From Tinder to running apps: Cellphones become a front for recruitment, spying, and sabotaging the enemy
Data collected by apps and social networks have become an intelligence source for militaries around the world

The alarms raised by the relationship between a Spanish NATO commander and a woman of Russian origin he met on Tinder, the dating app, are the latest chapter in a new espionage battleground: web applications. Sharing content on social media, posting your morning run, or looking for love online has become a latent risk for militaries around the world.
Both Russia and Ukraine have used fake profiles on social networks to carry out intelligence operations on dating sites, according to an EUvsDisinfo report from May. The operations include recruiting individuals to carry out acts of sabotage by Russian intelligence services, while Ukrainian intelligence persuaded enemy soldiers to reveal Russian military positions. The use of these apps goes back at least to 2018, when the Israeli military launched Operation Broken Heart to neutralize an espionage campaign attributed to Hamas that used fake dating apps to compromise members of its armed forces.
Mobile apps have also become a leak point for militaries. As Le Monde reported in a series titled StravaLeaks, a social network like Strava, for sports enthusiasts, allowed for the geolocation of French and Israeli military personnel. One of the most notorious episodes occurred when a French Navy officer revealed the position of the aircraft carrier Charles de Gaulle, which was heading to the Middle East. The sailor went for a run on the ship’s deck and logged it on Strava. His profile, accessible to anyone, showed the route he had run: a series of circles stretching across the middle of the Mediterranean Sea.
Meanwhile, the app Polarsteps, a social network where users can post their trips abroad, allowed researchers at Follow the Money to locate dozens of military personnel and public employees. Through their movements they were able to identify their homes and, in at least one case, the elementary school attended by a service member’s children.

Concern has reached such a level that the U.S. Army has considered forcing troops deployed to the Middle East to surrender their personal phones to eliminate the risk of a leak.
But the danger goes beyond an individual service member’s carelessness. The vast majority of mobile apps collect all kinds of information that they then sell to data brokers, who aggregate it and resell it. The practice is legal and includes information such as location, phone model, and browsing history. Accessing that data is relatively easy: in 2023, a group of researchers at Duke University purchased databases from these companies, sometimes for as little as $0.10 per record. With them, they identified people in the military by name, home address, and the branch they belonged to, as well as information about their health, religion, or financial situation.
A report by Interface, a European technology think tank, identifies signs of commercial data being used for intelligence purposes in Hungary, the Netherlands, Austria, France, Germany, and the United Kingdom. In the United States, since 2024, an intelligence-community regulatory framework to handle information available from commercial sources has been in use.
“We have reached a point where information collected by private companies is useful for military purposes,” says Tor Erling Bjørstad, a researcher specializing in commercial-source intelligence and a security consultant at the Norwegian firm Mnemonic. “The purposes of intelligence services and that of companies in this sector converge: to collect information from a wide variety of sources and organize it systematically.”
Two weeks ago, on September 4, 2026, the U.S. Army made public that it had blocked personalized advertising on its devices, according to several letters sent to Democratic Senator Ron Wyden. The move came after United States Central Command (CENTCOM) acknowledged in April that it had received multiple reports of adversaries using commercial geolocation data to surveil or target U.S. personnel deployed overseas. CENTCOM did not specify where or when these threats had occurred, but its area of responsibility includes the Middle East, where U.S. forces are engaged in a standoff with the Iranian military over the Strait of Hormuz.
Data brokers offer aggregated information over extended periods. In a wartime scenario, the process is different: “My hypothesis is that they are using Real-Time Bidding to obtain real-time data,” Bjørstad says.
Real-Time Bidding (RTB) refers to the auction process that occurs when an internet user opens certain websites or apps that contain ad spaces. In the microseconds it takes the page to load, device information is distributed to potential advertisers, who bid in real time for the right to place ads in those spaces.
Google and Meta dominate much of the global digital advertising market through RTB and rely heavily on it as a revenue source. Alphabet, Google’s parent company, posted $294 billion in advertising revenue in 2025, 73.2% of its total revenue, while Meta, Facebook’s parent company, brought in $196.175 billion, 97.6% of its total revenue.
In 2022, a ProPublica investigation revealed that RuTarget, a Russian ad-tech company owned by state bank Sberbank, continued to receive data from Google’s auction system after the invasion of Ukraine. A year later, Bloomberg documented that Israeli cybersecurity firm Rayzone had been collecting data through its own digital ad-buying platform for years. In 2024, a Wired investigation revealed that Gravy Analytics obtained location data via the RTB system and sold it to U.S. security agencies such as the Federal Bureau of Investigation (FBI), the Drug Enforcement Administration (DEA) and U.S. Immigration and Customs Enforcement (ICE).
Sign up for our weekly newsletter to get more English-language news coverage from EL PAÍS USA Edition







































