RG Herd ALERTS
Surveillance • Policy • Civic infrastructure
Back to alerts
July 12, 2026 14 min read

Your Phone Is a Tracking Device: ICE’s Expanding Location-Intelligence Network

ICE is not merely watching protests. The public record shows a layered surveillance system capable of identifying people, finding devices, reconstructing movements, mapping relationships, and converting ordinary commercial data into enforcement leads.

#ICE #location intelligence #surveillance #signal defense #mutual aid
RG Herd ALERTS cover image for Your Phone Is a Tracking Device
Related Video
ICE's New Surveillance System Knows Where You Go Every Day

⚠️ The warning: ICE can hunt through the data your phone leaves behind.

The strongest defensible conclusion is not that ICE has one secret military-style signals-intelligence system watching everyone. The public evidence shows something more fragmented, commercial, and immediately usable: a surveillance and location-intelligence stack assembled from cellular tracking tools, advertising-location data, facial recognition, license-plate records, social-media monitoring, utility records, data brokers, and integrated case-management systems.

That distinction matters. “Signal intelligence” can imply a single centralized program intercepting communications at intelligence-agency scale. What is publicly documented is a collection of systems that can produce many of the same operational outcomes inside the United States: identify a person, connect that identity to a phone or vehicle, reconstruct movement, infer home and work locations, map associates, and turn the result into an enforcement lead.

This is not limited to protest surveillance. It is infrastructure for finding people in ordinary life.

The central threat

Your phone does not only expose what you say. It can expose where you sleep, where you work, which vehicles and devices move with you, who repeatedly appears near you, which buildings you visit, and what routines make you predictable.

What the public record already proves

Georgetown Law’s Center on Privacy and Technology concluded after a two-year records investigation that ICE had scanned the driver’s-license photographs of roughly one in three adults, had access to driver’s-license data covering three in four adults, tracked drivers in cities containing three in four adults, and could locate three in four adults through utility records.[1]

That is not a narrow database of people already in immigration proceedings. It is access to ordinary systems Americans interact with simply by driving, applying for identification, renting housing, or maintaining utilities. The surveillance target does not need to voluntarily provide every piece of the profile to ICE. The profile can be assembled from systems created for entirely different purposes.

ICE’s use of cell-site simulators is also documented. Records obtained by the ACLU showed hundreds of deployments, including uses that located people and produced arrests. Cell-site simulators imitate cellular towers so nearby phones connect or respond to them, allowing operators to identify or locate devices with more precision than ordinary carrier records may provide.[2]

The Department of Homeland Security inspector general separately found that ICE, Customs and Border Protection, and the Secret Service procured and used commercial telemetry data without following required privacy processes or developing sufficient controls. Commercial telemetry data can include historical location information collected by mobile applications and tied to advertising identifiers.[3]

ACLU records showed that DHS purchased access to location data from brokers including Venntel and Babel Street. Venntel marketing material described collecting more than 15 billion location points from more than 250 million devices every day. The advertised capabilities included identifying devices observed at a place of interest, finding repeat visitors, locating frequented places, identifying associates, and discovering a person’s “pattern of life.”[4]

The commercial location market makes the threat larger.

A phone does not need to be wiretapped for its movement to become intelligence. Weather apps, games, advertising libraries, mapping tools, retail apps, and other software may collect location or nearby-network information. That data can move through advertising and brokerage markets until it reaches a company selling access to law enforcement.

Citizen Lab’s 2026 analysis of Penlink’s Webloc found documents describing access to a constantly updated stream of records from as many as 500 million mobile devices. The system reportedly supports geofencing, identifying devices present in multiple locations, viewing historical movement, and analyzing data extending back as far as three years. Citizen Lab identified ICE among the U.S. government customers linked to the broader system.[5]

The operational significance is obvious. An investigator may not need to begin with a person’s name. A search can begin with a place: an apartment building, workplace, meeting location, clinic, religious institution, shelter, courthouse, protest, or neighborhood. Devices seen there can be compared against devices seen somewhere else. Repeated locations can reveal a likely home. Regular daytime presence can reveal employment. Devices traveling together can reveal association.

A phone can become an identity even when the database begins with a supposedly anonymous advertising identifier.

Social media, vehicles, faces, and databases close the loop.

Location information becomes more powerful when it is combined with other records. ICE and other DHS components have used social-media information in vetting and investigative systems, and Brennan Center research documents how that information can be retained, shared, and incorporated into immigration-related databases and leads.[6]

A public post can reveal a person’s face, username, vehicle, employer, associates, event attendance, or current location. A license-plate system can reveal where a vehicle has appeared. A data broker can connect a phone number to addresses and relatives. Driver’s-license databases can provide identity photographs. Utility records can identify likely residences. Facial-recognition tools can compare an image captured in the field or scraped from the internet against other image collections.

None of these systems has to be perfect by itself. Their power comes from correlation. One weak identifier becomes useful when several systems point toward the same person.

Documented capability vs. defensible inference

The procurement, access, and use of these tools are documented. The reasonable inference is that they can be combined to locate people and map relationships. What remains hidden is the complete operational scope: exactly which systems are queried in each case, how often they are fused, which people are selected, and what internal rules actually constrain their use.

What has not been publicly proven

The public record does not establish that every person involved in immigration advocacy, mutual aid, protest activity, or immigrant communities is under individualized live surveillance. It also does not prove that ICE routinely hacks the phones of ordinary civil-immigration targets at scale.

Some DHS components possess or have sought forensic and spyware capabilities capable of extracting data from locked devices or accessing encrypted applications. But the public record remains incomplete about which tools are currently active, which units use them, and the classes of investigations in which they are deployed.

The warning does not require exaggeration. ICE does not need to compromise every phone when ordinary commercial and government systems already reveal so much.

Your normal phone is a persistent identity beacon.

A normal phone is linked to years of behavior. It connects from home. It travels to work. It joins familiar Wi-Fi networks. It pairs with vehicles, watches, earbuds, laptops, and other devices. It contains accounts, contacts, photographs, browser sessions, cloud backups, payment applications, and location permissions. Its phone number and device identifiers appear in carrier records and commercial databases.

Even when a specific application uses end-to-end encryption, the phone still exists as a physical object moving through networks. Encryption can protect message content in transit. It does not automatically hide the device’s location, account identifiers, contact timing, association patterns, vehicle movement, public posts, or information stored on the endpoint.

This is why putting a normal phone in airplane mode only when arriving at a sensitive location is incomplete. Properly enabled airplane mode can stop current cellular communication and reduce exposure to tower dumps or cell-site simulators. It does not erase the historical trail showing the device leaving home, approaching the area, reconnecting later, or repeatedly appearing with the same people. Wi-Fi and Bluetooth must also be checked because some devices allow them to remain active or be manually re-enabled while airplane mode is on.[7]

Mitigation 1: Leave the normal phone at home.

For a high-risk situation, the cleanest technical defense is also the least convenient: do not carry the device already tied to your identity and routine. Leave it powered on at home if creating a sudden absence would itself be unusual, or power it down according to your own threat model. The important point is that it does not travel with you.

This does not make a person invisible. Cameras, vehicles, financial transactions, witnesses, social-media posts, and other people’s phones still create exposure. It removes one of the richest and most persistent location signals from the situation.

Mitigation 2: Use Faraday isolation correctly.

A Faraday bag is a conductive enclosure intended to block cellular, Wi-Fi, Bluetooth, NFC, and other radio-frequency communication. For people who must transport a phone but do not want it communicating, a properly functioning bag can provide stronger isolation than software settings alone. EFF specifically recommends that higher-risk individuals consider Faraday isolation when defending against tower-based collection.[7]

A bag is not protection merely because a product listing says “Faraday.” Seams, closures, folds, damage, and poor construction can cause leakage. Test it before relying on it. Place the phone inside, close the bag exactly as instructed, and verify that cellular calls, messages, Wi-Fi connections, and Bluetooth connections do not reach it. Repeat the test periodically because the shielding can degrade through use.

Do not open the bag at the location you are trying to protect. The moment the phone reconnects, it can announce its presence and begin exchanging data. A Faraday bag also eliminates emergency communication while sealed. That tradeoff must be part of the plan.

Mitigation 3: A burner phone must be compartmentalized.

A prepaid phone is not anonymous merely because it was sold without a long-term contract. The device becomes attributable through behavior. Purchase records, store cameras, activation location, carrier records, Wi-Fi networks, installed accounts, contact patterns, recurring destinations, and proximity to an existing phone can all connect it to a person.

A burner used like your normal phone is just a second tracked phone.

Compartmentalization is a behavior, not a product. One login to a personal account, one connection to home Wi-Fi, one trip alongside the normal phone, or one familiar contact graph can collapse the separation.

A properly separated secondary phone should not be activated at home, work, or another location strongly tied to the user. It should not be powered on beside the normal phone. It should not connect to home Wi-Fi, a personal hotspot, a familiar vehicle, or previously paired Bluetooth devices. It should not sign into a personal Apple, Google, Meta, Microsoft, email, or cloud account.

Contact synchronization should remain off. Location permissions should be denied unless a specific function requires them. Unnecessary applications should not be installed. The device should use a strong passcode rather than biometric unlock, full-device encryption, current security updates, and the minimum data required for its role.

The phone number should also be treated as an identifier. Calling the same family, friends, organizers, or workplaces as the normal phone creates an association graph. The same is true when the secondary phone repeatedly appears near devices already tied to those people.

A secondary device can reduce exposure when it is isolated from an established identity. It cannot guarantee anonymity, and it should never be treated as magic.

Mitigation 4: Reduce the data available to brokers.

Review application permissions and remove precise location access from software that does not genuinely need it. Disable unnecessary background access, Bluetooth scanning, nearby-device permissions, advertising personalization, and platform location-history features. Remove applications built primarily around advertising or aggressive data collection when a less invasive alternative exists.

Resetting or limiting advertising identifiers can reduce some forms of future linkage, but it does not retrieve historical data that has already been collected or sold. Deleting an application does not necessarily delete the brokered copies created while it was installed.

Use privacy-preserving browsers, tracker blocking, encrypted DNS, and network tools as additional layers. These reduce exposure; they do not make a phone invisible. The ACLU notes that location information can reveal political activity, medical visits, relationships, and where a person sleeps.[9]

Mitigation 5: Protect the device if it is seized.

Use a long, strong passcode. Disable fingerprint and face unlock before entering a higher-risk situation. Keep the operating system and applications updated. Enable full-disk encryption. Remove data that does not need to travel. Store encrypted backups somewhere the device cannot automatically expose.

Do not rely on deleting messages immediately before an event as the primary defense. Local remnants, cloud backups, notification histories, synchronized desktops, other participants’ devices, and platform records may preserve copies. Data minimization works best when it is routine rather than performed in a panic.

Mitigation 6: Protect other people from your camera.

Do not publish identifiable faces of protesters, organizers, immigrants, legal observers, medics, drivers, or mutual-aid volunteers without informed consent. Video does not need to be processed in real time to become surveillance. Public footage can be downloaded, archived, enhanced, compared against other images, and analyzed later.

Where lawful and appropriate, masks, hats, ordinary clothing, and the absence of unique logos reduce visual identifiers. Faces should be blurred before media is uploaded—not after the original has already reached a public platform. Vehicle plates, tattoos, badges, reflections, metadata, backgrounds, and audio can identify people even when a face is obscured.

Do not tag participants, publish attendance lists, or describe where someone traveled from. A well-intentioned post can become a ready-made investigative lead.

Mitigation 7: Build mutual-aid networks that survive device loss.

Surveillance defense cannot be reduced to individual consumer products. People need transportation, temporary housing, food, childcare, legal support, language assistance, medical help, emergency funds, and trusted communication. Those needs require networks—but the network should not create one centralized list containing everyone’s identity, location, vulnerability, and role.

Divide information by function. A driver does not need the complete membership list. A housing coordinator does not need every legal detail. A dispatcher may need availability and a temporary contact channel, not a permanent dossier. Use role-based access and retain only what is operationally necessary.

Maintain offline fallbacks: printed legal numbers, memorized check-in procedures, physical meeting points, paper maps, predetermined time windows, and trusted people who know what to do when a device disappears. A network that collapses when one account is locked or one phone is seized is not resilient.

Avoid placing the entire operation inside one Facebook group, Google account, Discord server, WhatsApp group, email inbox, or volunteer spreadsheet. Centralized platforms simplify coordination, but they also simplify account takeover, subpoena response, platform removal, internal compromise, and mass exposure.

Mutual aid is strongest when care is coordinated but sensitive data is compartmentalized.

Mitigation 8: Own more of the communication layer.

End-to-end encryption remains important. Use it. But understand what it does and does not protect. It can protect message content between uncompromised endpoints. It does not automatically conceal who operates an account, when devices communicate, where those devices are located, what appears in notifications, or what is exposed when a phone is unlocked or infected.

Community-owned and federated infrastructure reduces dependence on a single corporate platform and gives groups more control over retention, moderation, access, backups, and account policy. It does not eliminate the need for endpoint security, careful account separation, limited data collection, or disciplined administration.

RG Herd Signal Defense Kit

The RG Herd Signal Defense Kit provides a practical starting map for tracking reduction, encrypted communication, Matrix and community-owned messaging, resilient peer-to-peer tools, device hardening, encrypted backups, private networking, and self-hosted infrastructure. Pick layers your people can actually maintain.

A practical threat model

Not everyone faces the same risk. A person attending a public rally, an immigration attorney, a family sheltering someone, a community driver, a journalist, and a person already named in an enforcement database require different precautions.

Ask four questions:

  • What information would cause the most harm if exposed? Location, identity, legal status, contacts, housing, transportation, medical needs, or organizational roles may carry different consequences.
  • Who could realistically seek it? Consider ICE, another DHS component, local police, a hostile private actor, platform employees, data brokers, abusive partners, or infiltrators.
  • Where does the information already exist? Phones, vehicles, cameras, social platforms, cloud accounts, utility records, payment systems, volunteer databases, and other people’s devices may already hold copies.
  • Which layer can be changed without breaking the care network? Security that prevents people from receiving help is not a successful design. Build alternatives before removing the convenient system.

The core warning

ICE’s documented surveillance capacity is already sufficient to find people through far more than a protest photo or an informant. Phones, applications, advertising systems, cellular networks, vehicles, cameras, public records, social platforms, and commercial databases can be treated as pieces of one location and identity puzzle.

The uncertainty is not whether the capability exists. It does. The uncertainty is how broadly, how routinely, and how secretly the available systems are being combined in individual operations.

Do not wait for proof that every capability has been used against every category of person before building defenses. Do not invent capabilities that have not been established either. The responsible position is evidence-based preparation: acknowledge what is documented, identify the reasonable operational inference, reduce unnecessary exposure, and build community systems that do not place everyone’s safety inside one phone or one corporate account.

Your phone is useful. It is also a sensor, identifier, archive, map, and relationship graph. Treat it accordingly.

Sources / reference points

  1. Georgetown Law Center on Privacy and Technology: American Dragnet — Data-Driven Deportation in the 21st Century
  2. ACLU: ICE Records Confirm Immigration Enforcement Agencies Are Using Invasive Cell-Phone Surveillance Devices
  3. DHS Office of Inspector General: CBP, ICE, and Secret Service Did Not Adhere to Privacy Policies Before Using Commercial Telemetry Data
  4. ACLU: New Records Detail DHS Purchase and Use of Vast Quantities of Cell-Phone Location Data
  5. Citizen Lab: Uncovering Webloc — An Analysis of Penlink’s Ad-Based Geolocation Surveillance Technology
  6. Brennan Center for Justice: Social Media Monitoring
  7. Electronic Frontier Foundation: Rayhunter — What We Have Found So Far
  8. Electronic Frontier Foundation: A Quick and Dirty Guide to Cell-Phone Surveillance at Protests
  9. ACLU: Cell-Phone Privacy and Location Tracking
  10. ACLU: DHS Is Circumventing the Constitution by Buying Data It Would Normally Need a Warrant to Access
  11. RG Herd: Signal Defense Kit
ARGUS logo
ARGUS on GitHub
Open-source release now public

ARGUS is now public on GitHub: an open-source coordination system for alerts, dispatch, incident tracking, and community response infrastructure.

View on GitHub