The fix sounds complete. Reuters reported on September 4, 2026 that the US Army had disabled advertising-ID tracking by default on the Android and Apple phones its personnel carry, extending to mobile a policy that had already applied to military-issued Windows computers since before 2021. Read the announcement on its own and the story is simple: a known privacy hole, patched.
It is worth slowing down on why the mobile fix mattered enough to make news in the first place. On April 14, 2026, US Central Command told Congress in a written response to Senator Ron Wyden's office that it had "received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater" during Operation Epic Fury in the Middle East. That is the incident the ad-ID fix is a response to. And an advertising ID on an official phone is one narrow input into a marketplace that buys and resells location data from any phone, official or personal, running any app that broadcasts it for real-time-bidding ads. Switching off that one input on government-issued devices does not touch the marketplace itself.
The market the fix does not reach
The clearest evidence that the marketplace survives intact is not classified. It is for sale. A Duke University Sanford School of Public Policy research team bought sensitive, individually identified records on active-duty military members, their families, and veterans directly from US data brokers, paying as little as $0.12 per record. No hack was involved. A university team with a purchasing account could do it, which means anyone else with the same access could too.
Records on serving military personnel sold for as little as $0.12 each.
The transaction that exposed this was a legitimate purchase, not a breach. That is the structural point: the vulnerability was never about a hacker getting in. It is a retail marketplace operating in the open.
This is not the first time a data broker's location-selling business has touched the military directly, either. Senator Wyden said he discovered in 2020 that the data broker X-Mode Social, later renamed Outlogic, had sold Americans' location data to US military customers through defense contractors. The FTC did not bar Outlogic from selling sensitive location data until January 2024, four years after Wyden's discovery. The company was one broker. The broader marketplace it operated in was not touched by that single order, and it is that marketplace, not any one vendor, that CENTCOM described to Congress in April 2026.
The warning came years before the fix
The National Security Agency published DoD-facing guidance in August 2020 urging National Security System and Department of Defense device users to limit their location-data exposure. The FTC's order against Outlogic followed about three and a half years later. The Army's fleet-wide fix on mobile ad IDs followed roughly five and a half years later, about two years after the FTC had already acted against just one broker in the same market.
The Army's mobile fix trailed the FTC's action against a single broker by about two years.
Neither timeline is fast. Both had the same 2020 starting point, and the gap between them is the story: a regulator narrowed one broker's practices well before the military closed the device-level gap on its own hardware, and the marketplace that made both problems possible predates both responses by years.

What one fix cannot do
The device-level fix is real and worth doing. Blocking the advertising identifier that apps use to tag a phone for the real-time-bidding ad auction removes one direct channel through which a government-issued device's location can end up for sale. It also does not need Congress or a new regulation, which is presumably why the Army could simply do it.
But CENTCOM's own language to Congress was about "commercial location data," not about advertising IDs on official phones specifically. A soldier's location is knowable from a spouse's phone, a fitness app on a personal device, a weather app, or any of the thousands of apps that participate in real-time bidding and hand location pings to brokers as a matter of routine. None of those run on a device the Army configures. The $0.12-per-record marketplace Duke's researchers bought into does not check whether the person in a record turned off ad tracking on their government phone; it just checks whether a broker has the data and a buyer is willing to pay.
The honest objection
The strongest case for the device fix is that it closes the channel the military actually controls, and controlling what you control is not nothing. Windows machines were already covered before 2021; extending the same policy to mobile devices removes the most direct and highest-confidence leak, the one running on hardware issued and configured by the service itself. A policy that cannot regulate the entire commercial data-broker industry can still plug its own hole, and doing that well is a legitimate, achievable goal that should not be dismissed because it falls short of everything.
That case holds for the device policy on its own terms. It does not hold for the broader claim that the exposure has been addressed, because CENTCOM's threat reports were never limited to what runs on Army-issued phones, and the $0.12-a-record marketplace Duke's team bought into runs entirely outside any device the military configures. A fix that only ever touched one category of device was never going to close a market that ingests location signals from every category at once.
Why this is not just a US story
India notified the Digital Personal Data Protection Rules, 2025 on November 14, 2025, marking the full operationalisation of the Digital Personal Data Protection Act, 2023, on an 18-month phased compliance timeline. That timeline means enforceable obligations on how personal data, including location data, is collected and shared are still being phased in rather than already binding on every processor. India also runs a large mobile ad market built on the same real-time-bidding pipes that made the US case possible: an app requests an ad, the request carries a location signal, and that signal can be captured and resold by any intermediary sitting in that pipe. Nothing about that pipeline is unique to the United States or to US brokers.
The mechanism that put US troops' locations up for sale for $0.12 apiece does not require a US-specific vulnerability. It requires an ad-tech supply chain with brokers willing to buy and resell location signals and a regulatory regime that has not yet finished switching on enforcement. The DPDP Rules give India that regime on paper starting in November 2025; the compliance runway extends well into 2027. Indian defence personnel carrying personal phones through that same runway sit in a structurally similar position to their US counterparts before the FTC and the Army acted: covered by data-protection rules that exist, in a market that has not yet had to fully answer to them.

The Signal
The Army's fix is a real, narrow patch on a device category it directly controls. It is not evidence that the underlying trade in military and civilian location data has been curtailed, because that trade runs through data brokers, personal devices, and ordinary consumer apps that no single service branch's device policy touches. Watch two things from here: whether Congress moves past device-level fixes to restrict the brokers themselves, the way the FTC did to exactly one company in 2024, and whether India's DPDP enforcement, still ramping through its 18-month runway, closes the same gap before or after its own defence establishment needs it closed. A market that sells a soldier's location for twelve cents does not stop selling it because one buyer's phone stopped broadcasting.
Reporting basis: the Army's fleet-wide ad-ID policy and its 2020-versus-2026 timeline for Windows and mobile devices are per Reuters, as reported by The Spokesman-Review. CENTCOM's April 2026 statement to Congress on commercial location-data threats in the Middle East is per Senator Ron Wyden's office, which published CENTCOM's written response. The $0.12-per-record purchase of military personnel and family data is from a Duke University Sanford School of Public Policy research report. The 2020 discovery that X-Mode Social/Outlogic sold location data to military customers through defense contractors, and the FTC's January 2024 order against the company, are both per Senator Wyden's office. The NSA's August 2020 guidance on limiting location-data exposure is via CISA. India's DPDP Rules notification and its 18-month compliance timeline are per the Press Information Bureau, Government of India. The years-elapsed figures comparing the NSA's guidance to the FTC's order and to the Army's mobile fix, and the age of each cited fact as of September 2026, are The Signal's calculations from those dates.



