{"id":983,"date":"2026-08-19T21:25:20","date_gmt":"2026-08-19T21:25:20","guid":{"rendered":"https:\/\/ovfile.com\/?p=983"},"modified":"2026-08-19T21:25:20","modified_gmt":"2026-08-19T21:25:20","slug":"new-service-decryptads-exposes-the-hidden-adtech-supply-chain-and-global-data-brokers","status":"publish","type":"post","link":"https:\/\/ovfile.com\/?p=983","title":{"rendered":"New Service DecryptAds Exposes the Hidden Adtech Supply Chain and Global Data Brokers"},"content":{"rendered":"<p>For ordinary internet users, navigating the modern web often feels like stepping through a digital minefield. Determining who is truly responsible for serving ads on a favorite news site or understanding which hidden entities are harvesting behavioral data from mobile applications can seem nearly impossible. While a vast amount of this operational data is technically semi-public, it has traditionally been buried deep inside complex files and tightly controlled within the walled gardens of large advertising platforms. <\/p>\n<p>That dynamic is beginning to shift thanks to DecryptAds, a powerful and free new service designed to scrape, correlate, and demystify adtech data. By translating dense developer files into accessible insights, the platform allows anyone to quickly learn a great deal about the complex web of entities tracking their online behavior.<\/p>\n<p>The newly launched platform operates by continuously monitoring and scraping the public-facing configuration files that websites and mobile applications use to disclose their business partnerships. These files include ads.txt, which lists authorized digital sellers and data brokers permitted to run advertisements or harvest data on a given site; app-ads.txt, which extends similar disclosures to mobile and smart TV applications; and buyers.json and sellers.json, which document the corporate entities buying, selling, or reselling digital ad inventory.<\/p>\n<p>Zach Edwards, chief research officer for DecryptAds and a threat researcher at the security firm Infoblox, explains that he and his co-founders built the service because isolated configuration files offer little value on their own. To truly understand the digital advertising ecosystem of any given website or application, these disparate data points must be cross-referenced and analyzed at scale. <\/p>\n<p>Edwards notes that while DecryptAds functions fundamentally as an adtech analysis tool, it approaches the industry primarily through a security lens. The platform is specifically tailored to address a wide range of privacy and security use cases that have historically been underserved by traditional security products, such as tracking down the origins of malicious advertising campaigns, identifying ad networks tied to geopolitical adversaries, and detecting the rapid proliferation of low-quality, AI-generated content farms.<\/p>\n<figure class=\"article-inline-figure\"><img src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/decryptads-ESPN.png\" alt=\"Who\u2019s Tracking You? Use This New Service to Find Out \u2013 Krebs on Security\" class=\"article-inline-img\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<p>According to Edwards and the platform&#8217;s documentation, supply-chain integrity vulnerabilities rarely manifest within a single, isolated file. Instead, they typically appear as broken cross-references between ads.txt and sellers.json files, cloned declaration sets across completely unrelated domains, or suspicious seller removals that only become apparent when viewed across multiple exchanges.<\/p>\n<p>To illustrate the depth of these hidden networks, a search on DecryptAds for the popular sports network ESPN reveals a staggering 143 ad partners and 19 registered data broker domains listed within its public authorization files. The visibility into these data brokers is expanding largely due to recent legislation in four U.S. states\u2014California, Oregon, Texas, and Vermont\u2014which now require data brokers to officially register if they buy or sell consumer information originating from those jurisdictions. DecryptAds reports that nearly half of the data brokers linked to ESPN are actively collecting precise geolocation data from visitors who do not utilize ad-blocking software, while others openly disclose the collection of device fingerprints and sensitive personal information.<\/p>\n<p>High-Risk Ad Partners and Geopolitical Exposure<\/p>\n<p>Beyond basic data collection practices, DecryptAds provides critical visibility into the financial beneficiaries and national origins of advertising firms operating within major digital properties. The platform features prominent warnings when an app or website maintains commercial relationships with advertising partners based in high-risk geographic regions, such as Russia and China, or in nations maintaining close financial and political ties to them, including Cyprus and the United Arab Emirates.<\/p>\n<p>As an example, DecryptAds highlights that ESPN maintains business relationships with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a corporate address in New York. However, the dossier maintained by DecryptAds classifies Between Digital as a Russian firm, noting that its publisher payout offers are processed through Alfa Bank, Russia&#8217;s largest private commercial bank. Alfa Bank was placed under heavy financial sanctions by the United States government following Russia&#8217;s invasion of Ukraine in 2022. <\/p>\n<p>A broader search across several prominent U.S. military news publications\u2014including Army Times, Air Force News, Defense News, Navy Times, Marine Corps Times, and Federal Times\u2014reveals that all of these platforms similarly authorize Between Digital to serve advertisements and track their readers. Additional partners listed on these military-focused sites include entities located in the UAE and the corporate secrecy jurisdiction of Panama. According to DecryptAds tracking data, Between Digital currently collects advertising data across approximately 55,000 partner websites.<\/p>\n<figure class=\"article-inline-figure\"><img src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/espn-supplychain.png\" alt=\"Who\u2019s Tracking You? Use This New Service to Find Out \u2013 Krebs on Security\" class=\"article-inline-img\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<p>Further examination of Between Digital\u2019s public app-ads.txt files uncovers hundreds of domains tied to simple web-based games that frequently interrupt users with advertisements. Edwards points out that Between Digital\u2019s own declarations indicate the firm acts as both a publisher and a reseller on roughly two-thirds of its portfolio. This dual role creates inherent conflicts of interest by allowing the company to play both sides of the bidding equation, directing client ad spend toward its own operated properties and internal infrastructure. For years, Edwards argues, the broader digital advertising ecosystem has suffered from a profound lack of independent oversight regarding these self-declared configuration files.<\/p>\n<p>The sprawling reach of foreign-controlled adtech is also evident on mainstream platforms like the Opera web browser. Although Opera maintains its operational headquarters in Oslo, Norway, it has been majority-owned and controlled by the Chinese firm Kunlun Tech since 2016. A profile of Opera&#8217;s primary web domain on DecryptAds identifies 27 registered data brokers, including 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. Notably, these identified entities represent just seven percent of the total adtech partners specified within Opera&#8217;s authorization files.<\/p>\n<p>Uncovering Malicious Networks and Quiet Removals<\/p>\n<p>One of the more complex features offered by DecryptAds is its legal dossier lookup tool. Although a comprehensive search can take several minutes to process, the system aggregates deep investigative data regarding domain ownership histories, registration timelines, corporate aliases, and underlying connections to advertising networks.<\/p>\n<p>This investigative capability recently proved valuable in untangling a widespread malware operation involving popular TV streaming sticks sold under the brand name H96. Security researchers from Bitsight discovered that these streaming devices quietly rented out the internet connections of unsuspecting users to external strangers. When the hardware was not actively being used to stream unauthorized video content, the devices engaged in automated fraud by spoofing mobile phone signatures to click on ads hosted across networks of artificial intelligence-generated slop websites. Bitsight&#8217;s investigation linked the malicious mobile applications embedded in the H96 streaming sticks to a Chinese entity known as the Fengwo Group, which simultaneously operated the network of low-quality advertising landing pages.<\/p>\n<p>A legal dossier query on DecryptAds for a dormant Fengwo Group domain associated with these AI content farms reveals shared seller identifiers with unrelated gaming sites. Pivoting on those seller IDs uncovers hundreds of active websites operating within Russian ad networks like Yandex, which continuously pepper visitors with low-quality games and ad-heavy utilities.<\/p>\n<figure class=\"article-inline-figure\"><img src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/decryptads-georisk.png\" alt=\"Who\u2019s Tracking You? Use This New Service to Find Out \u2013 Krebs on Security\" class=\"article-inline-img\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<p>To help security analysts track how ad networks police themselves, DecryptAds incorporates a quiet removals feed. According to Edwards, when major ad exchanges suspect that a specific partner is engaging in fraudulent traffic generation or distributing malicious advertisements, they frequently purge the offender from their sellers.json files without issuing public warnings or notifying the broader industry. This silent blacklisting allows problematic adtech firms to evade public accountability and quietly resume operations elsewhere. The DecryptAds feed correlates these removals across multiple ad exchanges, providing researchers with vital visibility into industry-wide enforcement actions that would otherwise remain opaque.<\/p>\n<p>The Convergence of Malvertising and AI Content Farms<\/p>\n<p>Malvertising\u2014the malicious injection of online advertisements designed to distribute malware or direct users to phishing infrastructure\u2014remains a persistent threat across the digital advertising landscape. However, Edwards emphasizes that contemporary malvertising attacks have largely migrated away from high-traffic destinations like major news outlets, which typically employ sophisticated third-party security tools to intercept fraudulent ads. Instead, threat actors increasingly target newly generated AI content farms that completely lack security oversight.<\/p>\n<p>These automated content sites, populated entirely by machine-generated blog posts and imagery covering topics ranging from home improvement to consumer technology, rely on low-quality advertising partners to maximize monetization. Without adequate filtering, these sites function as frictionless conduits for delivering malicious payloads to unsuspecting web users who arrive via search engine results. <\/p>\n<p>Edwards stresses that effectively combating malvertising and programmatic ad fraud will ultimately require greater transparency and data-sharing from major ad networks. Specifically, he advocates for the broader industry disclosure of the supply chain object, a structured data element attached to programmatic bid requests that allows buyers to trace every seller, reseller, and intermediary involved in passing an ad impression. Without access to these server-side supply chain objects, organizations targeted by sophisticated cyber threats often remain blind to the exact origins of malicious ad injections.<\/p>\n<p>To facilitate automated research and integration into existing threat intelligence workflows, DecryptAds provides an application programming interface that allows developers and researchers to query its aggregated datasets programmatically.<\/p>\n<figure class=\"article-inline-figure\"><img src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/fengwogroupwebsites.png\" alt=\"Who\u2019s Tracking You? Use This New Service to Find Out \u2013 Krebs on Security\" class=\"article-inline-img\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<p>Defending Against Surveillance and Tracking<\/p>\n<p>Given the pervasive tracking and security risks inherent in the modern ad ecosystem, many cybersecurity professionals advocate for the comprehensive blocking of online advertisements at the browser or network level. Beyond mitigating the risk of exposure to malicious ads, this approach significantly curtails the ability of data brokers and adtech firms to construct detailed behavioral profiles on individual users.<\/p>\n<p>For conventional desktop and laptop web browsing, open-source browser extensions such as uBlock Origin Lite offer robust, well-maintained protection. Similar extensions are supported on select mobile browsers operating on Android devices, while alternative tools like Adblock Plus provide functional filtering capabilities for Apple iOS users. Advanced users frequently rely on specialized script blockers like NoScript to prevent unauthorized JavaScript execution, though such granular controls often require constant manual management to ensure websites render correctly.<\/p>\n<p>For more technically inclined individuals seeking network-wide protection, hardware-based solutions offer an efficient and scalable alternative. Utilizing a low-cost, credit-card-sized computer such as a Raspberry Pi running software like Pi-hole allows users to establish a local DNS sinkhole that blocks advertisements and tracking requests across every connected device on a home network.<\/p>\n<p>Security experts also advise caution regarding the proliferation of mobile applications. While major digital platforms frequently pressure users to install dedicated mobile apps under the guise of an improved user experience, these applications often serve to extend surveillance capabilities, enabling companies to collect and monetize far more granular location and device data than traditional web browsers permit. Furthermore, many modern applications automatically opt users into data-sharing agreements designed to train large language models. As a result, security researchers recommend carefully evaluating the necessity of mobile apps and consulting transparency platforms like DecryptAds to understand the hidden adtech partnerships driving modern digital services.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For ordinary internet users, navigating the modern web often feels like stepping through a digital minefield. Determining who is truly responsible for serving ads on a favorite news site or understanding which hidden entities are harvesting behavioral data from mobile applications can seem nearly impossible. While a vast amount of this operational data is technically [&hellip;]<\/p>\n","protected":false},"author":26,"featured_media":982,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[358],"tags":[1167,1170,1169,359,403,1165,1166,1026,415,362,360,361,364,1168],"class_list":["post-983","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-data-privacy","tag-adtech","tag-brokers","tag-chain","tag-cybersecurity","tag-data","tag-decryptads","tag-exposes","tag-global","tag-hidden","tag-leaks","tag-privacy","tag-security","tag-service","tag-supply"],"_links":{"self":[{"href":"https:\/\/ovfile.com\/index.php?rest_route=\/wp\/v2\/posts\/983","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ovfile.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ovfile.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ovfile.com\/index.php?rest_route=\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/ovfile.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=983"}],"version-history":[{"count":0,"href":"https:\/\/ovfile.com\/index.php?rest_route=\/wp\/v2\/posts\/983\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ovfile.com\/index.php?rest_route=\/wp\/v2\/media\/982"}],"wp:attachment":[{"href":"https:\/\/ovfile.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ovfile.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ovfile.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}