The change was not a routine privacy update. It came after reports that foreign adversaries, including Iran, were buying commercially available location data from data brokers to identify and target US military personnel deployed in the Middle East. If that sounds abstract, here’s the plain version: someone with a credit card and a browser was able to reconstruct where American soldiers were, in near-real-time, from the same advertising infrastructure that powers the ads on your morning news feed.
What the Pentagon Actually Did
Every service branch confirmed to Senator Wyden that mobile advertising identifiers, commonly called MAIDs, have been disabled by default on their government-issued devices. According to a Reuters exclusive that first reported the story, the Army said advertising IDs had been blocked on Windows computers since before 2021, but the equivalent protection on Android and Apple mobile devices only rolled out “since at least February 2026.” The Air Force disabled them about two months ago. Special Operations Command described its rollout as “recent.” The Navy and Marines confirmed the changes but did not give a timeline.
A MAID is a unique identifier assigned to each individual phone or tablet, used across mobile apps and websites to build a persistent profile of the device’s owner. Data brokers buy these identifiers in bulk from advertising exchanges, link them to physical locations by cross-referencing app telemetry, and then resell that combined dataset. The result is a searchable map of where a specific device has been, when, and how often. On a normal consumer phone, the identifier is on by default the moment the device is unboxed.
Why the US Military Decided This Was Serious
Senator Wyden’s letters, sent alongside Representative Pat Harrigan of North Carolina, followed months of pressure on the Pentagon over the security risks posed by commercially collected location data. Harrigan’s framing captured why the issue crossed party lines: US enemies should not be able to pull out a credit card and buy information that helps them track American troops. The bipartisan concern is that the exact commercial infrastructure that powers ad targeting, MAIDs combined with location data, is available to anyone willing to pay for it, including hostile nation-state actors.
Reuters reported earlier this year that adversaries in the Middle East had used similar data to track US personnel. Wyden’s statement went further than the Pentagon’s own communications, calling the military’s efforts to date insufficient at neutralizing the threat. Zach Edwards, co-founder of the privacy firm Decryptads, called the move a positive step but noted that personnel can still be tracked through other technical channels. In other words, disabling the MAID closes the biggest and most obvious commercial pipeline, but it doesn’t eliminate the underlying market.
What a Mobile Advertising ID Actually Reveals About You
The story reads like a national security piece, but the mechanism it describes is exactly the one operating on every civilian smartphone in the country. A MAID doesn’t just show which apps you use. It correlates with GPS coordinates from apps you’ve granted location permission to, network identifiers from Wi-Fi hotspots you connect to, and behavioral signals collected by the ad tech ecosystem. Data brokers stitch those inputs into a timeline of movement that is often precise enough to identify home, workplace, gym, place of worship, and travel patterns down to the hour.
That data is not hypothetically available. It’s actively bought and sold. Government agencies purchase it without needing warrants, private investigators purchase it in support of stalking cases, foreign intelligence services purchase it, and advertisers purchase it to target specific individuals or households. The commercial market for MAID-linked location data is estimated in the billions of dollars annually, and the barrier to entry is a credit card and a data broker account.
Why This Applies to You, Not Just Soldiers
The Pentagon’s calculation is that a soldier deployed to a war zone is a high-value target whose location must be protected. That framing understates how transferable the risk is. Every civilian who has ever been targeted for phishing, for extortion, for physical stalking, for insurance discrimination, or for political profiling is exposed through the same MAID-driven pipeline. The military’s decision was to remove the identifier by default. That option is available to you as well, and it’s what the Pentagon effectively did on behalf of its own personnel.
There are two practical layers to close: the identifier at the operating system level, and the network traffic at the connection level. Turning off the advertising identifier on your iPhone or Android device is a settings toggle, and it should be the first step. But it addresses only the identifier itself, not the underlying tracking scripts, phishing domains, and cross-app fingerprinting that continue to operate independently. That’s where a network-level defense becomes necessary, and that’s where NordVPN‘s Threat Protection Pro fits into the same defense strategy the Pentagon just enacted.
Where NordVPN Fits, and Why It Handles Exactly This
NordVPN’s Threat Protection Pro, included in the Advanced and Ultra plans, operates on the same principle the Pentagon applied to its troops: block the tracker before it can collect the data. The feature maintains continuously updated lists of known ad tracking domains, cross-app fingerprinting scripts, and phishing infrastructure, and it blocks connections to them at the network layer. That means the tracking pipeline is severed before your device even attempts the request, regardless of which app or browser triggered it.
The core VPN layer adds the second protection. When your device connects through NordVPN, your traffic exits from a NordVPN server IP address rather than your own. Data brokers correlating location signals across sessions lose the ability to link your activity back to a fixed home IP, which breaks the profile that MAIDs and IP addresses together allow. NordVPN also operates under a no-logs policy that has been independently audited multiple times, which is part of why it consistently appears near the top of most best VPN comparisons focused on privacy-first architecture rather than just streaming speed.
Get NordVPN With Threat Protection
NordVPN Basic at $3.49 per Month
NordVPN’s Basic plan is currently available at $3.49/month, which works out to $94.23 billed once for 27 months of service (24 + 3 free). That is a 69% discount off the standard rate. Annual renewal continues at $139.08/year, cancelable from the account dashboard at any time.
The Basic plan covers the core VPN across up to 10 devices with applications for Windows, macOS, Linux, iOS, Android, browser extensions, and router installation. Threat Protection Pro, the feature most directly relevant to the tracker-blocking use case that motivated the Pentagon’s decision, sits in the Advanced and Ultra tiers rather than in Basic. If cutting off the ad tracking pipeline is the main reason you’re signing up after reading this, the higher tiers are the ones that actually deliver on the promise.
Get NordVPN Basic at $3.49/month
30-Day Money-Back Guarantee
NordVPN backs every plan with a 30-day money-back guarantee. If the service doesn’t fit the way you use your devices, you can request a full refund within the first month. Refunds are processed through 24/7 chat support, and funds typically return within 5 to 10 business days depending on the payment method used.
That gives you a full month to install the apps across your setup, test the speeds on your home connection, run the tracker filter against the actual traffic hitting your devices, and see whether the service holds up before the refund window closes. A note on the subscription: the $3.49/month rate applies to the first 27 months. Auto-renewal kicks in at the standard annual rate after that. If you would rather cancel or renegotiate before renewal, set a reminder in your calendar 7 to 10 days before the renewal date.