Determining who is responsible for serving advertisements on the websites we frequent, or identifying exactly which entities are harvesting data from the mobile applications we use daily, has long been a daunting task for the average internet user. While this information is technically semi-public, it has historically remained trapped behind a curtain of complexity, sequestered within the private, walled gardens of massive advertising platforms. This opacity has made it nearly impossible for researchers, privacy advocates, and security professionals to hold adtech companies accountable. However, a powerful and free new service called DecryptAds is changing that landscape. By scraping and correlating fragmented adtech data, the service provides a simple, accessible way to gain deep insight into the entities tracking users across the digital ecosystem.
The newly launched platform, decryptads.com, functions by constantly scouring the public-facing files that websites and mobile apps are required to maintain to disclose their advertising partnerships. These files, including the industry-standard "ads.txt" for websites, "app-ads.txt" for mobile and smart TV applications, and the "buyers.json" and "sellers.json" files, contain the blueprints of the modern digital advertising supply chain. By aggregating and cross-referencing this data, DecryptAds allows users to see the full, interconnected web of data brokers, ad networks, and resellers that interact with a single domain or application.
Zach Edwards, the chief research officer for DecryptAds and a prominent threat researcher at the security firm Infoblox, spearheaded the project alongside two other founders. Edwards explains that the initiative was born out of necessity; the raw data contained in these files is of limited utility when viewed in isolation. True visibility only emerges when that data is cross-referenced, allowing for a comprehensive view of the advertising ecosystem. According to Edwards, the tool is designed to approach the adtech industry through a rigorous security lens. It addresses a range of privacy and security use cases that have been historically underserved by the industry, including tracing the origins of malicious advertisements that distribute malware, identifying ad networks operating out of adversarial nations, and flagging the rapidly proliferating networks of AI-generated "slop" websites.

The complexity of these supply chains means that threats are rarely confined to a single file. As the DecryptAds team explains, security and integrity issues typically manifest as broken cross-references between different declaration files, cloned ad configurations across unrelated domains, or instances where sellers disappear from one exchange while remaining active in others. These discrepancies are nearly impossible to detect through manual inspection, but they become glaringly obvious when analyzed at scale.
A search for a major media outlet like espn.com using the new tool illustrates the depth of this exposure. The analysis reveals 143 distinct ad partners and 19 registered data brokers operating within the site’s declared files. This level of transparency is aided by recent legislation in states like California, Oregon, Texas, and Vermont, which now require data brokers to register if they buy or sell consumer data. DecryptAds indicates that nearly half of the brokers associated with espn.com are harvesting geolocation data from visitors who do not employ ad-blocking technology, while others explicitly disclose the collection of device fingerprints and sensitive personal identifiers.
Identifying High-Risk Ad Partnerships
One of the most critical functions of DecryptAds is its ability to map the geographic origins of advertising firms, providing a "geo-risk" warning when an entity is based in regions such as Russia, China, or countries with significant political and financial ties to these nations, such as the United Arab Emirates or Cyprus.

The research conducted by DecryptAds has already uncovered concerning trends. For example, the tool identifies that espn.com engages with four advertising entities based in high-risk jurisdictions. Among these is Between Digital, a firm that presents a New York business address but is identified by the dossier as a Russian entity. The service notes that Between Digital’s financial transactions are processed through Alfa Bank, Russia’s largest private commercial bank, which was hit with significant U.S. sanctions in 2022 following the invasion of Ukraine. Similar investigations into U.S. military news websites—including those covering the Army, Air Force, Navy, and Marine Corps—show that these sites also permit Between Digital to serve ads and track their users, alongside other entities based in the UAE and Panama.
The risk extends to the bidding process itself. Edwards points out that Between Digital is listed as both a publisher and a reseller on a vast portion of its portfolio, creating a conflict of interest where a company can effectively bid on its own ad inventory. This lack of policing in ad-tech files has allowed such practices to flourish unchecked for years. Furthermore, even major consumer technology brands are not immune to these complexities. The Opera web browser, which has been majority-owned by the Chinese firm Kunlun Tech since 2016, features a profile on DecryptAds that identifies 27 registered data brokers, including dozens of adtech partners in the UAE, China, Hong Kong, and Russia.
Deep-Dive Legal Dossiers and Market Trends
The "Legal Dossier" feature of DecryptAds allows researchers to perform extensive, multi-hour investigations into the ownership, registration history, and corporate relationships of specific domains. This is particularly relevant in the fight against "malvertising" and the surge of AI-generated content farms.

Recent investigations have highlighted how malicious actors, such as the Fengwo Group, have used low-quality AI-generated websites to serve ads to compromised devices, such as H96 TV streaming sticks, which were found to be spoofing mobile phone traffic. DecryptAds’ ability to map shared seller IDs across these networks reveals how a single, obscure entity can operate a sprawling network of sites that distribute ads, often while flying under the radar of major ad exchanges.
Edwards notes that when advertising networks suspect an advertiser is engaging in fraud, they often quietly remove them from their approved partner lists without public notice. This "quiet removal" practice protects the reputations of the ad exchanges but leaves the rest of the industry vulnerable. To combat this, DecryptAds has introduced a "quiet removals feed," which tracks and correlates these disappearances across the industry, providing a level of accountability that was previously non-existent.
The proliferation of AI-generated "slop"—low-quality blogs, recipe sites, and content farms—has created a "greased rail" for malicious ads. Because these sites lack the sophisticated vetting processes used by high-traffic outlets, they become prime targets for attackers looking to distribute zero-click payloads. Edwards emphasizes that addressing these threats requires the industry to embrace greater transparency, specifically through the sharing of the "supply chain object" (SCO). This structured data, which is currently only visible server-side, would allow for the identification of the final buyer in a malicious ad impression, thereby enabling defenders to stop attacks at their source.

The Case for Robust Ad Blocking
Given the current state of the adtech industry, security experts remain consistent in their recommendation: blocking ads is the most effective way for users to protect their privacy and mitigate security risks. For desktop users, open-source tools like uBlock Origin Lite offer a reliable, maintained solution for filtering out unwanted tracking and advertisements. Mobile users face more significant challenges, as many companies now aggressively steer users toward dedicated applications rather than web browsers.
These applications are often designed to circumvent standard browser-based privacy protections, allowing companies to collect more precise data on user behavior and, increasingly, to train large language models. Experts warn that the push for mobile app adoption is rarely about user experience and almost always about data extraction. For those seeking the highest level of security, network-level blocking—using hardware like a Raspberry Pi running Pi-hole—remains the gold standard, as it can filter traffic for every device connected to a home network. By staying cautious about which apps are installed and utilizing tools to inspect the underlying advertising relationships, users can begin to reclaim a measure of control over their digital footprint in an increasingly opaque ecosystem.

