Executive Overview
For decades, the mechanics of online advertising have operated behind a dense digital fog. While everyday internet users are acutely aware that they are being tracked across the web, determining the precise corporate entities responsible for harvesting personal data or serving targeted advertisements has historically required sophisticated forensic analysis. This information is technically semi-public, scattered across a decentralized web of machine-readable files, yet it has remained walled off from the average user, accessible only to large advertising platforms and elite security researchers.
That paradigm is now shifting. A powerful, free public service called DecryptAds (accessible at decryptads.com) has emerged to scrape, correlate, and demystify this complex adtech data. By systematically parsing public disclosures, DecryptAds strips away the obscurity surrounding digital tracking, making it simple to uncover the networks, shell companies, and data brokers operating in the shadows of the websites and mobile applications we use daily.
Co-founded by threat researcher Zach Edwards alongside a team of privacy engineers, DecryptAds approaches the advertising ecosystem from an aggressive security and privacy perspective. Rather than viewing ads through the traditional lens of marketing ROI or media buying, the platform treats adtech infrastructure as a vast, under-policed supply chain rife with vulnerabilities.
From exposing hidden data brokers harvesting precise geolocation details to identifying ad networks tied to sanctioned nations like Russia, China, and the United Arab Emirates, DecryptAds provides a much-needed window into the hidden machinery of the modern internet. This investigative report explores how the platform works, the systemic risks it has uncovered across high-profile websites—including major news outlets and sports networks—and the broader implications for digital security, privacy, and the proliferation of AI-generated content farms.
Detailed Chronology: The Genesis and Mechanics of Adtech Transparency
The foundation of modern web and mobile advertising relies on a series of standardized disclosure files that publishers are heavily incentivized—and often contractually required—to maintain. These files include:
ads.txt(Authorized Digital Sellers): Publicly lists all adtech companies, intermediaries, and data brokers authorized to sell or run advertisements on a specific website.app-ads.txt: The equivalent framework designed for mobile applications and smart TV software, disclosing entities permitted to harvest data or display ads within apps.buyers.jsonandsellers.json: Structured directories that detail the corporate entities buying, selling, or reselling ad inventory across various digital exchanges.
For years, these files existed in isolation. A single ads.txt file for a major publisher might list hundreds of distinct corporate entities, but analyzing that list in a vacuum revealed little about the underlying corporate structures, beneficial ownership, or operational risks of those partners. Supply-chain integrity issues rarely announce themselves in a single, neatly organized file; instead, they manifest as broken cross-references between exchanges, cloned declaration sets across completely unrelated domains, and phantom seller IDs operating in the shadows.

Recognizing this visibility gap, Zach Edwards—chief research officer for DecryptAds and a threat researcher at security firm Infoblox—teamed up with two other founders to build a centralized intelligence engine. Launched to address underserved privacy and security use cases, DecryptAds continuously crawls and scrapes these public declarations, cross-referencing them to construct a unified, comprehensive picture of the global advertising ecosystem.
The platform’s methodology allows security analysts to "pivot" through data points, tracing a single suspicious seller ID from an obscure gaming website directly to international ad networks operating under sanctions or out of offshore secrecy havens. By automating the aggregation of millions of supply chain records, DecryptAds has transformed what used to be weeks of manual forensic discovery into a matter of a few keystrokes.
Supporting Context & Metrics: Unveiling the Hidden Supply Chain
To understand the sheer scale of the digital tracking apparatus, one need only look at how prominent web properties fare under DecryptAds’ analytical microscope. A search for the widely visited sports network espn.com reveals an astonishing 143 ad partners and 19 registered data broker domains declared within its ads.txt and app-ads.txt files.
This unprecedented level of insight is partly facilitated by recent regulatory shifts in the United States. Four states—California, Oregon, Texas, and Vermont—have enacted legislation requiring data brokers to formally register if they buy or sell consumer data originating from within their borders. DecryptAds’ analysis of ESPN’s declared partners shows that nearly half of these registered data brokers actively collect geolocation data from visitors who do not employ ad-blocking technology. Furthermore, three separate entities explicitly disclose that they harvest device fingerprints and sensitive personal information.
High-Risk Ad Partners and Geopolitical Exposure
One of DecryptAds’ most critical features is its automated flagging of "geo-risk" entities. The platform highlights advertising firms operating out of adversarial nations—primarily China and Russia—as well as jurisdictions with deep financial and political alignments with those states, such as Cyprus and the United Arab Emirates (UAE).
For example, DecryptAds reveals that espn.com maintains commercial relationships with four distinct advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a nominal New York corporate address. However, DecryptAds’ dossier on the firm exposes its true operational roots as a Russian enterprise, noting that its publisher payout offers are processed through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank was heavily targeted and placed under economic sanctions by the United States government in 2022 following the Russian invasion of Ukraine.

The reach of such firms extends far beyond sports media. A security audit of major U.S. military-focused news websites—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveals a striking operational overlap. All of these defense-focused publications permit Between Digital to serve advertisements and track their users, alongside two entities based in the UAE and another registered in the corporate ownership secrecy haven of Panama. According to DecryptAds, Between Digital collects advertising and telemetry data across approximately 55,000 partner websites globally.
Pivoting further into Between Digital’s app-ads.txt infrastructure reveals hundreds of domains tied to simple, web-based mobile games that rely on aggressive, constant ad interruptions. Edwards points out that Between Digital’s own public declarations list the company as both a publisher and a reseller on roughly two-thirds of its portfolio.
"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest," Edwards explained. "The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files."
Similar entanglements appear when examining mainstream software. The popular Opera web browser, which has been majority-owned and controlled by the Chinese company Kunlun Tech since 2016 (while maintaining operational headquarters in Oslo, Norway), exhibits an extensive foreign adtech footprint. Opera.com’s DecryptAds profile identifies 27 registered data brokers collecting user information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. DecryptAds notes that these foreign-linked entities represent only seven percent of the total adtech partners specified in Opera’s public disclosure files.
Legal Dossiers and the "AI Slop" Ecosystem
Another powerful feature of the platform is its Legal Dossier lookup. Although individual queries can take several minutes to process as the system aggregates disparate public records, the output provides an exhaustive breakdown of domain ownership history, registration timelines, and corporate aliases.
This capability has proven invaluable in tracking down illicit digital operations. In a prior investigation by security firm Bitsight, researchers discovered that popular H96 branded TV streaming sticks were quietly commandeering residential internet connections to rent out to strangers as proxy nodes. When the devices were not being used to route pirated video content, they actively spoofed themselves as mobile phones, visiting and clicking on advertisements hosted across networks of low-quality, AI-generated "slop" websites. Bitsight traced this malicious infrastructure back to a Chinese entity known as the Fengwo Group, which simultaneously operated the malicious mobile apps installed on the streaming sticks and the network of AI-generated content farms receiving fraudulent ad clicks.

A DecryptAds legal dossier on a now-dormant Fengwo Group domain (medicalbeautyhub.com) revealed that it shared a seller ID (1674071) with a gaming website (giacoloredstones.com), which in turn linked to another seller ID (103488000). Pivoting on that secondary identifier exposed hundreds of active websites operating within Russia’s Yandex ad system, all churning out low-quality games and utility apps designed solely to bombard users with advertisements.
Quiet Removals and the Visibility Gap
In the opaque world of digital advertising, bad actors rarely face public accountability. When ad networks suspect that an affiliate is engaging in fraudulent click inflation or serving malicious payloads, they typically execute what Edwards calls a "quiet removal"—deleting the offending entity from their sellers.json files without issuing a public warning or notifying impacted publishers.
This practice allows dodgy adtech firms to seamlessly migrate to other exchanges and continue operations unabated. To counteract this information vacuum, DecryptAds incorporates a Quiet Removals Feed, which aggregates and correlates sellers.json deletions across multiple ad exchanges. By tracking when and where a seller domain disappears, researchers can map out coordinated crackdowns and identify high-risk operators that major ad exchanges are quietly dropping behind closed doors.
Official Statements and Industry Perspectives
The cybersecurity and adtech communities have long struggled with the systemic lack of transparency in digital marketing supply chains. Zach Edwards emphasizes that the weaponization of ad infrastructure for malware distribution and data harvesting is no longer an isolated phenomenon—it has evolved into an automated, industrialized enterprise.
"None of these slop AI content farms are paying for that kind of protection," Edwards noted, contrasting high-traffic media sites that employ robust security tooling with low-cost, machine-generated content mills. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather some lower quality content farm and someone just went there because it came up in a search."
According to Edwards, mitigating the modern epidemic of malvertising—where malicious banner ads redirect users to phishing sites or deliver zero-click exploits—requires a fundamental shift in how advertising exchanges share infrastructure data. Specifically, he points to the Supply Chain Object (SCO), a structured data payload attached to server-side ad bid requests that details every intermediary, reseller, and buyer involved in a transaction.

"That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload," Edwards explained. "You may see the malicious zero-click redirection, but without the supply chain object—which is only served server side—you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad."
To assist security teams and researchers in automating these investigations, DecryptAds provides a robust Application Programming Interface (API), allowing organizations to programmatically query its dataset and integrate its intelligence gathering capabilities into automated workflows and artificial intelligence platforms.
Future Outlook: Reclaiming Digital Sovereignty
The launch of DecryptAds marks a turning point in the ongoing struggle between automated digital surveillance and user privacy. As artificial intelligence lowers the barrier to entry for generating fraudulent web traffic, deploying malvertising campaigns, and spinning up decentralized content farms, transparency tools will become indispensable components of the cybersecurity stack.
However, relying solely on investigative platforms is insufficient to protect individual end users. Security and privacy experts universally endorse a multi-layered defensive posture to mitigate the risks posed by predatory adtech ecosystems.
Actionable Defense Strategies for Users
- Deploy Robust Ad-Blocking Extensions: For desktop and laptop users browsing via Firefox, Chrome, or Edge, open-source tools like uBlock Origin Lite provide comprehensive filtering against trackers, malicious scripts, and ad networks. Mobile users on Android can utilize Firefox combined with uBlock Origin, while iPhone and iPad users can leverage applications like Adblock Plus or network-level content blockers. Power users can further customize their defenses by subscribing to frequently updated blocklists maintained by projects like EasyList.
- Network-Level Ad Blocking (Pi-hole): For technical users seeking a comprehensive home network defense, deploying a low-cost Raspberry Pi running Pi-hole or similar DNS-sinkhole software allows households to intercept and neutralize ad requests and telemetry at the router level before they ever reach individual devices—protecting everything from desktop computers to smart home appliances.
- Exercise Extreme Caution with Mobile Apps: Major media platforms and commercial services aggressively push users to download dedicated mobile applications under the guise of an "improved user experience." In reality, mobile apps grant companies deeper, more persistent access to device telemetry, precise GPS coordinates, and behavioral tracking than a standard web browser permits. Furthermore, many mobile apps and smart TV platforms quietly enroll users in data-harvesting agreements designed to feed large language model training pipelines. Whenever possible, interacting with services via a secured mobile web browser is vastly preferable to installing proprietary applications.
As regulatory bodies begin to catch up with the data broker industry and innovative tools like DecryptAds continue to illuminate the darkest corners of the adtech supply chain, the digital landscape is slowly moving toward accountability. Until systemic reforms—such as mandatory supply chain object transparency—are universally adopted by major ad exchanges, vigilance, technical hardening, and comprehensive ad-blocking remain the most effective defenses for safeguarding personal privacy in an increasingly tracked world.
