RSS Amplifier

Project OSINT · Jul 24, 2026

Ad Auctions as a Weapon: How Iran Allegedly Used Tracking Data to Locate U.S. Troops

0
Sign in to vote or save

Project OSINT · Project OSINT

A soldier doesn’t need to post his location online for an adversary to find him. He just needs a phone with an ad-supported app running in the background — and someone on the other end willing to buy the bid stream.

That is the scenario now under scrutiny after a Financial Times investigation, reported on by Matthew Petti for Reason, into how Iran may have used commercial advertising data during its recent conflict with the United States to track American military personnel who had been moved out of their bases and into hotels and civilian offices in the region.

When U.S. forces evacuated several bases during the war, personnel were redistributed into hotels and civilian buildings across the Middle East, including in Iraqi Kurdistan and Bahrain. According to the Financial Times report, investigators suspect that in at least one instance in Iraqi Kurdistan, Iranian-aligned forces used advertising-tracking data to identify which hotels were housing U.S. troops. Iran-backed militias then struck several hotels in the region with drones, and Iranian forces bombed the Crowne Plaza in Bahrain directly, wounding two Pentagon employees. It remains unconfirmed which specific strikes, if any, were guided by ad-data targeting rather than other intelligence methods.

Byron Tau, the journalist whose reporting first exposed U.S. government use of commercial ad data to sidestep Fourth Amendment protections, told Reason in 2024 that any government running a competent cyber-intelligence program participates in this data trade, calling it an extraordinarily valuable source. The mechanism he described — governments buying access to advertising data that was never meant for intelligence use — is the same one now allegedly being turned against the personnel it once helped track.

The ad-tracking angle was not the only intelligence vector identified. The Financial Times report also documented use of Signaling System No. 7 (SS7), the protocol telecom carriers use to locate roaming phones internationally. An Iranian telecom operator reportedly sent a series of SS7 “pings” toward Arab countries, and Senator Ron Wyden told the Times that the Department of Homeland Security was aware Iran was using this method to locate American phones.

The mechanism described in the reporting maps onto a replicable technical chain — the same chain any analyst studying ad-tech exposure would need to trace.

  1. App-level data leakage. A phone runs an ordinary app — a fitness tracker, a prayer app, a game — that requests location and device-identifier permissions for advertising purposes. Precision here matters: the app doesn’t need to be built for surveillance, only to be ad-supported.

  2. Real-time bidding (RTB) exposure. When the app serves an ad, it broadcasts a bid request onto an RTB exchange — the auction system that lets advertisers compete for that specific ad slot. That request bundles location, device ID, and behavioral attributes into a single package visible to every bidder on the exchange, not just the winner.

  3. Demand-side platform (DSP) aggregation. Buyers use DSP software to place automated bids on these requests. Data brokers can sit inside this layer, harvesting the bid stream itself rather than actually buying ads — a use most RTB exchanges explicitly prohibit in their terms of service, but one the FTC’s own enforcement record shows is not reliably policed.

  4. Aggregation into a location pattern. A single bid request reveals one moment. Repeated requests, tied to a persistent device identifier, reveal a pattern — which hotel a phone returns to every night, for instance. This is the step that converts ad exhaust into targetable intelligence.

  5. Cross-validation against other signals. The Financial Times reporting notes that SS7 telecom pings and, more mundanely, social-media posts and human sources were also in play. In several Middle Eastern countries, which hotels housed U.S. troops was described as widely known locally. This matters methodologically: ad-data targeting, if it occurred, likely functioned as one corroborating layer among several, not a standalone targeting system.

  • Ad-supported apps are a location-disclosure risk independent of intent. Strava’s 2017 heat map and the flashcard-app exposure of U.S. nuclear personnel, later mapped by Bellingcat, show this isn’t hypothetical — it has already happened through completely unrelated apps.

  • RTB bid streams are a data source, not just an ad mechanism. Anyone conducting OSINT work involving device or location data should treat the ad-bidding layer as its own leak vector, separate from the app’s stated function.

  • Broker-level terms-of-service violations are hard to detect from outside. The FTC’s action against Mobilewalla for scraping RTB auctions in violation of exchange rules shows enforcement is reactive, not preventive — and that same settlement carved out an exception for geolocation data collected outside the U.S. for national-security purposes, which is worth flagging in any analysis of this ecosystem.

  • User-facing controls are emerging but narrow. Google’s new RTB Control setting, introduced after a user lawsuit, lets individuals limit what reaches ad auctions — a mitigation, not a fix, since it depends on adoption by the same population least likely to know the risk exists.

  • Attribution in this case remains unconfirmed. The Financial Times report raises the ad-tracking hypothesis; it does not establish which specific attacks, if any, were guided by it. Any downstream reporting or analysis should preserve that distinction rather than treat suspicion as confirmation.

  • Matthew Petti, “Iran Allegedly Used Ad Tracking to Hunt U.S. Soldiers,” Reason

  • Financial Times investigation into ad-data use during the Iran conflict (as cited in the Reason report)

  • Byron Tau’s reporting on U.S. government use of commercial ad data

  • Bellingcat’s 2021 investigation into flashcard-app data and U.S. nuclear-weapons locations

  • FTC settlement with Mobilewalla on unauthorized RTB data collection

The version of this story that should concern analysts isn’t the sophistication of the tradecraft — buying access to an ad exchange is not exotic. It’s that the infrastructure was never built for this, was adopted by militaries anyway, and is now available to whoever else decides to buy in. Anyone tracking similar cases, or with documentation on other ad-data targeting incidents, is welcome to send it in for the next installment of this series.

If this is useful, share it.

This is the weekly selection. But it’s not the only one.

If you’d like to read more: → full articles on the website

👉 https://projectosint.com

If you’d like to get the latest updates first: → Telegram

👉 https://t.me/osintprojectgroup

Read the original on projectosint.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.