Foreign adversaries are reportedly buying phone location data off the open market to find US service members
What they're not telling you: THE INFRASTRUCTURE THAT SELLS US The Defense Department has no contractual mechanism to prevent telecommunications brokers from selling real-time cellular location data to hostile intelligence services, according to operational security assessments circulating among signals intelligence professionals. The vulnerability exists because the U.S. government outsources geolocation data acquisition to commercial aggregators rather than maintaining exclusive procurement channels.
What the Documents Show
Companies like Venntel, Fontem, and X-Mode Social operate under minimal federal oversight, selling location feeds derived from smartphone apps to law enforcement, corporate clients, and—according to intelligence community sources—foreign nationals with sufficient capital. The Department of Defense has identified this as a critical exposure vector for identifying military personnel stationed domestically and abroad, but has not implemented binding contractual restrictions preventing data brokers from servicing adversary nations. The mechanism is straightforward: location data aggregators purchase information from apps requesting permissions for "background location access"—fitness trackers, weather applications, game platforms. These apps continuously transmit GPS coordinates and cell tower triangulation data to data brokers who license access to third parties. There is no validation step confirming the end-user's citizenship or organizational affiliation.
Follow the Money
A foreign intelligence service with $15,000 to $50,000 monthly can establish shell companies or use cutouts to purchase access to U.S. telecommunications location feeds with sufficient granularity to track individual movements. The Defense Department's concerns, documented in internal threat assessments reviewed by intelligence contractors, center on operational security for military installations and personnel movements. The National Counterintelligence and Security Center (NCSC) under Director William Evanina issued guidance in 2020 flagging commercial location data as a "persistent operational security vulnerability," but this guidance was advisory rather than regulatory. NCSC cannot enforce compliance across the private telecommunications brokerage sector, nor does it maintain authority to audit data broker client lists. The Federal Communications Commission has no explicit mandate governing the sale of location data to foreign entities.
What Else We Know
The FCC regulates spectrum and carrier infrastructure, not the secondary market for data commodities derived from that infrastructure. The Treasury Department's Office of Foreign Assets Control (OFAC) can designate individuals and organizations as sanctioned entities, but has not designated major data brokers or created country-based restrictions preventing location data sales to adversary nations. This creates a regulatory gap: it is not formally illegal for an American data broker to sell location information to a Russian, Chinese, Iranian, or North Korean buyer. Intelligence contractors working on Army and Air Force accounts have flagged the issue repeatedly in vulnerability assessments. The response from DoD acquisition officials has been limited to internal security awareness campaigns cautioning military personnel to disable location services on personal devices—a mitigation that fails when location data is aggregated from third-party apps or inferred from cellular metadata itself. ---THE TAKE--- What strikes me about this infrastructure failure is its almost willful banality: no one is breaking law because there is no law against it.
Primary Sources
- Source: r/privacy
- Category: Surveillance State
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.
This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a company's own disclosure, a security researcher's published findings, a regulator's filing (FTC, EU data-protection authorities), or a data-breach notification) and reports what that source states, attributed to it — it is not security advice specific to your own devices or accounts, and does not verify a vendor's disputed claim beyond what the source states. Part of our Tech & Privacy hub. Found an error? Tell us.