The Pentagon Just Made Bidstream Location Data a Battlefield Liability
The U.S. Army, Air Force, Navy, Marine Corps, and Special Operations Command have all disabled advertising identifiers on government-issued phones and computers, TechCrunch reported on September 4. The trigger was U.S. Central Command confirming "multiple threat reports" of adversaries using commercially sold location data to target troops in the Middle East. The same bidstream data that feeds geo-targeted ad campaigns is now, on the record, a weapon.
If you buy location-targeted media, this is the story to sit with this week. Not because the Pentagon flipping a device setting changes your reach numbers (it doesn't, really), but because it changes the political weather around every vendor in your geo stack.
What actually happened, and how slowly
The timeline is the part I found most telling. Military Times reported that CENTCOM sent a letter to Senator Ron Wyden on April 14 acknowledging it had "received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater." That was the first official confirmation that troops in active war zones were being found this way. The lawmakers' framing was blunt: the data "can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs."
Then, per Reuters, which broke the story, the branches moved at wildly different speeds. The Army says it blocked ad IDs on Windows machines "since before 2021" but only got Android and Apple phones disabled by default "since at least February 2026." The Air Force did its devices roughly two months ago. Special Operations Command did Windows devices "recently." The Navy confirmed the change and declined to say more.
So the most security-conscious organization in the country, with a documented threat to its own people, took months to toggle a setting that any of us could change on our own phone in under a minute. And Defense One noted that as of late May, the Pentagon had only just rolled out the ability to administratively disable location sharing on smartphones at all. I don't read that as a knock on the military specifically. It's what happens inside any large organization when the fix lives in a settings menu nobody owns.
Anyway, the point for us is what they were reacting to.
The data they turned off is the data you buy
A mobile advertising ID (MAID) is the identifier that lets an app auction your attention. When an ad slot loads, the app packages that ID, often with precise GPS coordinates, into a bid request. The IAPP's analysis of RTB risk describes that bid request going out "to dozens, sometimes hundreds, of demand side platforms," billions of times a day. Anyone sitting on the receiving end of that stream, whether they bid or not, gets to keep the coordinates.
That's the bidstream. And the brokers who harvest it are not exotic. The FTC's December 2024 action against Gravy Analytics and Venntel found the companies collecting more than 17 billion location signals per day from roughly a billion devices, then selling lists of who visited health clinics, places of worship, and other sensitive venues. The consent order forces them to maintain a sensitive-location program that explicitly includes military installations. The FTC's consumer protection director at the time said it plainly: this kind of surveillance "puts servicemembers, union workers, religious minorities, and others at risk."
The Electronic Frontier Foundation's March 2026 piece on CBP's location purchases adds the number I keep coming back to: Mobilewalla, another broker in the same FTC sweep, sourced about 60% of its billion-person dataset from RTB auctions. Not from a shady app SDK. From the same auction infrastructure a paid media team uses to buy a geofenced campaign around a competitor's store.
Which is why the Pentagon disabling ad IDs is, functionally, the Pentagon opting out of your targeting pool. As TechCrunch put it, troops' devices now "blend in with everyone else whose advertising ID is also disabled."
Where this goes next, if the last five years are a guide
I don't think the interesting question is whether military phones are now safer. Zach Edwards of Decryptads told Reuters the MAID restrictions are "definitely a positive thing" while noting personnel "might still be tracked through apps in other more complicated ways," which seems right to me. The interesting question is what a bipartisan group of 14 lawmakers does once the Pentagon has done the easy part.
Look at what they asked for in May, per Defense One: disable ad IDs on all government phones, issue guidance for personal devices used overseas or on bases, rip Google's browser off Pentagon devices, and pre-install browsers with ad blocking and Global Privacy Control turned on by default. Two of those four asks are aimed at the ad industry's plumbing, not at the military. Wyden's line to TechCrunch this week, that personal devices "could still expose service members and facilities to attacks," is him keeping the pressure on.
From what I've seen, regulatory attention on location data has moved in a fairly predictable sequence. First it's brokers (Gravy, Venntel, Mobilewalla). Then it's the platforms that let brokers ingest bidstream. The buyers come last, and mostly get hit through contract terms and audit obligations rather than fines. The IAB's own advertiser guide to the Multi-State Privacy Agreement already tells brands that state law requires "reasonable and appropriate steps" to ensure ad tech partners use personal data lawfully, including audit provisions in contracts. Most brands I've encountered signed that and never used it.
My prediction, with a number attached: by the end of 2027, at least one major DSP strips precise latitude and longitude from open-exchange bid requests by default, and the rest follow within a year of that. I'd put it at roughly 60% odds. When a data type gets described in a congressional letter as an input to missile and drone targeting, the exchanges will find it a lot easier to just drop the field than to defend it.
And to be fair, none of this is entirely new. The Strava heat map exposed base layouts in 2017. The Pentagon banned geolocation apps in operational areas in 2018. What's different now is that the threat is confirmed, the ad-tech pipeline is named in the record, and the fix that got applied was an ad-industry setting.
The vendor audit I'd run before someone makes you
You can do this in about 30 minutes with an email and a spreadsheet, and it's the kind of thing that looks very smart in six months.
First, list every vendor that touches location in your stack. DSP, any "foot traffic" or store-visit attribution partner, any audience provider selling you "people who visited X." For each one, ask three questions in writing: Is your location data sourced from bidstream, SDK, or both? Do you maintain a sensitive-location suppression list, and does it include military installations? Can you show me, per campaign, the share of impressions where you received precise lat/long versus IP or zip-level data?
Set a benchmark for the answers. A vendor that can't tell you their sourcing mix within five business days is one I'd pause, at least for anything using precise location. A vendor whose suppression list doesn't mention military installations hasn't read the Gravy order, which is a bad sign for what else they haven't read.
Second, run the substitution test you've probably been putting off. Take your best-performing geofenced campaign and clone it with the precise-location layer removed, substituting zip-level or contextual targeting (retail-adjacent content, local news, weather). Run both for two weeks. If cost per acquisition on the substitute lands within 15% of the geofenced version, you have your answer, and you can turn off the riskier line item before anyone asks you to. In most cases I've seen, the gap is smaller than the vendor deck implies. Sometimes there's no gap at all, which is a slightly uncomfortable thing to learn about a line item you've defended in three budget reviews.
Third, actually use the audit clause. If you're operating under the MSPA or a similar state-law framework, request the downstream use documentation from your largest location partner once. You don't need to find anything. You need a paper trail showing you looked, which is what "reasonable and appropriate steps" tends to mean when a regulator asks.
This is the same discipline we argued for in the Semrush-versus-Similarweb traffic fight: two vendors, same question, wildly different answers, and the only fix is to interrogate the methodology instead of picking the chart you like.
The setting the Pentagon flipped was yours
I keep thinking about how small the fix was. Every branch of the military spent months getting to a toggle that Apple and Google buried in a privacy menu years ago, and the reason it mattered enough to escalate to Congress was that the data flowing out of that toggle ends up in an auction. Our auction.
Precise location targeting probably doesn't disappear. It becomes a premium, consented, SDK-sourced product with a paper trail, and the cheap bidstream version that most geofencing quietly runs on gets a lot harder to justify. The teams that figure out how much of their location spend actually needed the precision, before the exchanges make the decision for them, are going to have a much calmer 2027.
Notice Me Senpai Editorial