← Latest papers
💻 computer science

Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks

A 2024 study analyzing U.S. Army unclassified network traffic reveals that over 21% of accessed domains are commercial web trackers, prompting recommendations to implement Cloud-Based Internet Isolation (CBII) configuration changes and policy updates to mitigate the resulting security risks to service members and unit operations.

Original authors: Alexander Master, Jaclyn Fox, Nicolas Starck, Maxwell Love, Benjamin Allison

Published 2026-04-09
📖 5 min read🧠 Deep dive

Original authors: Alexander Master, Jaclyn Fox, Nicolas Starck, Maxwell Love, Benjamin Allison

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: The Army's "Glass House"

Imagine the U.S. Army's unclassified computer network (the internet they use for daily work) as a giant, transparent glass house. Inside, soldiers and civilians are doing their jobs: checking bank accounts, taking online classes, booking travel, and reading news.

The report says that while the Army has locked the front door and installed high-tech security cameras to keep out hackers and spies, they forgot to put curtains on the windows.

Because the windows are clear, "commercial spies" (advertising companies and data brokers) can stand outside, peek in, and write down exactly who is doing what, where they are, and what they like. They aren't trying to break in; they are just collecting data to sell to the highest bidder.

The Investigation: Counting the Peeping Toms

The Army Cyber Institute (ACI) decided to take a census of these "peeping toms." They looked at the top 1,000 websites visited by Army personnel over two months in 2024.

The Shocking Stat:
They found that 21% of the most popular websites visited were actually just "tracker domains."

  • The Analogy: Imagine you go to a grocery store to buy milk. You walk in, grab the milk, and leave. But 2 out of every 10 stores you visit have a hidden camera in the ceiling that records your face, your gait, and what else you looked at, then sends that video to a stranger in a van down the street.
  • The Reality: 212 of the top 1,000 websites were purely designed to collect data. Another 10% were regular websites (like a bank or a news site) that had hidden "spyware" (tracking pixels) embedded inside them.

Who Are the Spies?

The report identified the "bad actors" running these cameras.

  • The Big Players: Companies like Adobe and Microsoft (who provide software to the Army) were the most frequent sources of tracking. It's like the Army hired a security guard, but the guard's uniform had a hidden microphone that was broadcasting the guard's location to a data broker.
  • The Foreign Risk: The report flagged TikTok's analytics. Since TikTok is owned by a Chinese company, having its data collection active on Army networks is like letting a foreign intelligence officer stand in the lobby of your office building, taking notes on who visits which desk.
  • The Gambling Glitch: They even found a defunct gambling site on the list, which suggests someone (or a bot) was clicking on it, potentially exposing the network to malware.

Why Should the Army Care?

You might think, "So what? They're just collecting data for ads." The report argues this is dangerous for three reasons:

  1. The "Stalker" Effect: Data brokers combine tiny pieces of information (like "Soldier X visited a bank," "Soldier X visited a travel site," and "Soldier X lives in Texas") to build a complete profile. This can reveal a soldier's home address, family details, and movement patterns.
    • Analogy: If a stalker knows you go to the gym on Tuesdays and buy coffee on Wednesdays, they can predict exactly where you will be at 5:00 PM.
  2. The "Swatting" Danger: The report mentions real-world violence. Criminals have used data broker information to find the home addresses of government officials and "swat" them (send a fake police raid to their house). If a soldier's home address is leaked via commercial tracking, they could be targeted.
  3. The "Trojan Horse" Risk: AdTech (advertising technology) is often how hackers sneak malware onto computers. By letting these trackers run wild, the Army is leaving the back door open for viruses.

The Solution: Putting Up the Curtains

The good news is that the Army already has the technology to fix this; they just need to flip a switch. The report recommends a few simple changes:

  1. The "Read-Only" Mode (The Invisible Glass):
    Currently, the Army's security system (called CBII) lets some websites pass through untouched. The report says: Stop doing that.

    • Analogy: Instead of letting the glass house be transparent, turn the windows into one-way mirrors. The soldiers can see out and use the websites, but the trackers outside can't see in or grab any data. The security system should strip out all the "spy code" before showing the website to the user.
  2. Update the Rules (The Policy Change):
    The Army needs to officially label "Advertising" and "Tracking" as dangerous categories, just like they label "Malware" or "Pornography." This forces the security system to automatically block or isolate them.

  3. Check the Browser Settings:
    Make sure the web browsers on Army computers are set to "Do Not Track" by default, like a "Do Not Disturb" sign on a hotel door.

  4. Change the Contracts:
    When the Army buys software from companies like Adobe or Microsoft, they should write into the contract: "No selling our data to third parties."

The Bottom Line

The Army has built a fortress to keep out enemy hackers, but they are accidentally leaving the windows wide open for commercial data brokers. These brokers aren't enemies in the traditional sense, but the data they collect can be used by enemies to target soldiers, track their movements, and compromise national security.

The report concludes that with a few minor technical tweaks and policy updates, the Army can close the curtains, protect its people, and stop the "commercial surveillance" without slowing down their work.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →