DecryptAds Unveils Hidden Adtech Ecosystems, Exposing 'Geo-Risk' Partners and Data Brokers
A new, free service called **DecryptAds** is transforming adtech transparency by scraping and correlating publicly available data to reveal the complex networks of companies tracking users. This powerful tool provides security professionals and privacy-conscious individuals with unprecedented insight into who is collecting their data and where those entities are located, highlighting potential supply chain integrity issues and 'geo-risk' partners.
Determining the entities responsible for displaying ads or harvesting data from websites and mobile apps has traditionally been a daunting task, often confined within the opaque walls of large advertising platforms. However, the newly launched **DecryptAds** service aims to dismantle these barriers, offering a comprehensive and accessible platform for uncovering the intricate web of adtech relationships.
**DecryptAds** continuously scrapes and analyzes publicly available files that websites and apps use to declare their advertising and data collection partners. These critical files include:
* **ads.txt**: Lists all adtech companies and data brokers authorized to run ads or collect data from a site.
* **app-ads.txt**: Identifies entities permitted to harvest data or display ads on mobile and smart TV applications.
* **buyers.json/sellers.json**: Discloses the entities involved in buying, selling, or reselling ad inventory for a given site or app.

**Zach Edwards**, Chief Research Officer for **DecryptAds** and a threat researcher at **Infoblox**, explained that the service was developed to address the critical need for cross-referencing this adtech data. He emphasized that individual files rarely provide a complete picture of the advertising ecosystem.
"It's an adtech tool but we're trying to approach adtech from a security perspective," Edwards stated. "It's really built for a lot of privacy and security use cases that have been dramatically underserved."
These use cases span a wide range of security and privacy concerns, including tracing the origins of malicious ads, identifying ad networks linked to adversarial nations, and detecting the proliferation of AI-generated "slop" websites and apps.
"Supply-chain integrity issues rarely live in a single file," the **DecryptAds** site explains. "They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisherβs authorized-seller list."
A search for **espn.com** on **DecryptAds** reveals a staggering 143 ad partners and 19 registered data broker domains declared within its **ads.txt** and **app-ads.txt** files. This data broker information is becoming increasingly available due to new regulations in states like California, Oregon, Texas, and Vermont, which mandate data broker registration. **DecryptAds** further reports that nearly half of these data brokers collect geolocation data from **espn.com** visitors, while three explicitly state they collect device fingerprints and sensitive personal information.

## High-Risk Ad Partners
Beyond basic partner identification, **DecryptAds** offers crucial insights into the national origins of advertising firms, flagging partners based in "geo-risk" areas such as China, Russia, Cyprus, and the United Arab Emirates (UAE).
For instance, **espn.com** reportedly collaborates with four advertising entities based in Russia, China, or the UAE. One such firm, **Between Digital**, despite listing a New York address, is flagged by **DecryptAds** as a Russian entity. Its dossier indicates that its publisher offers are processed through **Alfa Bank**, Russiaβs largest private commercial bank, which was sanctioned by the U.S. in 2022.
Intriguingly, several prominent U.S. military news websitesβincluding **armytimes.com**, **airforcetimes.com**, **defensenews.com**, **navytimes.com**, **marinecorpstimes.com**, and **federaltimes.com**βalso allow **Between Digital** to serve ads and track users. These sites additionally partner with entities in the UAE and Panama, a jurisdiction known for ownership secrecy. **DecryptAds** estimates that **Between Digital** collects ad data from approximately 55,000 partner websites.

Further analysis of **Between Digital**'s **app-ads.txt** file reveals hundreds of domains hosting simple web-based games frequently interrupted by ads. Edwards noted that **Between Digital**'s own declarations show the company acting as both a publisher and a reseller for about two-thirds of its portfolio. This dual role, he explained, can create conflicts of interest by allowing the company to direct client spending towards its owned and operated properties.
"The problem we have right now is that for years weβve had almost no one policing these ads.txt and app-ads.txt files," Edwards commented.
The **Opera** web browser, while popular, is majority-owned by the Chinese company **Kunlun Tech** since 2016. **Opera.com**'s profile on **DecryptAds** identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. Notably, these companies represent only seven percent of the adtech partners specified in **Opera.com**'s **ads.txt** and **app-ads.txt** files.
## Legal Dossiers
One particularly powerful feature of **DecryptAds** is its ability to compile comprehensive legal dossiers, a capability that promises to be invaluable for privacy advocates and security researchers alike.