Skip to content
BriefingsRSS · DSI
Series · Part 27 of 62
The Chokepoint Doctrine
The Surveillance That Nobody Had to Hack
Chokepoint DoctrineJune 2, 202616 min read

The Surveillance That Nobody Had to Hack

USCENTCOM has confirmed it: US forces in active war zones have been targeted using commercial location data bought from adtech brokers. No exploit. No malware. No insider. Just a credit card and a dataset. The Pentagon was first warned in 2016, when contractor Mike Yeagley tracked JSOC personnel from Fort Liberty to a covert facility inside a Lafarge cement factory in Syria using advertising data. A decade later the institutional response has remained a guidance document telling soldiers to review their privacy settings. This DSI piece maps the chain, the reverse pattern of life tradecraft, the carrier layer nobody is regulating, and what adequate protection actually requires.

~26 min

How the global adtech industry became the most powerful intelligence collection system ever built — and why the Pentagon has known about it for a decade and done almost nothing.

No Exploit Required

There is a particular category of intelligence vulnerability that is more dangerous than a zero-day exploit, more consequential than a nation-state APT campaign, and more difficult to defend against than any attack the Chokepoint Doctrine series has previously mapped. It requires no malware. It requires no social engineering. It requires no physical access, no credential theft, no supply chain compromise, and no technical sophistication whatsoever. It requires only a credit card and a willingness to use a service that operates entirely legally in most jurisdictions.

USCENTCOM acknowledged receiving multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater. This is not theoretical anymore. Hostile actors are buying the same data that follows you from Starbucks to Target and using it to track soldiers in active war zones.

On the twenty-eighth of May 2026, Senator Ron Wyden shared with Reuters a letter from US Central Command — dated the fourteenth of April — confirming that US forces deployed to war zones in the Middle East have been targeted using commercially available location data. The confirmation was the first official acknowledgement that US forces had been targeted in an active war zone using this specific method. CENTCOM’s area of responsibility includes the Gulf, where US forces are currently facing off against the Iranian military over the Strait of Hormuz.

Commercial location data can be used to identify where US troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes. That sentence — contained in the Pentagon’s own letter to Congress — is the clearest official description of what the surveillance economy has become in the context of armed conflict. The data that a soldier’s smartphone generates while checking the weather, browsing the web, or using a fitness app is sufficient to build the pattern of life intelligence that guides missile and drone targeting. No signals intelligence operation required. No satellite imagery analysis. No informant network. Just a purchase order from a data broker whose business model depends on the same advertising revenue ecosystem that funds every free app on every smartphone currently in the pocket of every person reading this.

This article names what that means — not for the soldier, but for every organisation, every executive, every diplomat, every intelligence officer, and every private citizen whose pattern of life is now commercially available to anyone willing to pay.

The Warning That Was Issued Ten Years Ago and Ignored

The most damning element of the USCENTCOM confirmation is not the threat itself. It is the timeline.

This vulnerability was identified at least ten years ago, when tech contractor Mike Yeagley briefed the Joint Special Operations Command on how enemies could exploit commercially available phone location data to create pattern of life profiles of individual service members. Yeagley’s programme — originally called Locomotive, for location plus motive, later rebranded to VISR for Virtual Intelligence, Surveillance and Reconnaissance — was the first systematic demonstration that commercial adtech data could serve as a military intelligence collection system. Yeagley demonstrated it to JSOC by doing the thing he was warning against: he used commercial location data to track the movements of JSOC personnel themselves. The programme was said to have led to Yeagley tracking a group of soldiers from the bedroom community of a Special Mission Unit outside of Fort Liberty in North Carolina to a covert US facility on Syria’s northern border with Turkey hidden within a Lafarge cement factory.

He tracked America’s most secretive special operations forces from their home base in North Carolina to a classified facility in Syria using commercially purchased advertising data. The year was 2016. The demonstration was so clear and so alarming that it should have produced immediate, mandatory policy change across every military branch and intelligence agency. Instead, per press reports, the DoD has encouraged the growth of this industry by buying location data from this contractor and other data brokers. As Motherboard reported in 2021, DoD was purchasing location data sourced from Muslim prayer and dating apps. In 2022, the Defense Intelligence Agency revealed to Congress that it buys and searches domestic location data without a warrant.

Timeline from 2016 Yeagley JSOC briefing through 2021 DoD broker purchases, 2022 DIA admission, 2025 Ramstein reporting, to April 2026 CENTCOM confirmation letter
The ten-year gap. The first warning to JSOC and the first official confirmation of active targeting sit a decade apart. Across the interval the institutional response was a guidance document advising personnel to review privacy settings.

The Department of Defense did not respond to the threat Yeagley demonstrated by protecting its personnel from the vulnerability he had identified. It responded by purchasing the same capability for its own intelligence operations — buying location data from data brokers, including data sourced from prayer apps and dating apps, to conduct surveillance that would have required a warrant through any conventional legal channel.

The institution that was shown in 2016 that its own special operations forces could be tracked from their home bases to their most classified deployments using commercially available data responded by becoming a customer of the same industry that created the vulnerability. And for the next decade, while the data broker industry grew, while smartphone adoption among active-duty military personnel became universal, while the commercial location data ecosystem expanded to encompass billions of data points per day from hundreds of millions of devices, the policy response remained a guidance document telling soldiers to periodically review their privacy settings.

USCENTCOM’s geolocation risk guidance directs personnel to disable geolocation functionality when not needed, periodically review device and application privacy settings, and limit public sharing of information — while simultaneously admitting that such guidance doesn’t always fully disable geolocation on smartphones. The guidance acknowledges its own inadequacy in the same sentence that states it. Disabling geolocation functionality does not disable the advertising identifier. Reviewing privacy settings does not remove the data already collected. And none of it addresses the carrier-layer data — the more than one hundred data points that mobile network operators log about every device on their network that have nothing to do with providing telephone service and everything to do with the surveillance economy their business models have become entangled with.

How the Machine Works and Why Settings Cannot Stop It

Understanding why the privacy settings recommendation is inadequate requires understanding the architecture of the commercial location data ecosystem — because it is more comprehensive, more technically sophisticated, and more difficult to opt out of than most people, including most security professionals, have fully modelled.

DSI Advisory

This analysis is published. Your decision isn't.

We run the same cross-domain, scenario-based foresight on the decision in front of you — a deal, a market entry, a supplier dependency. Board-ready in five days, with a foresight indicator watchlist.

Commission a Predictive BriefBook a 30-min strategic call