Security06:50 · 14m ago

Ad Data Fuels Journalist Tracking, Rights Groups Warn

Arab48
Translated & summarized from Arab48 by baba
The story · English

A joint investigation by the Committee to Protect Journalists and Harvard's Car-Ryan Center for Human Rights has revealed that commercial markets are increasingly using data collected by mobile apps and digital advertising systems to track journalists and their sources, bypassing the need for advanced spyware. The investigation highlights how location data gathered by seemingly ordinary apps can be transferred through advertising companies and data brokers to third parties, enabling the reconstruction of individuals' movements, their visited locations, and potentially their contacts.

Belgian journalist Nicolas Baudoux demonstrated the ease of access by obtaining a free two-week sample from a US data broker for 2025, containing data from approximately one million devices and 100 million locations. His team was able to use this sample to identify specific individuals. Similarly, German journalist Ingo Dahm found personal movement data within a comparable free sample. He had previously granted a weather app location access, not anticipating the information would later be available in a database accessible to others. In April 2026, German media also uncovered commercial data concerning Egyptian journalist Basma Mostafa, living in Berlin, including details about her home and visited places, raising concerns about potential surveillance.

The data flow originates from apps via technologies like Software Development Kits (SDKs) and the Real-Time Bidding (RTB) system. While SDKs help apps connect to ad platforms, they can also collect and transmit location data. In RTB, when an ad-supported site or app is opened, device and user information is sent to an electronic marketplace where advertisers bid for ad space. This data can include location, function, interests, political affiliations, or health and psychological information. Although not always containing a user's name, it's often linked to a unique mobile advertising ID. The US Federal Trade Commission notes that while these IDs can be reset, they don't provide true anonymity, as they can be linked with other data to identify device owners.

Previous research from the University of Washington showed RTB could be exploited to verify a device's presence in a specific location by targeting its advertising ID with an ad that appears only when near a certain geographic area. In 2023, the Irish Council for Civil Liberties warned that foreign government and non-government entities could use RTB data to gather information on US and European officials and military figures, stating similar risks apply to journalists. This warning was based on data from the Xandr advertising marketplace, which included user segments categorized by various traits and interests, some related to female journalists in Britain, journalists and news, and even an interest in the Committee to Protect Journalists.

In January 2025, the Irish Council for Civil Liberties and the Electronic Privacy Information Center filed a complaint with the US FTC against Google's RTB system, alleging data protection violations and data transmission to entities in China and Russia. Google denied wrongdoing, asserting strict data-sharing limitations. In 2026, Google offered an opt-in feature to limit shared information in ad auctions, but it was not enabled by default. The issue extends beyond ad platforms, as apps themselves have financial incentives to collect user data. In 2025, 404 Media reported on location data linked to RTB from popular apps like Candy Crush, Tinder, Grindr, and Temple Run, as well as news and health apps.

Once data leaves the phone, it enters a market driven by data brokers who aggregate information from various sources and sell it to commercial, security, or intelligence entities. This has led to the rise of Advertising Intelligence (ADINT) services, which use ad data for specialized surveillance capabilities, such as near real-time device location tracking or reviewing past movements. In 2025, Le Monde journalist Martin Ehlers identified over ten companies offering such services, noting this market provides global access to data that can be used to target journalists. One highlighted tool is the 'WebLocker' system developed by US company PenLink. A Citizen Lab investigation in April 2026 concluded that WebLocker relies on purchased data from consumer apps and digital advertising, enabling extensive geographic surveillance. PenLink acknowledged using location data linked to device identifiers but stated it was obtained from providers who confirmed user consent and that they implement restrictions against misuse and human rights violations. Citizen Lab found clients included Hungary's intelligence agency, El Salvador's police, the US military, and US law enforcement agencies, with indications of its use in countries including Germany, Austria, Italy, Romania, the UAE, Israel, Singapore, and Russia.

Read the original at Arab48
Open the live terminal