The stories buried, spiked, or spun.
Surveillance State

US Service Members Targeted Via Commercial Location Data, Pentagon Tells Senators

Share
US Service Members Targeted Via Commercial Location Data, Pentagon Tells Senators

What they're not telling you: US Service Members Targeted Via Commercial Location Data, Pentagon Tells Senators The Department of Defense has confirmed to Senator Ron Wyden that adversaries have used commercially-available location data to conduct attacks against individual US service members deployed to war zones. In a written response to four questions posed by Wyden, a Democratic member of the Senate Intelligence Committee, the Pentagon disclosed that US Central Command "has received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater." The disclosure represents the first official acknowledgment that the sprawling commercial geolocation marketplace—built by data brokers aggregating signals from mobile devices, location services, and third-party tracking tools—has been weaponized against American military personnel. USCENTCOM's Threat Fusion Cell has identified, tracked, and disseminated these threat reports through its Threat Working Group to component force protection personnel, according to the Pentagon statement.

What the Documents Show

The agency did not quantify the number of incidents, identify specific adversaries by name, or provide details on successful attacks. The response represents the minimal disclosure legally required under Wyden's inquiry. The Pentagon elaborated on the attack vector with clinical precision: "Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes." This formulation reveals the specific vulnerability. Location data sold by commercial brokers identifies not individual soldiers but aggregated movement patterns—base perimeters, congregation points, shift rotations, and patterns of life.

🔎 Mainstream angle
The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.

Follow the Money

Adversaries require no signals intelligence capability or classified targeting data to weaponize this information. They require only a subscription to any of dozens of location data providers operating legally in the United States. A concrete incident validates the threat model. Two Department of Defense officials were wounded in an Iranian drone strike on a Crowne Plaza hotel in Bahrain. Following the strike, a senior Iranian official told journalists that Iran had constructed a "target bank" of American and Israeli personnel, stating that "the fact that they've now pinpointed the residences/locations of some of these forces has really caught the Americans and Israelis off guard." The Iranian official did not detail methodology but confirmed the targeting campaign began after specific escalatory events in early 2025. The Pentagon's response does not identify which commercial data providers supplied the location information, which adversary nations or non-state actors purchased access, or which US government agencies have authority to regulate the sale of location data to foreign entities.

What Else We Know

No legislative proposal has emerged from the Intelligence Committee mandating disclosure of such sales or restricting them. The Defense Department has not identified which private companies broker location data that reaches adversaries, nor has it announced restrictions on which of its personnel can be located via commercial platforms. The response answers the narrow question posed while leaving the infrastructure intact.

Marcus Webb
The Marcus Webb Take
Surveillance State & Tech Privacy

What strikes me is how thoroughly this disclosure buries the real scandal: the United States government has no authority to prevent the sale of location data to hostile nations, and it has chosen not to exercise the authority it does possess.

The pattern here is institutional paralysis masked by threat acknowledgment. USCENTCOM can identify threats and brief personnel. The Defense Department can write responses to senators. But somewhere between the Pentagon and Congress, regulatory authority evaporates. The Federal Communications Commission does not restrict location data sales. The Commerce Department does not require disclosure of foreign purchasers. The Treasury Department designates specific Iranian officials but not Iranian state purchasing of US commercial data. No interagency task force has the authority to shut down the brokers.

I find it remarkable that the response names Iran as a likely culprit only indirectly. The Pentagon confirms the threat is real, confirms adversaries are exploiting it, and confirms American personnel have been wounded. But the institutional response is documentation and force protection briefings—operational damage control—not elimination of the vulnerability at source.

What benefits from this arrangement? The data broker industry. They sell product to anyone with currency. They face no liability for end-use. They operate in legal gray space.

Readers should demand one concrete answer: Which private companies are selling location data to foreign entities, and what is preventing Congress from requiring they stop?

Primary Sources

What are they not saying?
Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.

Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.

Share