The U.S. military has disabled advertising identifiers across a range of government phones and computers after U.S. Central Command reported that adversaries had used commercial location data to target or surveil personnel in theater.[1][3] The Air Force told Senator Ron Wyden that it disabled the identifiers on computers and mobile phones in July. Special Operations Command said it had recently disabled them on Windows systems. The Army said its mobile-device defaults changed by February, while Windows advertising IDs had been blocked since before 2021.[3]
This revisits California’s attempt to turn data-broker deletion into public infrastructure. That system addressed the civilian burden of finding and deleting hidden dossiers. The new development is a materially different consequence: commercially assembled location trails entered military threat reporting, and device configuration became part of force protection.
a consumer identifier crossed into operational security
Advertising identifiers were designed as replaceable handles for measurement and targeting. Google describes its advertising ID as a unique, resettable, deletable identifier supplied by Google Play services.[8] Apple says its IDFA is commonly used to track activity across companies’ apps and websites for advertising, measurement, or sharing with data brokers.[7]
That sounds narrower than a phone number or an account login. The power arrives through correlation. An identifier can join app events, ad impressions, location observations, device attributes, and repeated visits without requiring a broker to know a person’s name at collection time. Home, workplace, base, hotel, route, and repeated co-location can make the pseudonym legible later.
CISA now describes the chain in unusually direct terms. Device and app activity exposes interests, associations, whereabouts, and “pattern of life.” Data brokers compile those observations into profiles available for purchase, and threat actors can use them for targeted campaigns or physical harm. CISA’s recommended first move is blunt: disable the device’s advertising ID.[6]
The May 28 congressional letter provides the military consequence. It quotes USCENTCOM reporting “multiple threat reports” involving adversary exploitation of commercial location data against U.S. personnel. The same attachment said personal smartphones remained permitted in the area of responsibility, geolocation restrictions varied with force-protection conditions, and disabling location features did not always fully disable collection on commercial products.[1]
the fix arrived as fleet configuration
The September disclosures matter because they move the response from advice to administration. Telling personnel to inspect privacy menus leaves a security control dependent on thousands of people finding the right switch across operating systems and versions. A mobile-device-management policy can enforce a default, measure coverage, and keep the setting from drifting after replacement or reset.
Apple already supports the relevant management boundary. If a managed configuration profile limits tracking, apps cannot access IDFA through the normal permission path.[7] Android lets a user delete the advertising ID, after which API requests receive zeros, and Google documents enterprise-relevant policy around its use.[8] Windows exposes its own advertising ID control. The Pentagon did not need a new cryptographic primitive. It needed consistent fleet policy across phones and computers.
The reported rollout was fragmented. Reuters says the military branches disclosed different implementation dates and device classes, with some responses omitting dates. Special Operations Command described a recent Windows change, while the Army’s Windows restriction predated its mobile defaults by years.[3] That variation turns a simple switch into an inventory problem: which service, operating system, ownership model, management server, and deployment context actually received the policy.
The chronology before April comes from the May letter’s account of government briefings, public reporting, and a 2024 investigation. The current device changes come from branch responses and statements reported by Reuters.[1][3]
disabling the join key contains one path
Turning off an advertising identifier is useful because it damages a common join key. Reuters quoted privacy-adtech researcher Zach Edwards saying the change should keep managed devices out of many bulk sales, while warning that apps can still combine device characteristics, network data, and location information through other methods.[3] Google’s own documentation allows apps without an advertising ID to use persistent or proprietary identifiers for some purposes, subject to policy and privacy law.[8]
Personal phones remain the uglier boundary. The government can configure equipment it owns. A service member’s private phone carries personal apps, accounts, carrier relationships, SDKs, and consent history that sit outside the managed fleet. The May letter requested a policy for personal devices brought to facilities or overseas deployments, alongside fleet controls and data-broker deletion requests.[1] TechCrunch reported that personal devices used around bases could continue exposing personnel and facilities even after government hardware received the setting change.[4]
That leaves three separate jobs. Reduce collection on every relevant device. Prevent vendors from transferring data generated around military people and places. Remove or suppress records that have already entered broker inventories. The first is configuration. The second is procurement and platform policy. The third needs the deletion machinery discussed in the earlier California post.
the market remains available to both sides
The market contradiction is structural and documented. The May letter says Defense Department components have purchased commercial location data, including domestic data, while the department was trying to protect its own personnel from the same market.[1] Government buyers may value the reach and speed of broker datasets. Their purchases also sustain an industry whose inventory can be sold, leaked, stolen, or resold to actors with different objectives.
No device setting can repair that market by itself. Advertising-ID suppression narrows fresh collection from compliant apps. App permissions can reduce location access. Browser defenses can cut web tracking. Vendor contracts can restrict onward transfer. Broker deletion can remove some historical records. Each control touches a different point in the chain, and each has exceptions.
The military rollout provides a useful admission without requiring anyone to accept a broad ideological claim about advertising. A mechanism sold as ordinary monetization created enough physical risk that security administrators began disabling it across managed fleets. The product category changed at the moment a purchasable profile could describe where personnel gathered and how they moved.
The next useful public evidence will be operational: fleet coverage by service and platform, enforcement on replacement devices, treatment of contractors and personal phones, vendor restrictions, broker-removal participation, and tests for alternate identifiers. A policy memo says what should happen. Device telemetry and procurement records can show whether the commercial data trail actually thins.
Sources
[1] https://www.wyden.senate.gov/imo/media/doc/wyden_led_letter_to_dod_cio_kirsten_adavies.pdf | Lawmakers letter to DoD CIO on advertising IDs [3] https://www.usnews.com/news/top-news/articles/2026-09-04/exclusive-us-military-turns-off-ad-trackers-on-devices-amid-middle-east-targeting-reports | Reuters: US military turns off ad trackers [4] https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks | TechCrunch: US military disabled ad tracking [6] https://www.cisa.gov/resources-tools/training/limit-your-digital-footprint | CISA: Limit Your Digital Footprint [7] https://support.apple.com/en-us/102420 | Apple: App Tracking Transparency [8] https://support.google.com/googleplay/android-developer/answer/6048248?hl=en | Google: Advertising ID