Hundreds of mobile apps designed for US military personnel have been found to contain software originating from China, Russia, and other foreign nations, sparking serious concerns about potential data harvesting by adversary governments. This code could reveal sensitive information about where service members live, work, and are deployed.
Researchers from Purdue University, the US Military Academy at West Point, and Florida International University discovered that over one in eight apps marketed to military personnel included code from companies like Huawei, a Chinese telecom previously flagged by US regulators as a national security risk. Additionally, some apps incorporated code from Russian companies and utilized the Yandex ad service.
The study highlights a significant vulnerability within the largely unregulated advertising industry, which often treats civilian and military data similarly. This can inadvertently expose troop movements, unit activities, and the routines of personnel in sensitive locations, including those where nuclear weapons are stored. Previous investigations have already shown how location data from ordinary apps can pinpoint service members to their homes, schools, and off-limits establishments.
Experts have long warned that such data could be exploited by foreign intelligence agencies to identify individuals with access to sensitive sites, map facility security gaps, or uncover compromising details. The threat is no longer theoretical; US Central Command has acknowledged receiving reports of adversaries using commercial location data to target American personnel in the Middle East, marking the first official confirmation of troops in active war zones being surveilled via the data-broker economy.
The new research examined over 220 apps, ranging from uniform guides to banking and dating apps, and found that nearly two-thirds contained third-party software development kits (SDKs). These SDKs, often used for analytics and advertising, can track user behavior and share location data with external companies. Alarmingly, 40 percent of these apps collected or shared more data than they disclosed, and roughly 7 percent contained code from nations considered adversarial by the Pentagon.
The researchers also surveyed military-affiliated individuals, finding that over 83 percent were uncomfortable with the data practices of at least one app they used. A significant majority expressed extreme discomfort with apps containing code from China, Russia, Iran, or North Korea. However, there is currently no straightforward way for users to identify the country of origin of the software running within an app, as app store privacy labels do not provide this information.
Many participants reported receiving inadequate guidance on personal app usage from their institutions. When asked about potential solutions, in-phone warnings about foreign or unknown third-party code were ranked as the most effective and supported mitigation. Other suggested measures included federal laws restricting data brokers from handling military personnel data, independent app privacy audits, and stricter bans on foreign code in military-marketed applications.