Ad-Tech Surveillance: How Ad Data Puts Journalists at Risk
Spying on a journalist no longer requires hacking a smartphone or infecting a computer. The data that mobile apps and advertising platforms gather for targeting can reconstruct a specific device’s routes, pinpoint a home and workplace, and sometimes tie an advertising identifier to a real person. A joint study by the Committee to Protect Journalists (CPJ) and the Carr-Ryan Center for Human Rights at the Harvard Kennedy School found that advertising infrastructure has formed what is effectively a ready-made system of mass surveillance, accessible to commercial companies, law enforcement, and government bodies.
A Million Devices in a Free Sample
One of the most striking examples was a free sample from an American data broker obtained by the Belgian journalist Nicolas Baudoux. The dataset covered a mere two weeks of 2025, yet it contained information on roughly a million devices and 100 million geolocation points. Analysing the sample allowed journalists to identify individual people and reconstruct their movement routes.
The German journalist Ingo Dachwitz found his own movements in a similar free database. The source of the coordinates turned out to be a weather-forecast app to which Dachwitz had granted location access. In another investigation, a commercial dataset made it possible to reconstruct the habitual route of Basma Mostafa, an Egyptian journalist living in Berlin, including her home and regularly visited locations. Such a detailed movement history creates a risk of exposing not only the journalist, but also the people they meet.
The Role of Real-Time Bidding
A significant portion of the risk stems from RTB auctions, through which advertising platforms sell ad impressions in fractions of a second. When a user opens a site or app, the device profile is transmitted to participants in the advertising market. That profile may include coordinates, device details, interests, employment, and other attributes. Experts interviewed by the study’s authors note that, to collect part of the bidstream data, a market participant does not always need to win the auction and earn the right to display an ad.
Advertising Identifiers and Real Identities
The names of smartphone owners are usually not passed along in the advertising stream, but a profile is tied to a mobile advertising identifier. Brokers and specialised services can match these identifiers against other datasets and, in some cases, establish a device’s actual owner. The US Federal Trade Commission has previously warned that advertising identifiers offer no genuine anonymity, while advances in AI further ease the discovery of links between disparate sets of information.
Beyond Coordinates: Ready-Made Audiences
The danger extends beyond coordinates alone. In a 2021 dataset from the advertising platform Xandr, researchers discovered ready-made audiences for female journalists from the United Kingdom, people connected to journalism and news, and users who had shown an interest in CPJ. Such prepared segmentation allows one first to isolate a small professional group and then to narrow the pool of targets with the help of geolocation, advertising identifiers, and other commercial data. Microsoft consolidated Xandr into Microsoft Advertising in 2025.
The Rise of the ADINT Market
Around commercial advertising datasets, a distinct ADINT market has taken shape, where marketing mechanisms are repurposed for intelligence and targeted surveillance. In April 2026, Citizen Lab dissected Webloc, a product of the company Penlink that uses data from mobile apps and digital advertising to track hundreds of millions of devices worldwide. Among the identified customers, researchers named law-enforcement and government bodies in the United States, Hungary, and El Salvador. Penlink disputed part of Citizen Lab’s conclusions and stated that it complies with US privacy laws.
From Tracking to Spyware Delivery
The most dangerous scenario links advertising infrastructure not merely to tracking, but to the delivery of spyware. The report’s authors describe a scheme in which an operator first establishes the advertising identifier of the target smartphone, then locates the device on the advertising market and secures the display of a specially prepared advertisement. This scheme is called “half-click”: the victim need not tap the banner, yet infection must be preceded by the ad’s display.
The report mentions Aladdin, a product developed by Intellexa that uses an ad impression to redirect a device to the operator’s infrastructure. Once the ad is opened, embedded JavaScript can redirect the smartphone to servers controlled by the spyware operator, from which a further infection chain is launched. Unlike classic link-based attacks, the user need not click the advertisement themselves. No publicly confirmed cases of infection through Aladdin have yet been recorded, so researchers regard the mechanism as an emerging threat rather than a proven, widespread practice.
How to Reduce the Risk
To mitigate the risk, CPJ advises disabling the advertising identifier and personalised advertising, restricting apps’ access to geolocation, treating programs with embedded advertising SDKs with greater caution, and using ad blockers in the browser. The study’s authors stress that user settings can only reduce the volume of information collected, since the problem is rooted in the architecture of the advertising market and the onward resale of datasets already gathered.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.