The Pentagon Knew Enemies Could Track Troops' Phones for Years. Now They Are.
Cheap fixes existed. The military ignored them. Adversaries didn't.
Written by OutOfToken AI
June 6, 2026 · 4 min read · Synthesized from reporting by Wired · How this works
For years, defense officials received detailed warnings: the same commercial location data that powers targeted ads could be purchased by hostile actors to track American soldiers in real time. The fixes were neither classified nor expensive. The Pentagon adopted almost none of them. Now, according to reporting from Wired, adversaries are actively exploiting that negligence to locate and target U.S. troops during active conflicts.
A Known Vulnerability, Willfully Ignored
The mechanics of the threat are not subtle. Data brokers harvest precise GPS coordinates from smartphone apps — fitness trackers, weather utilities, mobile games — and package that information into feeds sold openly on commercial markets. Researchers and intelligence officials have flagged this pipeline as a national security liability since at least the early 2020s. Investigations demonstrated that devices could be traced inside sensitive installations, including Büchel Air Base in Germany, where U.S. nuclear weapons are believed to be stored in hardened bunkers. Reporters watched device pings move through restricted perimeters in near real time using nothing more sophisticated than a commercial data subscription. The Pentagon was briefed. Policy responses were drafted. Enforcement was minimal.
What Cheap Fixes Actually Look Like
The countermeasures experts have long recommended require no exotic technology. Prohibiting personal smartphones in and around sensitive operational areas is the most direct. Mobile Device Management platforms can geo-fence applications that transmit location telemetry. Mandatory operational security training — updated to address the specific risks of commercial data brokers, not just traditional signals intelligence — costs almost nothing to implement at scale. Some units have introduced these controls informally, but DoD-wide policy has remained fragmented, with enforcement varying widely by command and theater. The gap between what is technically achievable and what is institutionally practiced has remained enormous, and that gap is now being measured in casualties.
"Adversaries don't need to compromise a military network. They can buy the same location feed a retail advertiser would — and point it at a forward operating base."
A Market Structure Built for Exploitation
The deeper problem is structural. The U.S. data broker industry operates with minimal federal oversight, meaning the same commercial pipelines available to a lifestyle brand targeting sneaker buyers are theoretically accessible to foreign intelligence services and non-state actors with modest budgets. Congress has periodically examined legislation that would restrict data broker sales to entities flagged as national security risks, but comprehensive reform has stalled repeatedly. The Federal Trade Commission has taken enforcement actions against specific brokers for deceptive practices, but those cases address consumer harm, not counterintelligence exposure. The military has no formal authority to regulate the commercial data ecosystem — it can only attempt to manage its own personnel's digital footprint, a task it has demonstrably failed to prioritize.
The situation is a textbook case of institutional inertia colliding with an accelerating threat. The technology to exploit location data has grown cheaper and more accessible every year; the bureaucratic urgency to counter it has not kept pace. With adversaries now reportedly using commercial data feeds to actively target soldiers in the field, the Pentagon faces pressure to treat this not as an abstract future risk but as an ongoing operational failure demanding immediate, enforceable policy — before the cost in lives becomes impossible to ignore.
Editorial Note
Wired is a reputable technology publication with strong investigative journalism credentials. The claim aligns with well-documented security vulnerabilities in military smartphone use and publicly reported concerns from cybersecurity experts about OPSEC failures. However, specific details about adversary exploitation during ongoing conflicts would require access to classified assessments that cannot be independently verified.
Claim Tracker
AI-assessed
Article asserts this but does not provide specific dates, officials named, or documentation of warnings
Claim about nuclear weapons storage at Büchel is widely reported; the specific tracking demonstration through commercial data is attributed to reporters but not independently verified in excerpt
Well-documented industry practice confirmed by multiple security researchers and regulatory investigations
Attribution claim; article cites 'reporting from Wired' and unnamed adversaries but provides no specific incidents, timeframes, or damage assessment
Security researchers published warnings; intelligence official warnings are asserted but not documented in excerpt
Ask AI about this story
// discussion
sign in to join the discussion