Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

By Global Cybersecurity Desk
Published: August 2026


1. Main Facts: The Launch of DecryptAds

Navigating the modern digital landscape has become an increasingly hazardous endeavor. For years, ordinary internet users, privacy advocates, and security researchers have struggled to answer a fundamental question: Who is actually tracking our movements, harvesting our data, and serving advertisements across the websites we visit and the mobile applications we rely on every day?

While this critical infrastructure data has technically always been semi-public, it has historically remained fragmented, difficult to parse, and siloed within the closed ecosystems of major advertising platforms.

That paradigm shifted with the launch of DecryptAds (decryptads.com), a powerful, free, and publicly accessible intelligence service designed to scrape, aggregate, and cross-reference adtech data. Created by a trio of veteran threat researchers—including Zach Edwards, Chief Research Officer at DecryptAds and a threat researcher at security firm Infoblox—the platform strips away the opaque layers of the digital advertising supply chain.

By systematically processing foundational adtech files like ads.txt, app-ads.txt, buyers.json, and sellers.json, DecryptAds allows anyone to generate a comprehensive, unified dossier on virtually any website or application. The platform transforms millions of disjointed data points into actionable insights, providing a vital shield against privacy violations, shadow data brokers, nation-state tracking, and malicious advertising networks.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

2. Chronology: The Evolution of Adtech Transparency and the Rise of DecryptAds

To understand why DecryptAds is a watershed moment for digital security, it is necessary to examine the timeline of online advertising governance:

  • 2017–2018 (The Introduction of ads.txt): In an effort to combat ad fraud and domain spoofing (where fraudulent actors pretend to be legitimate publishers), the Interactive Advertising Bureau (IAB) introduced ads.txt (Authorized Digital Sellers). This initiative was meant to bring transparency by allowing publishers to publicly declare who was authorized to sell their ad inventory. Later, app-ads.txt was introduced for mobile and smart TV applications, alongside sellers.json and buyers.json to map the financial intermediaries.
  • The Enforcement and Visibility Gap: While these files were technically public, they quickly became massive data dumps. Because no single entity cross-referenced them, corrupt actors, low-quality content farms, and shady data brokers could easily exploit cross-references, clone declaration sets, or quietly manipulate files without public scrutiny.
  • Recent Years (The Rise of State-Level Data Regulations): Recognizing the unchecked power of data harvesting, several U.S. states—most notably California, Oregon, Texas, and Vermont—passed landmark legislation requiring data brokers to officially register if they buy or sell consumer data originating within their borders. This regulatory shift gradually forced more shadow entities out into the open.
  • Mid-2026 (The Genesis of DecryptAds): Realizing that adtech data was useless without comprehensive cross-referencing, Zach Edwards and his co-founders built DecryptAds. Approaching adtech strictly from a security and threat intelligence perspective, the team launched the platform to unmask supply-chain vulnerabilities, geopolitical risk factors, and silent removals that legacy systems missed.

3. Supporting Data: Inside the Ad Supply Chain

The sheer volume of hidden tracking exposed by DecryptAds is staggering. Consider the digital footprint of major mainstream properties versus low-quality AI-generated content farms.

The ESPN Case Study

A baseline search for the premier sports network espn.com on DecryptAds reveals an astonishing 143 distinct ad partners and 19 registered data broker domains explicitly listed within its ads.txt and app-ads.txt files.

Of those data brokers, DecryptAds discovered that:

  • Nearly 50% actively collect precise geolocation data from visitors who do not employ ad-blocking software.
  • An additional 3% explicitly disclose the collection of advanced device fingerprints and highly sensitive personal information.

High-Risk Jurisdictions and Geopolitical Entanglements

DecryptAds features a specialized "Geo Risk" warning system that flags advertising entities rooted in adversarial nations or financial hubs closely linked to them—specifically highlighting China, Russia, and intermediary financial havens such as Cyprus and the United Arab Emirates (UAE).

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
  • Between Digital: Espn.com was found to maintain business relationships with four advertising entities tied to Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a nominal New York address but is flagged in DecryptAds dossiers as a Russian enterprise. Its financial payouts and publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank, which was placed under heavy U.S. sanctions following the 2022 invasion of Ukraine.
  • Targeting U.S. Military Personnel: A broader investigation into prominent U.S. military news properties—including Army Times, Air Force Times, Defense News, Navy Times, Marine Corps Times, and Federal Times—revealed that all of them authorize Between Digital to serve ads and track users. They also permit tracking from two UAE-based entities and an anonymous holding firm in Panama. According to DecryptAds data, Between Digital actively siphons ad data across approximately 55,000 partner websites.
  • The Opera Browser Paradox: While the operational headquarters of the popular Opera web browser remain in Oslo, Norway, the company has been majority-owned and controlled by Chinese tech conglomerate Kunlun Tech since 2016. DecryptAds profiles for opera.com identify 27 registered data brokers—including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These entities represent just 7% of the total ad partners declared in Opera’s public files.

4. Official Responses and Investigative Insights

Security researchers have long warned that the adtech ecosystem functions as an unregulated Wild West, where bad actors can easily evade accountability.

The Conflict of Interest in Bidding

Investigating Between Digital’s app-ads.txt ecosystem uncovered hundreds of domains hosting low-grade mobile web games interrupted by constant ad prompts. Zach Edwards noted that Between Digital’s own declarations show the company acting as both a publisher and a reseller on roughly two-thirds of its portfolio.

"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards explained to security journalist Brian Krebs. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."

Quiet Removals and Hidden Fraud

When ad networks suspect that an exchange partner is engaged in fraudulent traffic, bot-driven clicks, or malvertising, they frequently enact "quiet removals." Rather than issuing a public warning or sharing intelligence across the industry, the network simply purges the offender from its sellers.json file overnight.

To bridge this visibility gap, DecryptAds introduced a Quiet Removals Feed, which aggregates and tracks sudden drops across multiple ad exchanges. This feed allows researchers to trace how blacklisted operators attempt to rebrand, migrate domains, or spin up new proxy shell companies under different aliases.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

5. Implications: Malvertising, AI Slop, and Protecting Yourself

The convergence of unvetted adtech partners, automated content farms, and geopolitical bad actors has created severe systemic risks for everyday internet users and enterprise networks alike.

The Rise of AI Slop and Zero-Click Exploits

While major high-traffic properties like ESPN or major news outlets employ robust security teams and specialized content-filtering tools to intercept malicious ads, the explosion of AI-generated "slop" websites has created a superhighway for cybercrime. These automated content farms—churning out low-quality recipes, home improvement tips, and generic blog posts—rarely invest in security verification.

Consequently, cybercriminals routinely leverage these low-tier content farms to execute malvertising campaigns. These malicious ads bypass basic safety checks, attempting to foist malware, execute zero-click drive-by downloads, or redirect unsuspecting visitors to sophisticated phishing infrastructure.

Edwards warns that government employees and enterprise workers are frequently targeted by these exact vectors. Without parsing underlying ad supply chain data, security teams remain completely blind to the threat infrastructure targeting their personnel.

Recommended Mitigation Strategies

Given the profound privacy violations and security risks inherent in the modern digital advertising ecosystem, security experts overwhelmingly endorse a proactive, multi-layered approach to blocking digital tracking:

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security
  1. Network-Level Blocking (Pi-hole): For technical users, setting up a low-cost Raspberry Pi running Pi-hole creates a local network-wide DNS sinkhole. This approach effectively strips advertisements and known trackers from every device connected to your home network.
  2. Browser-Level Extensions: On standard desktop and laptop browsers, open-source extensions such as uBlock Origin Lite provide robust, lightweight blocking capabilities. iPhone and iPad users can utilize alternatives like Adblock Plus, while advanced users can configure custom blocking lists from repositories like easylist.to.
  3. App Caution and Minimization: Mobile applications are primary vectors for high-precision surveillance and data harvesting. Whenever possible, security experts recommend interacting with services directly through a hardened web browser rather than installing dedicated mobile or smart TV applications. Furthermore, users can run app domains through DecryptAds to audit their corporate ownership and risk profiles before granting them permissions.

As digital threats continue to evolve, tools like DecryptAds represent a vital step toward democratizing threat intelligence, shifting the balance of power away from hidden data brokers and back into the hands of the public.