personnel studying on public flashcard apps, and used the data to map U.S. nuclear weapons throughout Europe.
But other forms of data are more insidious because users share it unwittingly and unwillingly. Muslim Pro, a popular Islamic prayer clock with a virtual compass that points towards Mecca, was selling user data to a broker until 2020, when it was revealed that the broker was passing that data on to the U.S. military. Muslim Pro cut off the relationship immediately after finding out.
In other cases, user data leaks out in the process of selling ads. Apps sell targeted advertisements on real-time bidding (RTB) exchanges, a type of virtual auction house that displays users' location and other attributes. For example, when I open a video about cameras, the RTB exchange sends out an offer for the attention of a 29-year-old American male in England who likes photography, along with other unique identifiers. Customers use software known as a demand-side platform to automatically bid on these offers.
Despite the fact that many RTB exchanges forbid using the auctions for non-advertising purposes, some data brokers do it anyway. Last year, the Federal Trade Commission (FTC) disciplined the company Mobilewalla for violating the terms of service on several RTB exchanges to scrape user data. Interestingly, the FTC settlement agreement includes a mysterious carveout for location data "collected outside the United States and used for National Security purposes conducted by federal agencies."
In response to a separate customer lawsuit for failing to protect user data, Google agreed this year to create a new setting called RTB Control, which allows users to limit the data sent to ad auctions. This new feature is not just a boon to people who (irrationally) hate algorithms or (more rationally) fear government surveillance. As the recent war has shown, it may be a matter of national security, too.
How Iran Allegedly Turned Smartphone Ads Into a Battlefield Weapon Against U.S. Troops
The battlefields of the twenty-first century are no longer defined solely by missiles, drones, and fighter aircraft. Increasingly, they are shaped by the invisible flow of digital information generated every time a smartphone connects to a cellular network or opens a mobile application.
According to recent reports based on an investigation by the Financial Times and discussed by Reason, Iranian actors allegedly exploited commercial advertising technology and long-known vulnerabilities in global mobile phone networks to locate U.S. military personnel during the recent Iran war. The reports suggest that data routinely collected for online advertising may have helped identify the locations of American forces after they relocated from military bases to civilian hotels and office buildings across the Middle East.
If accurate, the revelations represent more than a successful intelligence operation. They highlight a profound transformation in modern warfare, where commercially available digital data can become a strategic military asset.
From Consumer Marketing to Military Intelligence
The reports indicate that Iranian-linked actors may have combined two separate surveillance methods.
The first involved exploiting Signalling System No. 7 (SS7)—a decades-old telecommunications protocol that allows mobile operators to route calls and messages between networks worldwide. Cybersecurity researchers have long warned that weaknesses in SS7 can be abused to estimate the location of mobile phones roaming abroad.
The second involved the commercial advertising ecosystem that powers smartphone apps.
Modern mobile applications often share device identifiers, approximate locations, and behavioral information with advertising exchanges so marketers can deliver targeted advertisements. While intended for commercial purposes, these datasets can reveal movement patterns and concentrations of devices.
According to the reports, Iranian actors allegedly leveraged such advertising data to identify hotels and civilian facilities housing U.S. personnel in places including the Kurdistan Region of Iraq and Bahrain.
The Kurdistan Connection
One particularly significant aspect of the reporting concerns the Kurdistan Region of Iraq.
During the conflict, portions of the U.S. military reportedly relocated personnel from exposed military installations into hotels and civilian facilities as a protective measure.
According to the Reason article, Iraqi Kurdistan was among the locations where Iranian forces were suspected of using commercial advertising data to determine which hotels contained American personnel. The article notes that it remains unclear which specific attacks, if any, relied directly on such data.
For Iraqi Kurdistan, this carries broader implications.
The region has long hosted coalition forces supporting operations against ISIS while simultaneously serving as a diplomatic and commercial hub.
If commercial digital data can expose temporary military deployments, civilian infrastructure—including hotels—may increasingly become indirect targets during regional conflicts.
The Commercial Data Economy
The reported operation illustrates a growing convergence between private technology markets and national security.
Every day, billions of smartphones participate in real-time bidding (RTB) systems that determine which advertisements users see.
When an application requests an advertisement, advertising exchanges often broadcast limited information about the device—including identifiers, location data, and user characteristics—to numerous potential advertisers within milliseconds.
Although these systems are designed for marketing rather than surveillance, cybersecurity experts have long warned that location information can be aggregated and analyzed for intelligence purposes.
The concern is not theoretical.
Researchers and regulators have previously documented cases in which commercial data brokers collected or resold sensitive location information that could reveal visits to military facilities, government offices, or other sensitive sites.
Warnings Ignored
The latest reports also revive longstanding concerns inside the United States regarding operational security.
The Pentagon has faced repeated warnings over the past decade about risks associated with smartphones, fitness applications, and commercial location data.
Among the most notable examples:
- 2017: Public fitness-app heat maps revealed the locations of military bases and patrol routes.
- 2021: Researchers used publicly available study-app data to identify personnel associated with U.S. nuclear facilities.
- Commercial location brokers have repeatedly demonstrated the ability to track sensitive movements using advertising identifiers.
The recent reporting suggests these vulnerabilities may now have been exploited during an active military conflict.
Cyber Warfare Without Malware
One of the most striking aspects of the alleged operation is that it reportedly did not require sophisticated hacking.
Rather than breaking into smartphones, the reported techniques relied on:
- telecom signaling protocols,
- commercially available advertising data,
- open-source information,
- and potentially human intelligence.
This reflects a broader evolution in cyber conflict.
Modern intelligence operations increasingly depend upon combining legally obtainable commercial information with technical expertise rather than deploying advanced malware alone.
A New Form of Hybrid Warfare
The allegations demonstrate how digital surveillance has become integrated into conventional military operations.
Instead of separating cyber operations from kinetic warfare, states increasingly combine:
- cyber intelligence,
- commercial data collection,
- drone surveillance,
- satellite imagery,
- missile targeting,
- electronic warfare.
Such integration enables military planners to identify troop concentrations, logistics hubs, and temporary headquarters with unprecedented precision.
National Security Meets Privacy
The reports also renew debate over digital privacy legislation.
For years, privacy advocates argued that unrestricted commercial data collection threatened civil liberties.
The latest allegations suggest those same practices may also create national security vulnerabilities.
If foreign intelligence services can legally or indirectly obtain commercially available location data, then ordinary advertising infrastructure becomes part of the modern intelligence battlefield.
Several U.S. lawmakers have renewed calls for stronger restrictions on commercial location-data markets following the recent reports.
Implications for Future Conflicts
The reported operation carries lessons extending well beyond the Middle East.
Military organizations worldwide increasingly rely upon smartphones, civilian communications infrastructure, and commercial digital services.
Adversaries need not penetrate classified networks if commercial ecosystems reveal enough operational information.
Future conflicts may therefore place greater emphasis on:
- restricting mobile device use,
- disabling advertising identifiers,
- strengthening telecom security,
- regulating commercial data brokers,
- improving operational security training.
The Strategic Lesson
Whether every detail of the reporting is ultimately confirmed or not, the broader lesson is unmistakable.
The distinction between civilian technology and military infrastructure is rapidly disappearing.
A smartphone originally designed to display advertisements may inadvertently reveal troop movements.
A telecommunications protocol developed decades ago for international roaming may become an intelligence collection platform.
Commercial data, once viewed primarily as an economic resource, has become a strategic asset with military value.
Conclusion
The reports that Iran allegedly exploited advertising technology and telecommunications vulnerabilities to track U.S. military personnel illustrate how warfare is evolving in the digital age.
Unlike traditional espionage, these methods rely not on secret satellites or covert agents but on the vast ecosystem of smartphones, advertising exchanges, and telecommunications networks used daily by billions of civilians.
For governments, the episode is a reminder that protecting national security increasingly requires protecting digital privacy.
For militaries, it underscores that operational security now extends far beyond the battlefield.
And for the technology industry, it raises difficult questions about whether commercial data markets can continue operating under existing rules when the same information that powers personalized advertising may also help adversaries locate military personnel during armed conflict.
#Iran #UnitedStates #CyberSecurity #CyberWarfare #Geopolitics #MiddleEast #Privacy #Surveillance #MilitaryTechnology #Intelligence #Kurdistan #NationalSecurity #Telecom #DigitalWarfare
- Get link
- X
- Other Apps
Comments
Post a Comment