The trail your phone
leaves anyway.
↳ the carriers stopped; the market did not
Between 2018 and 2019, all four major US carriers shut down the programs that sold customer location data to third-party aggregators, after reporting revealed that a sheriff’s deputy had obtained location data by uploading his own car-insurance policy as the “legal authorization,” and that bounty hunters had bought access. In April 2024 the FCC fined the four carriers nearly $196.5 million in total: $80,080,000 for T-Mobile, $57,265,625 for AT&T, $46,901,250 for Verizon and $12,240,000 for Sprint.
The carriers challenged the fines and the appeals split. In June 2026 the Supreme Court ruled 8 to 1 for the FCC, holding that because a forfeiture order does not itself compel payment and the government must win a jury trial before collecting, issuing one without a jury does not violate the Seventh Amendment. The fines against Verizon, T-Mobile and Sprint are final. AT&T’s is not: its case was reversed and remanded, and the Fifth Circuit expressly did not reach its other arguments, with no new opinion as of 15 August 2026.
The consumer-facing win that survived untouched: two circuits held that device-location data is statutorily protected customer information under Section 222.
“all of the participating carriers ended their LBS programs. So our decision today does not address any ongoing practice… They have simply shifted to obtaining this same type of location information from other types of entities.”
Brendan Carr, dissenting from the AT&T order, before becoming FCC Chairman in January 2025 · FCC enforcement documents
That is the honest bottom line, and it comes from the agency’s own current chairman. The carriers got out of the business. The business did not need them.
↳ where it moved to: the advertising bid stream
Every time an app loads an ad, a request goes out describing the device and often its location, and it goes to many potential bidders at once. Companies collect from that stream whether or not they ever win a bid, which is exactly what the FTC described Mobilewalla doing.
The best current investigation is Databroker Files: Targeting the EU, published November 2025 by netzpolitik.org with BR, Le Monde, L’Echo and BNR. It is empirical rather than modelled: cumulatively more than 13 billion location points, obtained as free samples. The Belgian slice alone exposed devices at the European Commission headquarters, the European Parliament, NATO headquarters, and the home addresses of five officials. The series was still running as of 11 August 2026.
Two cautions about the numbers you will see quoted elsewhere. The widely-repeated claim that your phone broadcasts your location a specific number of times per day comes from an aggregate industry broadcast count divided by an assumed online population, drawn from a confidential unpublished source, and the organization that produced it called it a low estimate. We are not going to repeat it as a per-person figure. And the claim that one surveillance vendor profiled five billion people is that vendor’s own marketing claim, not a measurement.
On enforcement: no EU or German regulatory outcome resulted from the Databroker Files through August 2026, and the long-running challenge to the ad industry’s consent framework has gone the industry’s way on appeal twice. The fair summary is that it remains unresolved after more than four years of appeals.
↳ the leak that showed the plumbing:
In January 2025, a hacker who had contacted the company obtained data from Gravy Analytics using a stolen cloud key, and posted a sample. Not the database: a sample, containing more than 30 million location points, including devices at the White House, the Kremlin, the Vatican and military bases. Its parent filed with Norway’s data-protection authority and the UK ICO confirmed receiving a report.
The load-bearing finding is the one that reads backwards from the headlines. The files listed source app names, including dating apps, games, fitness trackers, period trackers, prayer apps and VPNs. But researchers who examined them concluded the data came from the advertising bid stream, not from code embedded in those apps. The named apps denied any relationship with the broker. As one researcher put it, the evidence suggested the broker was acquiring data from the bid stream “rather than code embedded into the apps themselves.”
So the correct lesson is not “delete that app.” It is that an app you trust can leak your location through an ad request it did not choose the recipients of. And the company was not shut down: it now redirects to its parent, which raised $28 million in December 2025 and is still marketing location data.
↳ three famous stories, told accurately:
Muslim Pro. Reporting established two parallel things: that the app sent data to the broker X-Mode, and that X-Mode sold to defense contractors. It never established that the US military received Muslim Pro users’ data specifically, and the reporters said so themselves. The FTC’s X-Mode complaint names neither the app nor the military.
Life360. The family-safety app was one of the largest sources of raw location data, earning $16 million from it in 2020. It is often said to have stopped in 2022. It did not: it exited the broker market with exceptions, and its own FY2025 annual report shows data revenue of $32.7 million in 2025, up from $26.6 million and $21.6 million in the two prior years, with risk factors conceding precise geolocation is a core component of its products.
The priest. In 2021 a publication bought commercially available app signal data from an unnamed vendor and used movement patterns to identify a US church official, who resigned. The data carried no name; the attribution was inference. It was never established that any particular app sold or leaked his data. Separately and unrelatedly, Norway fined Grindr NOK 65 million in December 2021 over conduct that ended in April 2020, upheld on appeal three times through October 2025. Those are two different stories and they get merged constantly.
And what a subscription buys. In October 2024, a private investigator hired by a privacy company obtained a free two-week trial of a location-tracking tool sold to government, and was told that merely contemplating future government work was “good enough” and that “they don’t actually check.” The demonstration showed devices at a mosque, a synagogue, and a juror parking lot. Read that as a capability demonstration by a company building a lawsuit, which is what it was, rather than as evidence that particular people were surveilled.