US Central Command rolled out the ability to switch off location sharing on government smartphones in May 2025, approximately 10 years after the first documented warning about commercial location data exposing US military personnel. The move followed multiple threat reports indicating adversaries were exploiting such data to target or surveil US personnel deployed in the Middle East.

In 2016, a government technologist at Joint Special Operations Command demonstrated how commercial location data could track phones from Fort Bragg and MacDill Air Force Base through Turkey into northern Syria, where they clustered at a covert forward operating base.

In late 2024, a free sample of location data from a Florida broker contained 3.6 billion coordinates tied to roughly 11 million phones in Germany over a two-month span. That dataset included movements of 12,313 devices passing through at least 11 US installations in Germany, including Wiesbaden Army headquarters, military schools, Büchel Air Base, and Grafenwöhr.

Earlier in May 2025, the Army instructed soldiers to use personal phones for government work. The Army claims its access is limited to a walled-off work app that leaves personal data like texts, photos, and browsing history untouched. Army researchers noted that data brokers face no such restrictions and can obtain far more detailed information.

In 2023, researchers at Duke University, working under a grant from the US Military Academy at West Point, purchased data on active-duty troops—including names, home addresses, health conditions, and financial details—for as little as 12 cents per record. Other researchers obtained geofenced data from brokers related to Fort Bragg and Quantico by posing as buyers through a Singapore-based domain. One broker offered to skip identity verification if payment was made by wire transfer.

In 2025, a bipartisan group of 14 lawmakers sent a letter to the Pentagon stating it had known about the commercial location data threat for more than a decade and failed to adopt recommended cyber defenses. The lawmakers urged Pentagon Chief Information Officer Kirsten Davies to disable advertising IDs on military phones, replace Chrome with privacy-focused browsers, and enroll service members in state data-broker opt-out systems.

A Pentagon spokesperson stated the department was aware geolocation services could put personnel at risk and urged service members to follow operational security protocols. In May 2025, the Army Cyber Institute reported that more than a fifth of the most-visited domains on the Army’s unclassified networks were commercial trackers and recommended restricting Chrome because it declined to block third-party cookies.