The researcher who spent $300K buying location data just showed the Pentagon what it could do with yours

12 Min Read

Mike Yeagley spent $300,000 of his own money to buy location data harvested from smartphones across the globe, then handed his findings directly to the Pentagon and other U.S. government agencies.

What he discovered wasn’t theoretical. It was a working blueprint for mass surveillance of American civilians—one that requires no warrant, no court order, and no legal framework explicitly forbidding it. The data was already for sale. The technology to weaponize it already exists. The only missing piece was someone willing to show officials what they could actually do with it.

Key Findings:
  • The Data Is Already for Sale: Commercial location brokers aggregate precise movement signals from hundreds of millions of devices and sell access to anyone willing to pay—including government agencies—without requiring a warrant or court order.
  • The Consent Gap Is Structural: Data flows from your phone through advertising networks to brokers to buyers in a chain that is entirely legal under current U.S. law, with no federal privacy statute explicitly prohibiting government purchase of this data.
  • The Demonstration Was Real: Yeagley’s $300,000 experiment used actual commercial datasets to prove, inside a Pentagon office, that persistent individualized tracking of American civilians is operationally achievable today.

Yeagley’s experiment exposes a structural gap in American privacy law that has existed for years but is only now becoming impossible to ignore. Commercial data brokers—companies that aggregate location signals from mobile apps, advertising networks, and location services—operate in a regulatory shadow. They buy and sell precise movement patterns of millions of Americans without explicit consent, without transparency, and without any legal requirement to ask permission. The data flows from your phone to data aggregators to brokers to buyers, each transaction legal under current law.

The Pentagon and other government agencies have long known this data exists. But Yeagley’s hands-on demonstration appears to have crystallized something abstract into something concrete: a working model of how location data could enable the kind of persistent, individualized tracking that was previously the domain of classified intelligence programs.

How Does Commercial Location Tracking Actually Work?

Here’s the mechanics of what Yeagley did. He purchased location datasets—the kind available on the commercial market to anyone with money—and then analyzed what those datasets could reveal about specific individuals and patterns of movement. He then presented his findings to Pentagon officials, showing them, in practical terms, what surveillance capability they could access if they chose to buy or broker access to commercial location data. The demonstration wasn’t a theoretical exercise. It was a proof of concept using real data, real movement patterns, and real people.

The implications are immediate and personal. Your phone generates location signals constantly—through GPS, cell tower triangulation, WiFi positioning, and Bluetooth beacons. Apps you use, services you’ve granted permission to, and advertising networks embedded in apps you’ve never heard of all collect these signals. Most users have no idea this is happening. Most have never explicitly consented to it in any meaningful way. And most have no way to know where that data ends up.

By the Numbers:
• Data brokers aggregate location signals from hundreds of millions of devices across the United States, packaging movement trajectories, dwell times, and behavioral patterns for commercial sale
The FTC’s January 2024 enforcement action against X-Mode Social and Outlogic confirmed that sensitive location data—including visits to medical facilities, religious sites, and political gatherings—was being sold without meaningful user consent
A March 2024 FTC analysis found that data brokers like InMarket collected location data sourced from publicly available feeds and other brokers, compounding the opacity of the supply chain

Why Does This Mirror the Cambridge Analytica Playbook?

This mirrors a pattern we’ve seen before. During the Cambridge Analytica scandal, the world learned that Facebook data on millions of Americans—ostensibly collected for benign purposes like app functionality and ad targeting—was harvested, weaponized, and used for behavioral micro-targeting in political campaigns. The data itself wasn’t obtained illegally. The platforms’ terms of service permitted it. The legal framework allowed it. What shocked people was not the existence of the data, but the revelation of what could be done with it at scale.

Yeagley’s location-data demonstration follows the same structural logic: data collected for one purpose (app functionality, advertising), aggregated by intermediaries (data brokers), and then repurposed for surveillance and tracking. The consent erosion is identical. The scale is identical. The gap between what’s legal and what feels like an invasion of privacy is identical. As documented in the legacy of Cambridge Analytica, the scandal’s most durable lesson was not about one rogue firm—it was about the infrastructure that made the firm possible. That infrastructure is still operating, now applied to physical movement rather than psychological profiles.

The difference is that Yeagley didn’t wait for a scandal to break. He bought the data himself, spent his own money to prove the capability, and walked it directly into a Pentagon office. Understanding how surveillance capitalism monetizes human data makes Yeagley’s method entirely legible: he simply did what any well-funded advertiser, hedge fund, or political operation could do, then made the result visible to people with the authority to respond.

Is the Government Legally Allowed to Buy Your Location Data?

What makes this moment significant is timing. Government agencies have been buying location data through commercial brokers for years, but the practice has remained largely opaque. Congressional inquiries have raised questions. Privacy advocates have warned about it. But there’s been no unified demonstration of what the actual capability looks like in practice. Yeagley’s work appears to have provided that.

The data Yeagley purchased came from the same commercial ecosystem that’s available to advertisers, hedge funds, real estate investors, and anyone else willing to pay. Data brokers aggregate location signals from hundreds of millions of devices. They sell access to this data in various forms—heatmaps showing foot traffic in specific locations, individual movement trajectories, behavioral patterns tied to specific demographics. The granularity is striking. A buyer can identify not just that someone visited a location, but when they arrived, how long they stayed, and where they went next.

For government agencies, the appeal is obvious. Traditional surveillance requires warrants, court orders, and oversight mechanisms. Commercial location data requires none of those things. It’s already collected. It’s already aggregated. It’s already for sale. The only legal question is whether an agency can purchase it—and so far, the answer appears to be yes.

Expert Analysis:
• The Senate Commerce Committee’s examination of the data broker industry’s collection and sale of consumer data identified a fundamental accountability gap: brokers operate largely outside the direct relationship between consumer and service provider, making informed consent structurally impossible for most users
• The FTC has moved against individual brokers—X-Mode, InMarket, Avast—but each enforcement action addresses a single actor in a market with dozens of comparable operators, leaving the underlying commercial infrastructure intact
• Without a comprehensive federal privacy statute, the legal question of whether government agencies may purchase commercial location data remains unanswered by any binding authority

Yeagley’s decision to spend $300,000 of his own money to demonstrate this capability suggests he believed the information was too important to wait for official channels or media investigations. He essentially forced a confrontation between what the law permits and what the public might reasonably expect to be protected.

The Pentagon’s response to Yeagley’s demonstration hasn’t been fully detailed in public reporting, but the fact that he was able to walk into a Pentagon office with this data and these findings suggests the agencies involved took it seriously. Whether that leads to policy changes, new regulations, or simply a more careful approach to how government agencies purchase commercial data remains unclear.

What’s certain is that your location data is for sale right now. Apps you use are selling it. Advertising networks are aggregating it. Data brokers are packaging it. And government agencies are buying access to it—all without your knowledge or explicit consent. The question of whether we are already living in a world without meaningful privacy is no longer hypothetical when a private citizen can replicate a surveillance capability and demonstrate it to the Pentagon for $300,000.

The legal framework that permits this hasn’t caught up to the technology. The Federal Trade Commission has limited authority over data brokers. State privacy laws like California’s CCPA and Virginia’s VCDPA have created some restrictions, but they’re fragmented and don’t explicitly address government purchase of commercial location data. Congress has discussed privacy legislation repeatedly, but no comprehensive federal privacy law exists.

Yeagley’s $300,000 experiment may have been designed to show the Pentagon what’s possible. But the real audience is Congress and the public. The question now is whether his demonstration will catalyze the kind of regulatory response that the Cambridge Analytica scandal eventually did—or whether location data will remain in the same legal gray zone it’s occupied for years.

Your phone is a tracking device. That’s not new. What’s new is the clarity that someone with money and access can now prove, in a Pentagon office, exactly how easy that tracking has become.

Share This Article
Miora Danielle Raveloarison is a journalist at CA Privacy Watch covering surveillance, data privacy and the human impact of technology. A graduate of the Catholic University of Madagascar with a background in the social sciences, she has spent over a decade turning complex subjects into clear, engaging reporting, and brings a humanistic lens to questions of privacy, AI and digital rights.