English.Elpais Mobile Apps Used for Espionage and Recruitment in Military Operations
Article Content
- •Mobile apps are being exploited for military espionage and recruitment.
- •Fake profiles on dating apps are used by both Russia and Ukraine for intelligence operations.
- •U.S. Army may require troops to surrender personal phones to prevent data leaks.
A Spanish NATO commander's relationship with a Russian woman on Tinder highlights a new espionage front involving mobile applications. Both Russia and Ukraine have utilized fake profiles on social media for intelligence operations, including recruiting individuals for sabotage and extracting military information. This trend has been observed since at least 2018, with incidents like Israel's Operation Broken Heart targeting Hamas. Additionally, apps like Strava and Polarsteps have inadvertently exposed military personnel's locations, leading to significant security breaches. The U.S. Army is considering measures to mitigate these risks, including confiscating personal phones from deployed troops. The collection and sale of personal data by mobile apps further complicate the security landscape, as this information can be exploited for intelligence purposes. Reports indicate that commercial data is being used for espionage across multiple European nations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…