Nobody Needs to Hack Your Phone
Nobody Needs to Hack Your Phone
Following someone used to require a warrant, a van, or a skilled intruder. Now it mostly requires a credit card. Here is how ordinary apps came to produce a map of your life, why calling that data "anonymous" is a technicality, and what can actually be done about it.
The apps on an ordinary phone generate a stream of small, boring records — an app opened, a location fixed, an advert requested. Individually they are nothing. Stacked up over weeks, they describe where you sleep, where you work, who you travel with and when your routine changes. That stream is a legitimate industry, it is bought and sold, and in 2026 the US military confirmed it had switched off part of it on government phones because adversaries were using it to find soldiers.
What a week looks like from the outside
Imagine a list. Every row has four things: a long random-looking code, a pair of coordinates, a timestamp, and the name of whichever app happened to be open. There are a few hundred rows for a given phone in a given week. Nothing in the list is a name, an address, a photograph or a message.
Now sort the rows by that random code and plot them on a map.
The place the code sits still between midnight and six in the morning is, almost always, where that person sleeps. The place it sits between nine and five on weekdays is where they work. A second code that appears at the same two places at the same times probably belongs to someone in the same household. A code that travels the same route as yours every Tuesday evening belongs to whoever you go to the gym with.
You did not have to be identified for any of that to be true. The map was drawn entirely from records that contained no name at all.
Nobody read your messages. Nobody planted anything. The information was produced by your phone working exactly as intended, and sold by companies operating entirely within the law.
The uncomfortable partThis is the thing that people consistently underestimate about location data. The privacy risk is not in any single record. It is in the fact that human beings are extraordinarily regular, and regularity is easy to detect. You do not need to know much about a person to recognise them by their routine. The routine is the identifier.
How your phone came to be a data source
Almost no app makes money by being an app. Free apps make money by showing adverts, and showing the right advert to the right person is worth many times more than showing a random one. So an industry grew up to answer one question very fast: who is this, roughly, and what are they likely to want?
To answer it, the industry needed three things. A way to recognise the same phone across different apps. Some context about what that phone is doing. And a market where advertisers could bid for the chance to reach it.
The identifier
Every Android phone has an advertising ID — a long code that apps can read. Apple has an equivalent. It is deliberately not your name; it is resettable, and you can switch it off. Its whole purpose is to let unrelated companies agree that "the phone that did this" and "the phone that did that" are the same phone, without any of them knowing who you are.
That sounds like a privacy feature, and in a narrow sense it is. But a stable code that links your behaviour across every app you use is exactly what is needed to build the map described above. Anonymity that survives being followed around for a year is not really anonymity.
The context
Apps collect what they are permitted to collect. A maps app that has location permission genuinely needs it. The wrinkle is that advertising code doesn't live outside the app — it is a library bundled inside it, and the phone cannot tell the two apart.
When you grant an app access to your location, you are granting it to everything inside that app — including the advertising and analytics libraries the developer included. Android has no way to say "the weather feature may use my location, but the ad library bundled into it may not." They share one identity as far as the operating system is concerned. This is not a bug someone forgot to fix; it is a consequence of how apps are built and packaged.
The auction
Here is the part most people have never heard of, and it is the part that matters most.
When an app displays an advert, it does not simply fetch one. It runs an auction, in about a tenth of a second. A description of the opportunity — roughly what kind of phone this is, roughly where it is, what app is open, and often that advertising ID — is broadcast to a large number of potential buyers, who bid. One wins and their advert appears.
your phone opens an app
|
v
"ad slot available" + device context
|
v
AD EXCHANGE
|
+------+------+------+------+
| | | | |
v v v v v
bidder bidder bidder bidder bidder ... often dozens
|
+--> one wins, shows you an advert
the others saw your data anywayEveryone who was invited to bid saw the description. Only one of them needed it. There is no technical mechanism that stops the losers keeping a copy.
This is not theoretical. In a 2024 enforcement action, US regulators found that one company had been bidding in these auctions and retaining the data from auctions it lost — accumulating more than 500 million unique advertising IDs paired with precise location over roughly two and a half years [1]. Participating in the marketplace was itself the collection method.
"But it's anonymous"
This is the industry's standard answer, and it is worth taking seriously rather than dismissing, because it is not a straightforward lie. The records really do not contain your name. The companies involved often genuinely do not know who you are and have no particular interest in finding out.
The problem is that "does not contain a name" and "cannot be connected to a person" are very different claims, and only the first one is true.
- Your home address identifies you. The place a device rests overnight, cross-referenced against any public record of who lives there, is a name.
- You log in to things. The moment a service knows both your account and your device, the "anonymous" code has a person attached to it — and that link can be shared onward.
- Resetting the ID doesn't erase history. It starts a new chapter; it does not delete the old one, and companies specifically build systems to bridge across resets.
- Other identifiers survive. Individual apps keep their own internal codes, which are unaffected by anything you do to the advertising ID.
US regulators have stated the point plainly in enforcement actions: raw location data tied to an advertising ID is not anonymised, and can be used to trace a device to the places its user visited [1].
Your phone is almost certainly not secretly listening to your conversations through the microphone to target adverts. This is the single most common belief about ad tracking and there is no good public evidence for it. It would be enormously expensive, legally catastrophic if discovered, and — crucially — unnecessary. Everything described in this article explains the eerily accurate advert perfectly well without it. If you mentioned a holiday out loud and then saw a holiday advert, the likelier explanation is that you, or someone whose network and routine you share, searched for it.
This matters beyond trivia. Believing in the microphone makes the real mechanism harder to see, and the real mechanism is worse: it is continuous, it is documented, and it is legal.
The moment this became a security problem
Everything above is a consumer privacy story. It became something else when people noticed that the same market is open to anyone with money — including governments, and including hostile ones.
Consider what the data shows if the phone in question belongs to a soldier. The overnight location is their home, which puts their family on a map. The weekday location is their base. A cluster of devices that move from that base to an airfield and then stop appearing is a deployment. Devices that always travel together are a unit. None of this requires knowing a single name.
In September 2026, correspondence released by two members of the US Congress confirmed that the Army, the Air Force, the Department of the Navy and Special Operations Command had each disabled the advertising identifier on government-issued phones and computers [2]. The changes followed reporting that commercially available location data had been used to track and target American personnel in the Middle East. Some branches had only made the change months earlier.
The legislators who released the letters did not treat it as a success story. They asked the Department of Defense's Inspector General to examine whether the measures were effective at all, and said publicly that they were not.
An adversary who wants to follow a soldier no longer needs an intelligence service. It needs a corporate identity and a purchase order.
Why this is different from ordinary surveillanceThere is a broader point here that applies well beyond the military. Regulators have documented data products built around visits to health clinics, places of worship, political gatherings and domestic violence shelters. In February 2026 the US Federal Trade Commission wrote to thirteen data brokers about a law restricting sales of sensitive data to foreign adversaries, noting that it had found companies offering products involving whether an individual is a member of the armed forces [3].
If your routine reveals something about you that you would rather not advertise — a medical condition, a faith, a relationship, a political commitment, a job — then it is already in the same pipeline, described by the same coordinates, sold on the same terms.
The half-measures, honestly rated
Before the things that work, the things that mostly don't — because a false sense of protection is worse than none.
| Measure | Verdict | What it actually does |
|---|---|---|
| Resetting your advertising ID | Partial | Breaks the chain going forward. Doesn't delete what exists, and doesn't touch the separate codes each app keeps internally. |
| A consumer VPN | Largely no | Hides your network address from websites and your browsing from your ISP. Does nothing about an app that has your GPS location and sends it to its own servers. Most of the tracking described here passes straight through a VPN untouched. |
| Private / incognito browsing | No | Affects browser history on your own device. Irrelevant to apps. |
| Ad blockers | Partial | Effective in a browser. Much weaker inside apps, and blocks nothing when an app sends your data to its own servers first and passes it on afterwards. |
| "I have nothing to hide" | No | The data does not describe what you're hiding. It describes where you are, on a schedule, forever. Whether that's harmless depends entirely on who buys it and why — which you don't control. |
None of these are useless. They are just aimed at different problems from the one described in this article.
What actually helps — if you're a person
The realistic goal is not invisibility. It is reducing how many companies receive a usable copy of your routine, and how easily those copies can be joined together. That is achievable, and the highest-value actions are unglamorous.
Cut the number of apps
The single most effective step, and the one nobody wants to hear. Every app is a separate company with separate commercial incentives. Deleting the free game you play twice a year removes an entire data source permanently. Fewer apps beats better settings.
Be strict about location, and especially background location
Most apps that ask for your location do not need it, and very few need it while closed. Modern phones let you grant location only while an app is open, or grant an approximate area instead of a precise point. Background location is the setting that produces the overnight-and-weekday map. Give it to almost nothing.
Turn off the advertising ID
Both major phone platforms let you delete or disable it outright, not merely reset it. It is a genuine improvement, it takes a minute, and it costs you nothing except less relevant adverts. Just don't mistake it for a solution on its own.
Prefer apps you pay for
An app with no advertising business model has far less reason to carry tracking libraries. Paying a few currency units for a weather or notes app is often the cheapest privacy measure available.
Use a browser instead of the app, where you can
A website generally sees much less about your device than the same company's app does, and browser defences against tracking are considerably more mature than anything available inside apps.
Keep the phone updated, and buy one that gets updates
Not strictly about advertising — but every restriction described here only exists because the platform enforces it, and those enforcement mechanisms arrive in updates. A phone that stopped receiving them is a phone where the old rules still apply.
Do all of this and you are still visible to your mobile network, to the services you log in to, and to any app you decided you needed. What you have removed is the long tail: the dozen incidental apps quietly contributing rows to a shared map of your week. That's a real reduction, and it's the part you control.
What actually helps — if you run an organisation
For a company, a government department or anyone responsible for other people's phones, the individual advice does not scale and settings that users can change are not controls. The approach that works is different in kind, and it comes down to four ideas.
| Idea | In practice |
|---|---|
| Decide what may run | On a managed phone, the organisation chooses the apps, not the user. Every app is a separate company receiving data, so the list of approved apps is the list of companies you've decided to trust. Keeping it short does more than any filtering technology. |
| Decide what it may reach | Sensitive permissions — location, microphone, contacts — granted deliberately per app rather than left to whoever taps "Allow", and identifiers switched off centrally rather than hopefully. |
| Decide where it may talk | Route the phone's traffic through infrastructure the organisation controls, so an approved app can only reach destinations it has a documented reason to reach. This is the layer that catches apps behaving unexpectedly. |
| Check, then keep checking | Before an app is approved, run it in a test environment and watch where it actually sends data — which is often not what its documentation says. Then repeat it for every update, because behaviour changes between versions. |
That last one is the least popular and the most important. Approving "the mapping app" is meaningless; approving a specific version of it, having watched what it does, is a real control. It is also the only part of this that addresses the hardest case: an approved app that legitimately sends data to its own servers, where the company later sells it on. No technology on the phone can see that happen. The only defences are choosing the app carefully, negotiating a version without the tracking, or writing it into the contract.
Products that promise you cannot be tracked. None of this makes a phone untraceable. The mobile network necessarily knows roughly where every phone is — that is how calls reach you — and no app-level measure changes that. A vendor claiming otherwise is either confused or selling.
Solutions that are only a blocklist. Blocking known tracking servers is worth doing and is not a strategy. It cannot help when an app sends data to its own perfectly legitimate servers and the onward sale happens later, somewhere you cannot see.
The honest ending
There is a version of this article that ends with a reassuring checklist, and it would be dishonest. So here is the accurate version.
You cannot opt out of this entirely while carrying a phone. The mobile network knows where you are by design. The services you log in to know it's you because you told them. Data already collected is not recalled by a setting you change today, and it does not expire quickly.
What you can do is change the scale. The difference between a phone with forty apps, most of them free and permission-hungry, and a phone with twelve, chosen deliberately, with location off by default and the advertising ID disabled, is not a rounding error. It is the difference between contributing a detailed weekly map to a dozen commercial datasets and contributing fragments to one or two.
This is not a problem you solve. It is a problem you reduce, deliberately, knowing what you're trading and what you're keeping.
The realistic goalAnd the broader point is not really about settings at all. A market exists in which anyone with money can buy a detailed record of where large numbers of people have been. That market was built to sell trainers and takeaways. It turns out to work just as well for finding soldiers, identifying who attended a protest, or working out which building an unmarked facility occupies — and it was never designed with any of that in mind.
That is a policy problem, not a phone-settings problem. But it is much easier to argue about once you know it exists, which is the entire reason this article is not shorter.
A full technical treatment of this subject — the complete catalogue of signals a phone emits, the routes data takes off the device, an evaluated reference architecture for organisations, and the verification tests required before anyone claims it works — is published separately as Bought, Not Hacked. It is written for engineers and assumes familiarity with mobile platform internals.
Sources
[1] US Federal Trade Commission, FTC Takes Action Against Mobilewalla for Collecting and Selling Sensitive Location Data (December 2024) — the source for the 500 million figure, for data being retained from lost auctions, and for the finding that location data tied to advertising IDs is not anonymised. ftc.gov. See also the FTC's own explainer on how real-time bidding works: Unpacking Real Time Bidding.
[2] Reuters, reporting on correspondence released by Sen. Ron Wyden and Rep. Pat Harrigan, 4–5 September 2026, confirming that US military branches disabled advertising identifiers on government devices and requesting an Inspector General review. Widely syndicated; an accessible account is at Task & Purpose.
[3] US Federal Trade Commission, FTC Reminds Data Brokers of Their Obligations to Comply with PADFAA (February 2026), and the accompanying warning letter template, which references products involving armed-forces status. ftc.gov
Corrections are welcome and will be published rather than quietly applied: smk@pakcrypt.org