F-35B USS Boxer
A U.S. Marine Corps F-35B Lightning II conducts flight operations aboard USS Boxer (LHD 4), April 2026. Photo: U.S. Marine Corps/DVIDS (Public Domain)

The Pentagon announced this week it has finally disabled advertising trackers on government-issued phones and computers across every branch of the U.S. military. The mobile advertising ID — the tiny piece of code that lets data brokers follow a single device across every app it touches, map where it sleeps, where it works, where it travels, and sell that information to anyone with a credit card — has been shut off.

This should have happened years ago. It did not. People may have died because of that failure. We want to know who is responsible.

This is not a surprise problem that emerged from nowhere. The warnings have been documented for nearly a decade. In 2018, fitness app Strava published a global heat map of user activity that inadvertently revealed the layouts and patrol routes of secret U.S. military bases in Syria, Afghanistan, and Africa. The Pentagon scrambled. Nothing changed. In 2021, the Wall Street Journal reported that a U.S. military contractor demonstrated it could reconstruct American military operations in real time using nothing but commercially available app data from soldiers’ phones. The Pentagon took note. Nothing changed. In 2024, Wired magazine showed that the same commercial data streams could pinpoint U.S. military contractors at specific overseas locations — including, humiliatingly, German brothels.

Still nothing changed.

Then came the Iran war. And the cost of that inaction became impossible to ignore.

Meanwhile, Russia has been blowing up Ukrainian troop locations using cell phone data since early in the current war. Another data point that should have been seen and acted upon.

U.S. Central Command confirmed in April 2026 that it had received multiple threat reports of adversaries actively exploiting commercial location data to track American personnel in theater. The Financial Times reported that actors linked to Iran had abused advertising databases to track American phones in Iraqi Kurdistan. Iran-backed militias struck hotels in Iraq, Bahrain, and across the Gulf, injuring American personnel and contractors. In July, Admiral Brad Cooper — the head of CENTCOM — sent a letter to troops under his command warning them that Iran was using their own cellphone videos to assess the accuracy of its missile and drone strikes. His words deserve to be read slowly: the cost of this open-source intelligence failure, he wrote, “could be measured in the lives of American service members and civilian residents in targeted Gulf countries.”

Could be measured in lives.

And as of August — during an active shooting war with Iran — U.S. troops at targeted bases were still posting their running routes on Strava. Precise GPS tracks. Daily patterns. Publicly visible. While Iran was trying to kill them.

In other words, the solution to this problem existed for a long time. The military had been informed of the threat. It cost nothing to fix the problem. And yet for years, and now during wartime, the military failed to take this simplest of steps to protect the lives of its service members. Instead, their lives were put in danger by the actions of enemy forces who were able to use a credit card to purchase location information about American service members.

The lack of adherence to policy and procedures by senior military officials and civilian management on the issue of tracking military personnel using mobile advertising data is scandalous. Someone in the chain of command — multiple someones, across multiple years and multiple administrations — looked at all of that evidence and did not act. The individual or individuals responsible must be identified. They must be relieved of command — not reassigned, not retired with full benefits, relieved. The families of anyone killed or wounded in attacks that may have been enabled by this negligence deserve nothing less.

Sen. Wyden said even now the military’s efforts “have not been effective at neutralizing this threat” because personal phones carried onto bases by troops and contractors remain unprotected. Rep. Pat Harrigan said it plainly: U.S. enemies “should not be able to pull out a credit card and buy information that helps them track American troops.” He is correct. And the fact that they could — for years, including during wartime — means someone failed in their fundamental duty to protect the men and women under their command.

The investigation by the Pentagon’s inspector general requested by Sen. Wyden and Rep. Harrigan must be conducted and released publicly. All those who received the warnings, read the evidence, and failed to act must be identified and relieved of command. A press release is not accountability. We demand better. And we will keep demanding it until someone answers.