“The spirit of our endeavour is, To strive, to seek, to find and not to yield”

Alessandro Minuto-Rizzo, President

From Commercial Micro-Targeting to Critical Asset Intelligence: a Door to Hybrid Warfare via RTB

Source: epic.org
Source: epic.org

The bottom line of this article can be resumed in three bullets:

  • The Real-Time Bidding (RTB) and Data Broker ecosystem, originally conceived for advertising monetization, now constitutes one of the most expansive passive intelligence infrastructures available to both state and non-state actors.
  • The fragmentation of this supply chain precludes the identification of a single culprit (patient zero), transmuting surveillance from a targeted hostile act into an emergent market phenomenon.
  • The very same geospatial data streams that fuel telemarketing and neighbourhood spoofing enable the tracking of military personnel, government officials, and critical infrastructures across NATO and Euro-Mediterranean theatres.
  • In the public discourse surrounding digital security, the framing of surveillance still clings to twentieth-century paradigms: a state actor (or an intelligence agency) orchestrating the targeted interception of an individual via bespoke espionage technologies, such as lawful interception or advanced spyware.

This interpretation is conceptually obsolete. The most pervasive threat to the security of institutional and military cadres stems not from complex clandestine operations, but from the unceasing haemorrhage of metadata through the digital marketing and geolocation data supply chain.

The seemingly trivial phenomenon of geographic caller ID spoofing—the automatic adjustment of the dialler’s area code (e.g., from a Tuscan 055 to a Roman 06) as a user crosses provincial lines—is the visible symptom of real-time spatial tracking. This mechanism does not rely on the complicity of telecommunication companies; rather, it exploits the secondary market of location data harvested by ubiquitous, everyday applications.

The value chain that transforms a domestic GPS sensor into a hybrid threat vector operates on three integrated tiers:

The Application Tier (Software Development Kits – SDKs)

At the base of the pyramid lies the granting of permissions within mobile operating systems (iOS/Android). Through the integration of third-party SDKs into the development modules of non-critical apps (weather, games, utilities), exact location data is extracted and transmitted externally without the consumer’s knowledge, often financially compensating the primary developer in the process.

Aggregation and the Data Broker Market

These primary streams converge toward private aggregators (the so-called Data Brokers). Entities sanctioned by the US Federal Trade Commission—such as Gravy Analytics, Venntel, Mobilewalla, Outlogic (formerly X-Mode), Kochava, and InMarket—demonstrate that spatial profiling is not a fringe activity, but an industry that is only marginally regulated.

  • The impact of these datasets transcends mere purchasing preferences; it extends to relational and behavioural mapping: the frequency of visits to diplomatic missions, military commands, healthcare facilities, or places of worship.

The Real-Time Bidding (RTB) Infrastructure as a Data Leakage Vector

The true engine of mass tracking is the Real-Time Bidding (RTB) mechanism. With every loading of a webpage or app screen, hundreds of instant ad auctions broadcast the user’s technical parameters (IP address, precise GPS coordinates, Advertising ID, device type) in the clear to an undefined audience of bidders. As highlighted by reports from the Irish Council for Civil Liberties (ICCL), this unregulated outflow constitutes the most colossal data breach of personal information in the history of telecommunications.

Source: Irish Council for Civil Liberties.

The convergence of commercial advertising tools and strategic intelligence capabilities fundamentally alters the very concept of national vulnerability.

Cyber incidents between 2024 and 2025 (including the exposure of Gravy Analytics’ datasets) have confirmed that samples extracted from the RTB market encompass devices active within:

  • Strategic command centres (The Pentagon, the Kremlin, European Ministries of Defense).
  • NATO operational bases and logistical hubs.
  • Vatican City and international diplomatic missions.

The availability of such intelligence on parallel markets or via advanced commercial tracking platforms—such as the Israeli system PATTERNZ, which allegedly queries ad-tech streams to profile billions of devices—proves that the distance between an invasive telemarketing campaign and an informational targeting operation aimed at political decision-makers or high-ranking officers is strictly a matter of the data’s purchase price.

In hybrid warfare, the defining characteristic is the absence of attributional clarity. The effect of total surveillance is not orchestrated by a single adversary intelligence hub; it is the emergent result of thousands of legitimate commercial transactions. This renders traditional frameworks of state retaliation or countermeasures inapplicable: there is no single “director” to sanction or neutralize, but rather an open ecosystem of data exchange.

 

Vulnerability does not reside in a flaw within an operating system, but in the commodification of individual tracking. For as long as a citizen’s location is treated as a commercial conversion metric, the precise coordinates of a political policymaker or a military unit will remain a target readily acquirable on the open market.

 

Europe finds itself in a position of structural asymmetry: while its regulatory framework (GDPR) attempts to enforce formal data compliance, the underlying RTB infrastructure continues to haemorrhage spatial information to third parties. This includes competing state actors (e.g., the Russian Federation, the People’s Republic of China, etc.) who indirectly acquire control over these auction streams.

The immediate mitigation recommendations for INFOSEC are:

  • Hardening of Service and Personal Devices for Strategic Personnel: Strict restriction of location permissions at the OS level (While using or Never), systematic deactivation of the Advertising ID and the disabling of personalized ads based on physical sensors.
  • Regulatory Framing of RTB as Critical Infrastructure: The imperative to extend cybersecurity directives (e.g., NIS2) to the supply chain of ad-exchanges and data brokers, treating high-precision geographic metadata as assets bound by digital sovereignty.
  • The Doctrine of Digital Hygiene: The awareness that information and operational security (INFOSEC, OPSEC) cannot be decoupled from the sanitization of the daily digital behaviours of individual operators.

Share on

Archive

Subscribe to our newsletter

This field is required.
This field is required.
Please enter a valid email address.
This field is required.
This field is required.

In the first field, enter the international prefix (e.g. 0039 or +39), while in the second field, enter the mobile number without the prefix.

I consent to have this website store my submitted information so they can respond to my inquiry after reading Privacy Policy
You must accept the terms to proceed.