Foreign Software Found in Apps Marketed to US Military Personnel
A new study reveals that over 12 percent of mobile applications targeted at US service members contain software components originating from China and Russia. These findings highlight significant national security risks regarding the potential for foreign surveillance of military personnel and sensitive base locations.
A recent collaborative study conducted by researchers at Purdue University, the US Military Academy at West Point, and Florida International University has identified that more than one in eight mobile applications marketed specifically toward US military personnel contain software code developed by companies in China or Russia. This discovery underscores a growing concern among security experts regarding the vulnerability of service members to data harvesting by foreign adversaries, which could potentially expose troop movements, residential locations, and the operational routines of personnel stationed at sensitive facilities.

The research highlights specific instances where apps used by military members to rate base living conditions incorporated code from Huawei, a Chinese telecommunications firm previously designated as a national security threat by US regulators in 2020 as reported by Ars Technica. Additionally, the study identified apps utilizing Russian advertising services, such as Yandex. These software components are often integrated into the broader, largely unregulated digital advertising ecosystem that tracks user behavior across both civilian and military populations without distinction.
The implications of this data exposure extend beyond theoretical risks. In April, US Central Command confirmed to Senator Ron Wyden that it had received reports of adversaries exploiting commercial location data to surveil American personnel in the Middle East according to Ars Technica. This acknowledgment serves as the first official confirmation that commercial data-brokerage practices are being leveraged to track troops in active conflict zones, a scenario that security researchers have warned about for nearly a decade.
Joshua Shinkle, a PhD researcher at Purdue University and the study’s lead author, emphasized the necessity of this research in fostering better privacy standards. He noted that the findings are intended to assist military-affiliated personnel, developers, and policymakers in making more informed decisions regarding the security of the software ecosystem surrounding the armed forces. As the digital landscape continues to evolve, the challenge remains in balancing the convenience of commercial applications with the stringent security requirements necessary to protect those serving in the military from sophisticated, data-driven surveillance.