During the Iran war, the U.S. military relocated many personnel from bases to hotels and civilian offices. A recent Financial Times report reveals that Iranian forces exploited ad tracking data to identify these locations, particularly in Iraqi Kurdistan, where Iranian-backed militias attacked hotels housing American troops using drones. Additionally, Iranian forces bombed the Crowne Plaza in Bahrain, injuring two Pentagon employees.

Byron Tau, author of a book exposing these intelligence practices, told Reason in 2024, "Any government with a halfway decent cyber intelligence program is participating in these [ad data] exchanges, because it's such an immensely valuable source of data."

The U.S. government has previously used private ad data to circumvent the Fourth Amendment and track Americans without warrants. However, this data has now been weaponized by foreign adversaries to hunt American soldiers.

Past incidents illustrate similar vulnerabilities: In 2017, Strava released a global heatmap revealing military base locations and troop movements, prompting the Pentagon to ban geolocation fitness apps. In 2021, Bellingcat used public flashcard app data to map U.S. nuclear weapons in Europe. Moreover, Muslim Pro, an Islamic prayer app, sold user data to a broker until 2020, unaware that the data was passed to the U.S. military; the app severed this relationship immediately after discovery.

These events underscore the complex security challenges posed by digital data in military and intelligence operations.

Sources