Green digital data streams flowing across a dark screen resembling the Matrix
Photo via Unsplash

TL;DR: On April 9, the University of Toronto’s Citizen Lab published a technical investigation into Webloc, a surveillance system built by Penlink (formerly Cobwebs Technologies) that harvests location data from mobile ads and app SDKs to track up to 500 million phones worldwide. No warrants. No court orders. Just your apps quietly broadcasting your GPS coordinates every time an ad loads, and a company selling that data to ICE, the U.S. military, police departments from LA to Baltimore, Hungary’s intelligence service, and El Salvador’s national police. The data goes back three years. In March 2026, 72 members of Congress demanded an investigation into this exact system. The government’s response? Silence.

From Your Phone to a Government Screen in Milliseconds

Here’s how it works, and it’s worse than you think.

Every time an ad loads in one of your apps (your weather app, your flashlight app, your favorite game), your phone broadcasts a packet of data into the digital advertising ecosystem. That packet includes your device’s Mobile Advertising ID (MAID), your GPS coordinates, a timestamp, what app you’re using, and device specifications [1].

This data enters what’s called the Real-Time Bidding (RTB) system. Within milliseconds, hundreds of companies compete to show you an ad. But here’s the dirty secret: most of those companies aren’t actually bidding on your ad space. They’re harvesting the data that gets broadcast during the auction. Your location. Your behavior. Your identity.

One data broker with RTB access told Citizen Lab it had “data on more than one billion mobile devices.” Another, collecting data from SDKs embedded in 400 apps, claimed coverage of 40 million phones [1].

Penlink buys this data (billions of daily location signals from hundreds of millions of devices) and packages it into Webloc. Government customers log in, type a phone number or draw a box on a map, and watch the dots move. Where you slept last night. Where you worship on Sunday. Which protest you attended. Which clinic you visited. Three years of your life, searchable in seconds.

The Customer List

Citizen Lab confirmed the following agencies as Webloc customers [1]:

United States:

  • Immigration and Customs Enforcement (ICE): $2.3 million contract
  • U.S. military units
  • Texas Department of Public Safety
  • West Virginia Department of Homeland Security
  • New York City district attorneys’ offices
  • Police departments in Los Angeles, Dallas, Baltimore, Durham, Tucson, Pinal County, and Elk Grove

International:

  • Hungary’s Special Service for National Security (NBSZ): six licenses renewed March 2026, weeks before today’s parliamentary elections [2]
  • El Salvador’s National Civil Police: purchased in 2021 [1]

And those are just the confirmed customers. Citizen Lab sent 96 freedom-of-information requests across 14 European countries and six EU bodies. Europol confirmed it held Webloc-related information but refused to release it. The UK Home Office and Swedish Police Authority declined to confirm or deny. Thirty-nine UK police departments neither confirmed nor denied knowledge [1].

The refusals tell you everything.

“Anonymous” Data Isn’t Anonymous

The advertising industry has spent years claiming that Mobile Advertising IDs are “anonymous.” The FTC disagrees.

The FTC clarified that MAIDs “offer no anonymity in the marketplace” because “many” companies “regularly link consumers’ MAIDs to other information about them, such as names, addresses, and phone numbers” [1].

Webloc exploits this. The system can infer your home address (where your phone sits overnight) and your workplace (where it sits from 9 to 5). Cross-reference with a data broker database that links MAIDs to real names, and you’ve identified the person behind the dot.

Citizen Lab notes that much of the harvested location data “is inaccurate.” But for targeted surveillance, accuracy doesn’t need to be perfect: “90% of the data is flawed, as long as the target’s device identifier is in the set” [1]. In other words, they don’t need every data point to be right. They just need yours.

72 Members of Congress Asked Questions. The Government Ghosted Them.

In March 2026, Senator Ron Wyden and Representative Adriano Espaillat led a letter signed by 72 members of Congress demanding an investigation into ICE and DHS’s warrantless purchases of Americans’ location data, including the $2.3 million Penlink/Webloc contract [4].

The letter called for DHS to explain what data is being purchased, which companies supply it, how many Americans are affected, and what legal authority justifies warrantless mass location tracking.

ICE was supposed to brief lawmakers on February 10, 2026. They cancelled “with no explanation and without any offer to reschedule” [4].

As of today, more than a month past the March 5 deadline that Congressional leaders set for answers, ICE has not responded.

What You Can Do Right Now

  • Reset your advertising ID regularly: On iPhone, go to Settings → Privacy & Security → Tracking and toggle off “Allow Apps to Request to Track.” On Android, go to Settings → Privacy → Ads → Delete advertising ID
  • Audit your app permissions: Any app with location access can feed this pipeline. Revoke location permissions from apps that don’t genuinely need it, especially weather, flashlight, and game apps
  • Use an ad blocker: Ad-based tracking requires the RTB system to fire. Block the ad request and you block the data broadcast
  • Consider a privacy-focused phone OS: GrapheneOS and CalyxOS strip out much of the advertising infrastructure that feeds systems like Webloc
  • Contact your representatives: Tell them to pass the Government Surveillance Reform Act and the Fourth Amendment Is Not For Sale Act. The data broker loophole is the reason Webloc works

References

  1. Citizen Lab. Uncovering Webloc: An Analysis of Penlink’s Ad-based Geolocation Surveillance Tech (April 2026)
  2. VSquare. Orbán’s Spying Kit Revealed: Hungary Uses Webloc Surveillance Tool (April 2026)
  3. The Hacker News. Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data (April 2026)
  4. Sen. Ron Wyden. Wyden, Espaillat and 70 Democrats Call for Investigation of ICE, DHS Warrantless Purchases of Americans’ Location Data (March 2026)
  5. UNITED24 Media. Hungary Deploys Israeli Webloc Surveillance Tool Violating EU Privacy Regulations (April 2026)