Breaking News

Iran Allegedly Tracked US Troops Through Their Phones. The Real Weakness Was the Data Market

Written by Maria-Diandra Opre | Jul 22, 2026 12:00:02 PM

A smartphone can map military movements using the same systems that support roaming and targeted advertising.

Iran-linked actors allegedly used two ordinary parts of the mobile ecosystem to track US personnel during the 2026 conflict: SS7 requests sent through telecom networks and commercially available location data collected by smartphone apps (Financial Times, 2026). Altogether, those signals can show where a device connects, which locations it visits repeatedly, and how its movements change before an operation.

Researchers detected a surge in suspicious location requests across Middle Eastern networks, while US officials raised concerns that advertising data may also have been used to follow devices in Iraqi Kurdistan. Investigators have yet to tie the surveillance to a specific strike, but the method matters on its own. Systems built for roaming and targeted advertising had become tools for military intelligence.

SS7 is a decades-old protocol that allows mobile operators to route calls, texts and location requests when subscribers move between networks. Operators need access for legitimate roaming services. The same access can be abused to query a phone’s approximate location across borders.

Patterns reviewed by security researchers suggested a coordinated effort to identify particular devices. Citizen Lab researcher Gary Miller said Iran possesses the capability to obtain “real-time, immediate, and continuous location information” through regional telecom access.

Commercial data offers a second route. Many apps collect location data for advertising and analytics, linking it to persistent device identifiers. Buyers can use the resulting datasets to map repeated visits, home locations and daily routines. When applied to military personnel, ordinary consumer metadata can reveal troop concentrations, contractor movements, and temporary facilities.

US Central Command confirmed in April 2026 that it had received “multiple threat reports” involving adversaries using commercial location data to target or monitor American personnel during Operation Epic Fury. The warning became more serious in May, when a bipartisan group of lawmakers accused the Department of Defense of leaving basic protections unfinished despite knowing about the threat for at least a decade.

“Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs,” the lawmakers wrote, according to a release (Martin Heinrich, News Room , 2026).

The lawmakers argued that continued access to data from personnel serving in military hotspots reflected the Pentagon’s failure to adopt safeguards already recommended by federal cybersecurity agencies. Besides, the letter revealed that advertising identifiers remained active on some government-issued smartphones despite years of guidance from the National Security Agency and the Cybersecurity and Infrastructure Security Agency recommending their disabling. CENTCOM only gained the ability to switch off location sharing remotely in May 2026.

Advertising identifiers allow data collected across different apps and services to be linked back to the same device. Combined with location records, they can expose troop concentrations, regular routes and changes in movement that may signal an upcoming operation.

The scale of commercially available tracking data makes the concern difficult to dismiss. A sample examined by journalists in 2024 reportedly contained three billion location points from 11 million devices. More than 12,000 devices appeared near 11 US military sites in Germany, and some could then be followed away from the bases.

Regulators have already challenged parts of the market. In 2025, the Federal Trade Commission prohibited Gravy Analytics and Venntel from selling or using sensitive location data except in limited circumstances, following allegations involving data linked to healthcare facilities, religious sites and other sensitive locations. (Federal Trade Commission, 2025).

Encryption can protect message content while leaving the surrounding trail intact: where a phone connects, which apps collect its location, and who can purchase the data. A phone only needs to keep reporting its location. The greatest warning is that Iran’s alleged campaign relied on familiar infrastructure rather than a futuristic cyberweapon.