The Hidden Web of Ad Tracking, Now Visible
Ever wonder who’s actually behind those ads that follow you around the internet? Or which companies are quietly harvesting your data from the apps on your phone? The answers have always been semi-public, but buried in technical files that most people can’t parse.
That’s changing. A new free service called DecryptAds scrapes and cross-references the adtech declaration files that websites and apps are required to publish. The result? You can now see the full roster of companies tracking you on any site — often dozens or even hundreds of them.
What DecryptAds Reveals About Your Favorite Sites
Type in a domain like espn.com, and DecryptAds pulls together data from three key public files:
- ads.txt — lists all adtech companies and data brokers allowed to run ads or collect data on a site
- app-ads.txt — the same info for mobile and smart TV apps
- buyers.json / sellers.json — shows who’s buying, selling, or reselling ad inventory
For ESPN, that reveals 143 ad partners and 19 registered data brokers. Nearly half of those brokers are collecting geolocation data from visitors who aren’t blocking ads. Three others openly admit to device fingerprinting and collecting sensitive personal information.
Data Broker Registrations Are Growing
This data broker information is becoming available thanks to new laws in California, Oregon, Texas, and Vermont that require brokers to register if they buy or sell consumer data from those states. DecryptAds founder Zach Edwards, a threat researcher at security firm Infoblox, says the service was built to approach adtech from a security perspective.
“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”
High-Risk Ad Partners You Never Knew About
One of the most striking features is the Geo-Risk warning. DecryptAds flags adtech partners based in countries like China, Russia, Cyprus, and the UAE — places with strong financial or political ties to adversarial nations.
Take the military news sites. A search across armytimes.com, airforcetimes.com, defensenews.com, and others shows they all allow a Russian adtech firm called Between Digital to serve ads and track users. The company lists a New York address, but its publisher offers are processed through Alfa Bank — one of Russia’s largest banks, placed under U.S. sanctions in 2022.
Between Digital is collecting ad data on approximately 55,000 partner websites. And here’s the kicker: on about two-thirds of those sites, the company is listed as both a publisher and a reseller.
“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties,” Edwards explained. “For years we’ve had almost no one policing these ads.txt and app-ads.txt files.”
Opera Browser’s Chinese Ties Exposed
Many users don’t know that Opera has been majority-owned by Chinese company Kunlun Tech since 2016. DecryptAds shows Opera.com has 27 registered data brokers collecting information — including 15 adtech partners in the UAE, six in China, three in Cyprus, and two in Russia. That’s still only seven percent of Opera’s total adtech partners.
Legal Dossiers and Quiet Removals
The Legal Dossier lookup is a rabbit hole. It takes several minutes per search but returns a treasure trove: who owns a domain, when it was registered, and how it connects to other adtech entities.
For example, a dossier on a dormant domain linked to the Fengwo Group — the same Chinese company behind malicious streaming stick apps — revealed a shared seller ID with a gaming website. Pivoting on that ID exposed hundreds of low-quality sites within Russia’s Yandex ad system.
DecryptAds also tracks quiet removals — when ad exchanges silently remove a seller from their sellers.json file without public explanation. This practice lets dodgy adtech firms escape accountability. The quiet removals feed records and correlates these removals across exchanges, making patterns visible.
Malvertising and the Rise of AI Slop Sites
Edwards says malicious ads are increasingly found on AI-generated content farms rather than major sites like ESPN.
“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads.”
These AI slop sites cover everything from home improvement to recipes, and they’re prime vectors for malvertising attacks. The fix, Edwards argues, is for ad networks to share the supply chain object (SCO) — structured data attached to each bid request that reveals every intermediary in the ad delivery chain. Currently, that data is only served server-side, making it nearly impossible to trace malicious ads back to their source.
What You Can Do Right Now
The obvious takeaway? Block ads everywhere. Security experts broadly endorse this because it also blocks the tracking that powers these ad networks.
Here’s what works:
- uBlock Origin — the gold standard for desktop browsers, also works on Android via Firefox
- Adblock Plus — a decent option for iPhone and iPad users
- NoScript — blocks all non-approved JavaScript, but requires patience to manage
- Pi-hole on a Raspberry Pi — blocks ads network-wide for every device in your home, the most secure and scalable option
But here’s a warning: ad blockers do little against tracking inside mobile apps. And more sites are pushing apps — not because the experience is better, but because apps make it easier to collect precise data and resell it.
“The cold truth is that big web destinations tend to get pushy with their apps because they make it easier to keep you on their platforms longer,” Edwards says. Many of these apps also opt users into training AI models by default.
So before you install that next app, check its DecryptAds listing. It might just show you who’s really behind it.