Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

Recent examination Of the hundreds of mobile applications marketed to US military personnel, more than one in eight were found to contain software designed by companies in China, Russiaor other foreign countries, raising new concerns that hostile governments could collect data revealing where military service members live, work and are deployed.
according to Researchers at Purdue University, the U.S. Military Academy at West Point, and Florida International UniversityOne popular app used by service members to assess living conditions on their own bases includes code from Huawei, the Chinese telecommunications company that US regulators deemed a national security threat in 2020. Two other apps were created by Russian companies and include the Russian advertising service Yandex.
The advertising industry is largely unregulated Which tracks Americans online Civilians and service members are mostly treated the same way, unless there is one The profit is in distinguishing between them– Despite evidence suggesting that exposure can reveal troop deployments, unit movements, and personnel routines inside intelligence facilities and bunkers where nuclear weapons are believed to be stored.
WIRED’s investigations have previously shown Location data collected from regular apps that track U.S. service members to their homes, their children’s schools, and off-base institutions where seeing troops is prohibited. Experts warned that the same data could help foreign spies Determine which employees have access to sensitive sitesOr map when the facility is less guarded or show other dangerous details.
Risks are no longer hypothetical. In April, US Central Command He confessed in a letter Washington told Senator Ron Wyden that it has received multiple threat reports of adversaries exploiting commercial location data to target or monitor US personnel in the Middle East, where US forces remain in a standoff with the Iranian military over the Strait of Hormuz. Lawmakers described it as the first official confirmation that troops in an active war zone are being tracked through the data broker economy, a threat that Pentagon contractors and researchers have warned about for nearly a decade.
The new study takes a first look at one part of that exposure: what’s actually inside apps that are designed and marketed specifically for the military.
“We are grateful for the opportunity to bring more attention to these issues,” says Joshua Shinkle, a doctoral researcher at Purdue University and lead author of the study. “We hope the research helps military personnel, developers, and platforms make more informed decisions regarding privacy and encourages continued discussion with developers, platforms, and policymakers about how to address these vulnerabilities.”
The researchers examined more than 220 such apps — ranging from standardized guides and preparation for promotion exams to banking apps and dating apps — that were pulled from the Google Play Store and military subreddits. Nearly two-thirds — or 64 percent — contain third-party code, known as SDKs: pre-built software components, typically used for analytics and advertising, that can also track user behavior, including their location, and share that information with third-party companies.
The researchers found that 40% of the apps collected or shared more data than they disclosed in their Google or Apple Store listings.
The most popular SDKs came from Google and Facebook, the two companies that dominate digital advertising in the United States. But 76 of them have been found, including code dating back to China, Russia, Israel, India, Germany and others. Nearly 7% of the apps carried third-party code from a country the Pentagon considers hostile.
Twelve of the apps contain HMS Core, a software suite from Huawei that advertises the ability to pinpoint users’ locations, deliver ads, and store photos and video. Many were built for state National Guard organizations.
The researchers did not observe any data actually going to Huawei’s servers. But the SDK can be updated remotely at any time. Code that is inactive today can still be spyware tomorrow. In at least one case, noted by the study, Huawei code arrived without the app developer’s knowledge, and was smuggled as a dependency into a commercial media tool.