TL;DR: Every time an ad loads on your phone, your device broadcasts your GPS coordinates, device ID, and personal data to thousands of companies in under a second. Most of those companies aren’t trying to sell you shoes. They’re harvesting your location data. Citizen Lab’s April 2026 investigation revealed that a company called Penlink packages this ad data into a tool called Webloc and sells it to ICE, the U.S. military, police departments, and foreign intelligence agencies, covering 500 million devices across 30+ countries. No warrant. No court order. Just a purchase order. Ad blockers aren’t a convenience anymore. They’re a survival tool.

What Actually Happens When an Ad Loads on Your Phone

Open your weather app. Check the forecast. Close the app. In the three seconds that took, your phone just told dozens of companies exactly where you’re standing.

Here’s the chain of events, broken down:

Step 1: The app requests an ad. Your weather app has advertising code baked in, either through the Real-Time Bidding (RTB) system or through a Software Development Kit (SDK) that the app developer embedded for revenue. The moment the app opens, it signals an ad network that it has space to fill [1].

Step 2: Your data gets broadcast. The ad network fires off what’s called a “bid request” to hundreds or thousands of potential advertisers. That bid request includes your Mobile Advertising ID (MAID), your GPS coordinates, a timestamp, your device type, operating system, the app you’re using, your language settings, and (depending on the SDK) your age, gender, interests, purchase history, Wi-Fi information, and sensor data [1].

Step 3: The auction happens. Advertisers have roughly 100 milliseconds to decide if they want to bid on your eyeballs. But the bidding is beside the point. Every company that received the bid request now has your location data. Whether they bid or not.

Step 4: The data gets saved. Data brokers participating in this system don’t delete the bid requests. They accumulate them. One broker told Citizen Lab it had data on “more than one billion mobile devices.” Another, collecting through SDKs in 400 apps, claimed 40 million phones [1].

This entire process takes less than one second. It happens every time an ad loads. On average, your phone does this hundreds of times per day.

How Webloc Turns Ad Data Into a Police Tracking Tool

Penlink (the company that now owns Webloc after acquiring Israeli firm Cobwebs Technologies in 2023) buys this ad auction data in bulk. Billions of daily location signals from hundreds of millions of devices [1].

Then it builds a product. Government customers get a login. They can:

  • Search by phone number, device ID, or advertising ID
  • Draw a box on a map and see every device that passed through that area
  • Pull location history going back three years
  • Identify where someone sleeps (home address), where they work, where they worship, what clinics they visit, and which protests they attend
  • Set up continuous monitoring to track a device in near-real time

The system covers up to 500 million mobile devices across more than 30 countries, serviced by 219 active servers: 126 in the U.S., 32 in the Netherlands, and 17 in Singapore [2].

No warrant required. No judge involved. The Fourth Amendment says the government needs probable cause to track you. The Supreme Court confirmed this in Carpenter v. United States (2018) for cell-site location data. But Webloc skips the phone company entirely. It buys from the advertising industry instead. Different pipeline, same result, no oversight.

Who’s Buying Your Ad Data

Citizen Lab confirmed the following agencies as Webloc customers [1]:

U.S. agencies:

  • Immigration and Customs Enforcement (ICE): $2.3 million contract
  • U.S. military units
  • Texas Department of Public Safety
  • West Virginia Department of Homeland Security
  • New York City district attorneys
  • Police departments in Los Angeles, Dallas, Baltimore, Tucson, Durham, Elk Grove, and Pinal County

International:

  • Hungary’s Special Service for National Security: renewed six licenses in March 2026, weeks before parliamentary elections [3]
  • El Salvador’s National Civil Police: purchased 2021 [1]

Citizen Lab sent 96 freedom-of-information requests to agencies across 14 European countries and six EU bodies. Europol confirmed it had Webloc-related documents but wouldn’t release them. The UK Home Office refused to confirm or deny. Thirty-nine UK police forces gave the same non-answer [1].

The NPR investigation that broke this story to mainstream audiences on April 26 was syndicated across 15+ affiliate stations: WFAE, WYPR, NHPR, WUNC, WQCS, WKNO, KLCC, Connecticut Public, and more [4]. The scale of the pickup tells you something about how this hit a nerve.

The “Anonymous” Data Lie

The ad industry calls Mobile Advertising IDs “anonymous identifiers.” The FTC has called that out as fiction. In enforcement actions, the FTC clarified that MAIDs “offer no anonymity in the marketplace” because companies “regularly link consumers’ MAIDs to other information about them, such as names, addresses, and phone numbers” [1].

You don’t need a name attached to a MAID to identify someone. If a device sleeps at the same address every night and sits at the same office every weekday, you’ve identified its owner. Cross-reference with a commercial database (the kind that data brokers sell for pennies) and you have a name, address, and phone number.

Citizen Lab notes that much of the raw location data is inaccurate. But that doesn’t matter for targeted surveillance. Researchers noted that “90% of the data is flawed, as long as the target’s device identifier is in the set” [1]. They don’t need every ping to be accurate. They just need yours to appear.

Ad Blockers Are Now a Privacy Survival Tool

The entire Webloc pipeline depends on one thing: ad requests firing from your phone. Block the ad request and you block the data broadcast. It’s that direct.

Here’s how to cut the pipeline at every stage:

Block ads at the source:

  • Install uBlock Origin on your browser. It blocks ad network requests before they fire
  • Use Firefox or Brave on mobile, both of which support content blocking
  • Set up DNS-level blocking with NextDNS or Pi-hole to block ad domains across all apps on your network

Kill your advertising ID:

  • iPhone: Settings → Privacy & Security → Tracking → toggle off “Allow Apps to Request to Track”
  • Android: Settings → Privacy → Ads → Delete advertising ID
  • Without a MAID, the bid requests are harder to link to a persistent identity

Audit app permissions ruthlessly:

  • Your weather app doesn’t need precise location. Your flashlight app doesn’t need location at all
  • Revoke location access from every app that doesn’t absolutely require it
  • Switch to apps that don’t run ads: paid alternatives or open-source tools

Go further:

  • GrapheneOS or CalyxOS strip out Google’s advertising infrastructure entirely
  • A VPN masks your IP address from bid requests (though GPS coordinates from the SDK are harder to hide)
  • Use F-Droid for Android apps. Open-source apps don’t embed ad SDKs

None of these are foolproof. But every layer you add makes you harder to track. And unlike waiting for Congress to pass a law, you can do all of this right now.

Congress Could Fix This Tomorrow. They Won’t.

In March 2026, 72 members of Congress signed a letter demanding DHS explain its warrantless purchases of Americans’ location data, including the $2.3 million Webloc contract. ICE was supposed to brief lawmakers on February 10. They cancelled without explanation and haven’t rescheduled [5].

The data broker loophole that makes all of this legal remains wide open. The Fourth Amendment Is Not For Sale Act and the Wyden-Lee Government Surveillance Reform Act would require a warrant before the government buys location data from brokers. Neither has passed.

Meanwhile, the ad industry keeps broadcasting. The data brokers keep collecting. And Penlink keeps selling. Five hundred million devices. Thirty countries. Three years of history. All because you checked the weather.

References

  1. Citizen Lab: Uncovering Webloc: An Analysis of Penlink’s Ad-based Geolocation Surveillance Tech, Report No. 191 (April 9, 2026)
  2. The Hacker News: Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data (April 2026)
  3. VSquare: Orbán’s Spying Kit Revealed: Hungary Uses Webloc Surveillance Tool (April 2026)
  4. NPR: A New Study Shows How Ad-based Technology Is Used for Surveillance (April 26, 2026)
  5. Sen. Ron Wyden: Wyden, Espaillat and 70 Democrats Call for Investigation of ICE, DHS Warrantless Purchases of Americans’ Location Data (March 2026)