Peering Behind the Adtech Curtain: How DecryptAds Exposes the Hidden Surveillance Economy

For the average internet user, the digital ecosystem is a black box. We click a link, a page loads, and advertisements appear—often tailored with eerie precision to our recent searches or location. Behind this seamless experience lies a sprawling, opaque web of data brokers, adtech intermediaries, and opaque supply chains. Historically, understanding the entities responsible for harvesting mobile app data or serving ads has been a task reserved for industry insiders.

A new, free service called DecryptAds aims to shatter this wall of obscurity. By scraping and correlating publicly available adtech data, the platform provides a transparent window into the complex relationships governing the digital advertising world, offering users and security researchers alike a way to visualize exactly who is tracking them.

The Mechanics of Transparency

At the heart of the digital advertising ecosystem are standardized, yet largely ignored, text files hosted on nearly every major website and mobile application. These files—ads.txt, app-ads.txt, and sellers.json—are designed to disclose which companies are authorized to sell ad inventory or collect user data. While intended to provide transparency, they are often difficult for the average person to parse or cross-reference.

DecryptAds, spearheaded by Chief Research Officer Zach Edwards—a seasoned threat researcher at Infoblox—has automated the process of synthesizing this data. “It’s an adtech tool, but we’re trying to approach adtech from a security perspective,” Edwards explained. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

By scraping these files across the web, DecryptAds allows users to query any domain to see a list of every authorized partner. As the service demonstrates, a single ads.txt file rarely tells the whole story. Supply-chain integrity issues, Edwards notes, manifest as broken cross-references, cloned declaration sets across unrelated domains, and supply paths that appear in bid logs but are absent from a publisher’s official list.

A Data-Driven Chronology of Adtech Oversight

The rise of DecryptAds comes at a critical juncture in data privacy legislation. In recent years, California, Oregon, Texas, and Vermont have passed landmark laws requiring data brokers to formally register their operations if they buy or sell consumer data. This regulatory shift has forced a level of disclosure that was previously unthinkable.

In the past, identifying the sheer volume of trackers on a major platform like espn.com was a manual, laborious process. Today, a quick search on DecryptAds reveals that the site maintains partnerships with 143 ad partners and 19 registered data brokers. Alarmingly, the service reports that nearly 50% of these brokers collect geolocation data from users who have not enabled ad-blocking software, while others actively harvest device fingerprints and sensitive personal identifiers.

The tool’s launch addresses a long-standing "visibility gap." For years, ad networks have been accused of quietly removing bad actors from their ecosystems without public disclosure. DecryptAds combats this through its "Quiet Removals" feed, which tracks when companies are purged from sellers.json files, preventing shady firms from simply rebranding or shifting operations without scrutiny.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Supporting Data: The "Geo-Risk" and Supply Chain Integrity

Perhaps the most alarming feature of DecryptAds is its "Geo-Risk" filter, which flags adtech partners based in nations with adversarial relationships to the West, or in jurisdictions known for lax financial oversight.

A search of espn.com reveals partnerships with four advertising entities based in Russia, China, or the United Arab Emirates (UAE). One such firm, Between Digital, lists a New York address but is identified by DecryptAds as a Russian entity. Furthermore, the platform links Between Digital’s publisher offers to Alfa Bank—Russia’s largest private commercial bank, which has been under U.S. sanctions since the 2022 invasion of Ukraine.

The risks extend beyond sports news. When researchers queried top U.S. military-focused websites—including armytimes.com, defensenews.com, and navytimes.com—they found that these sites were also serving ads through Between Digital and other entities located in the UAE and Panama. With Between Digital collecting ad data across an estimated 55,000 partner websites, the scope of this potential data leakage is massive.

Official Responses and Industry Accountability

When approached regarding these findings, industry transparency remains a point of contention. Edwards argues that the adtech industry relies on "security by obscurity," where reports on ad fraud are siloed among a few high-paying clients rather than made public.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

"The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files," Edwards stated. He suggests that the solution lies in the adoption of the "Supply Chain Object" (SCO)—structured data attached to every bid request that reveals every intermediary involved in an ad’s lifecycle. Currently, most major ad networks refuse to share this data server-side, effectively shielding the identity of the final buyers who serve malware payloads to unsuspecting users.

Implications: Malvertising and the Rise of "AI Slop"

The intersection of malvertising and AI-generated "slop" websites represents a new frontier in cybersecurity threats. Malvertising, the practice of using ad networks to deliver malware or phishing links, has largely migrated away from high-traffic, well-defended websites to low-quality, AI-populated content farms.

These "slop" sites, which feature machine-generated articles on everything from home improvement to recipes, often bypass the rigorous vetting processes found on major news outlets. "None of these slop AI content farms are paying for that kind of protection," Edwards noted. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads."

This creates a dangerous feedback loop. Recent investigations into H96 TV streaming sticks revealed that these devices were being used to spoof mobile phone traffic to click ads on these AI-generated websites. By using DecryptAds to trace the seller IDs associated with these sites, researchers have been able to link hundreds of seemingly disparate, low-quality sites to the same underlying ad-fraud infrastructure.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

Protecting Yourself in an Observed World

The implications for the average consumer are stark: modern mobile apps and web destinations are increasingly designed to maximize data extraction. While many companies push their mobile apps as a "better experience," the reality is often that these apps facilitate deeper, more persistent tracking and enable data harvesting for AI model training.

For those looking to mitigate these risks, the advice from the security community remains consistent:

  1. Ad Blocking: For desktop users, uBlock Origin Lite remains the gold standard. For mobile, the options are more limited, though browser-based ad blocking (such as on Firefox for Android) is highly recommended.
  2. Network-Level Defense: Technically inclined users should consider a Pi-hole or similar DNS-sinkhole solution, which blocks ads and tracking at the router level, protecting every device connected to the home network.
  3. App Hygiene: Be extremely cautious about which apps you install. If a service offers a website version, use it in a browser rather than downloading a dedicated app. Avoid "smart" hardware that frequently relies on intrusive data-broker relationships.
  4. Transparency as a Tool: Services like DecryptAds are not just for experts. By checking a site’s dossier before engaging, users can make informed decisions about whether to trust a platform with their attention—and their data.

As we move deeper into an era of automated content and pervasive digital surveillance, tools like DecryptAds provide a much-needed counterbalance. By turning the industry’s own transparency files against its most predatory actors, we can begin to reclaim a measure of privacy in an increasingly transparent digital landscape. The "walled gardens" of adtech are finally being opened, and the view inside is a wake-up call for every internet user.