The European Front in Commercial Data Exploitation
Photo: Mirivox/Adobe Stock (Generated with AI)
Germany’s main domestic intelligence agency, the BfV, published an advisory several weeks ago warning German defense and security companies of heightened risks of Russian espionage, sabotage, and attack. Part of the list warned about potential Russian exploitation of commercial location data. Foreign intelligence services, the advisory said, could access data “sufficient to deduce commutes, residences, and movement profiles” of members of Germany’s defense base.
This is not an outlier scenario but a major point of exposure in Western security. Recently, U.S. Central Command (CENTCOM) confirmed that it has received reports of an adversary, which it did not name—ostensibly Iran, though if not, then probably China or Russia—exploiting “commercial location data to target or surveil US personnel” in the Middle East. The Russian government has previously targeted NATO soldiers’ smartphones to track their locations. And in the Putin regime’s continued war on Ukraine, location information can likewise fuel physical and digital targeting of Western governments and companies supporting Kyiv.
For the United States and its Western allies and partners, including Germany, the problem is rooted in the explosion of commercial data available for purchase. The data broker industry’s nuanced, persistent collection of data on a wide range of people, activities, places, and things means adversaries such as Russia have plentiful opportunities to gain insights they can use to their advantage. There are several interrelated challenges to addressing the problem: American data privacy and security laws are weak, the threats persist across borders and in other jurisdictions (e.g., the European Union), and the required responses sit awkwardly across consumer data protection and national security risk mitigation, as well as require an incessant understanding of what adversaries are doing in this space.
There are two immediate Western steps toward building a better solution. First, Western security professionals should close the analytical gap between privacy issues and national security issues, which are often treated separately yet manifest quickly into risk where they intersect. Second, U.S. policymakers should initiate bilateral and multilateral conversations on the commercial data threat space. Data threats are everywhere, and no country can go it alone.
Defining “Commercial Data” in Modern Intelligence and War
Nation-states have a wide range of ways they can obtain and steal information for their advantage. They can hack. They can recruit human spies. They can break into safes or launch satellites into space, taking high-resolution photographs from above. And, increasingly, there is another option on the table: purchasing data outright from private companies looking to sell it.
There are thousands of these data brokers in the United States, and they sell a wide range of data. This includes data on people’s demographic information, political preferences and beliefs, finances and transactions, health conditions and treatments, travel, devices, geolocations, and, in some slowly growing cases, genetic information. Data brokers in the United States operate globally, and there are data sellers based in other countries selling data on populations around the world, too. The U.S. Intelligence Community calls this “commercially available information,” which includes “any data or other information that is of a type customarily made available or obtainable and sold, leased, or licensed to members of the general public or to non-governmental entities for purposes other than governmental purposes.”
Adversaries of the United States can look to exploit this ecosystem for their own ends. When U.S. companies offer for sale the personal data of active-duty military servicemembers and their families, such as information on marriages and debts or comprehensive location histories, foreign adversaries can easily set up front companies to purchase that wealth of data. From there, the possibilities are numerous: intelligence operations relying on pre-assembled targeting packages; cyber operations leveraging insights into devices and behaviors; and even kinetic action based on the ability to monitor the locations of people, places, and people and places in connection to one another. And because the data broker industry collects data on all kinds of people, necessarily encompassing individuals such as university scientists, leading private sector engineers, and defense industrial base employees, the counterintelligence risks are significant.
These risks do not exist only in specific countries, such as to U.S. personnel in the United States or to German personnel in Germany. A 2024 investigation from Wired and 2025 follow-ups from 404 Media and Wired found that a Lithuanian company sold location data covering U.S. military forces in Europe to a U.S. data broker, which made it available for resale. Journalists could access hundreds of thousands of location signals from thousands of devices across Büchel Air Base (“a high-security German installation where as many as 15 US nuclear weapons are reportedly stored”), Grafenwöhr Training Area (“where thousands of US troops are stationed”), and Ramstein Air Force Base (“which supports some US drone operations”). Using this location data collected by a European firm and sold by an American one, they could even track mobile devices traveling to base schools for the children of U.S. military personnel—and see four devices from Ramstein Air Force Base travel off-site to a brothel.
Any foreign adversary interested in exploiting personal vulnerabilities, sourcing the names of personnel working at a facility, and otherwise tracking the personnel of Western governments around the clock would find tremendous value in this commercially available data.
Tackling the Broader Threat, Including from Russia
Germany’s advisory speaks to this risk in Europe. For one of the Russian security services, getting access to geolocation data on German defense and security companies could enable its personnel to identify persons of interest, sniff out susceptibility to bribery or blackmail, uncover unadvertised but sensitive facilities, and much more. Device-level commercial geolocation data can be particularly dangerous in this context: It can enable retroactive investigations, real-time tracking, and pattern-of-life analysis that aims to look into the future. When the Putin regime continues to carry out sabotage, assassination, crime-for-hire, and more in Europe, that adverse action against German interests could look kinetic as easily as it could look digital. Other adversaries could exploit this ecosystem of data, too, especially technologically sophisticated ones such as the Chinese government.
The German advisory describes several steps companies can take, including limiting the information shared online, exercising caution when traveling abroad, creating awareness campaigns on security procedures, and training regularly on secure technology. But it still begs the question of what Germany, and what its Western allies and partners similarly exposed in this arena (including the United States), can do on the structural level.
While the European Union implemented its globally known privacy regime, the General Data Protection Regulation (GDPR) in 2018, it unfortunately has proven insufficient to rein in this threat space. The prior Lithuanian example makes that clear. Certainly, the United States’ lack of privacy laws is disastrous not just for consumers but also for national security—there is much to be learned from other countries that have implemented more comprehensive regimes. But there are still gaps elsewhere, and those gaps can indirectly impact U.S. security as well.
Looking forward, there are significant opportunities for the U.S. government to work with allies and partners on intersectional issues around data, intelligence, privacy, and national security. Privacy regulators are understandably focused, most of the time, on consumer privacy in and of itself, not the national security dimensions. Analysts, operators, and policymakers in the national security arena, conversely, typically remain focused on “national security” issues per se and view topics such as consumer privacy as outside of their remit.
Where privacy and national security intersect, a gap is left—meaning concerted bilateral and multilateral dialogues between Washington and its partners could help to address those vulnerabilities. Those dialogues could start with identifying the data types of greatest security concern (such as geolocation data) and move toward establishing what policy frameworks, such as the U.S. government’s bulk data transfer and national security program, might provide a baseline for reining in the highly risky sale of personal data.
Additionally, the United States, Germany, and other allies and partners should work on operational responses to the problem. Military or other personnel working on shared Russia problems may be facing the same risks from the commercial data ecosystem when they visit Ukraine or collaborate in-person elsewhere in Europe. Building out the tools, technologies, and capabilities that these respective governments have to evaluate their own exposures, prioritize the most urgent issues to address, and help them securely communicate, travel, and live is imperative to better operational security in the current environment. Private sector firms, such as the defense and security base of many Western countries, could also leverage these capabilities.
Commercial data is everywhere, and the opportunities for adversary exploitation present a panoply of serious cyber, counterintelligence, physical security, and other threats to American and Western security. As yet another warning from a government makes clear, doing nothing is no longer an option.
Justin Sherman is a senior associate (non-resident) with the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies in Washington, D.C.