# ESPN Lets Russian and Chinese Ad Firms Track You. Now You Can See It.
The public files were always there. The data was technically accessible. Nobody bothered to connect it — until now.
A free service called DecryptAds launched this month with a straightforward premise: the adtech industry has been hiding in plain sight, publishing disclosure files that are technically public but practically unreadable without serious engineering work to correlate them. DecryptAds does that correlation for you, and what it surfaces should concern anyone who assumed "permitting ads" and "permitting surveillance" were different things.
## What the Files Actually Reveal
The Interactive Advertising Bureau's ads.txt standard was designed to reduce ad fraud by having publishers publicly declare which companies are authorized to sell their inventory. It worked, sort of — fraud dropped, but it created a detailed map of the adtech supply chain that nobody ever bothered to read in aggregate.
DecryptAds scrapes and cross-references four file types: ads.txt (desktop web), app-ads.txt (mobile and smart TV apps), and the buyers.json/sellers.json pair that documents who's buying and reselling ad inventory across exchanges. Any one of these files is dense and opaque. Correlated across thousands of domains, they become something else entirely — a window into the surveillance infrastructure underneath the modern web.
Pull up ESPN.com. You'll find 143 declared ad partners and 19 registered data broker domains. Nearly half of those brokers explicitly disclose they're collecting geolocation data from visitors who aren't running an ad blocker. Three more admit to collecting device fingerprints and sensitive personal information. This isn't inference or speculation — it's what Disney's sports network has put in its own public disclosure files.
Zach Edwards, DecryptAds' chief research officer and a threat researcher at Infoblox, put it plainly: "It's an adtech tool but we're trying to approach adtech from a security perspective. It's really built for a lot of privacy and security use cases that have been dramatically underserved."
## The Geo-Risk Problem Nobody Is Talking About
Here's where it gets geopolitical.
DecryptAds flags advertising partners based in countries it classifies as "geo-risk" — Russia, China, and nations with close financial or political ties to both, including Cyprus and the UAE. ESPN.com works with four advertising entities headquartered in Russia, China, or the UAE. One of them is Between Digital, a Russian adtech firm.
Think about what that means in practice: a major US media property, owned by Disney, is routing ad impressions — and user data — through entities based in adversarial nations. The data involved isn't just "you watched a highlights reel." It's geolocation, device fingerprints, behavioral profiles. The kind of data that intelligence services pay a lot for, and that ad networks collect incidentally as a business model.
This isn't theoretical. The US government has spent years worrying about Chinese-owned apps (TikTok being the loudest example) collecting data on American users. The adtech supply chain running underneath mainstream American websites deserves the same scrutiny — and has received almost none of it.
Supply chain integrity problems in adtech are notoriously hard to detect because they're distributed across multiple files and exchanges. As DecryptAds notes: "They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges." No single file tells the story. The story only emerges when you treat the whole ecosystem as one data set.
## State Laws Are Opening the Vault
Part of what makes DecryptAds possible right now is legislative. Four states — California, Oregon, Texas, and Vermont — have passed laws requiring data brokers to register if they buy or sell data on residents of those states. That registration creates a public record, and DecryptAds is pulling it into their database, matching broker registrations against the entities that appear in ads.txt files.
This is a meaningful shift. For years, data brokers operated in near-total obscurity. The IAB files disclosed that they existed; the registrations are starting to disclose what they collect. Combine the two, and you can now answer questions that were previously unanswerable without expensive investigative work or a subpoena.
More states will pass similar laws. The scope of mandatory disclosure will expand. Which means DecryptAds will only get more useful — and the adtech industry's comfortable obscurity will continue to erode.
## What Defenders and Security Teams Should Do With This
The obvious consumer use case is checking the apps you use daily. But for security professionals, the implications are broader.
Malvertising — the delivery of malware through legitimate ad networks — has surged in recent years, with threat actors buying ad placements that redirect users to exploit kits or credential-harvesting pages. Investigating the origin of a malicious ad has historically required access to ad exchange logs or significant investigative resources. DecryptAds gives incident responders a starting point they didn't have before: a fast way to enumerate which ad partners a given site or app works with, cross-referenced against known bad actors.
Corporate security teams should be pulling their own domains. An organization that runs a news outlet, a consumer app, or any ad-supported property should know which entities are authorized to run code against their users. Many won't know. Some of what they find will surprise them.
---
## HackWire Analysis
The DecryptAds launch is a transparency forcing function, and the adtech industry should be nervous.
The sector has long relied on a specific kind of opacity: everything is technically disclosed (because the IAB requires it), but the disclosure format is designed for automated processing, not human comprehension. The average person cannot read ads.txt and derive anything meaningful from it. That's not an accident.
What Edwards and his co-founders have built is a normalization layer — the engineering work that translates raw disclosure into something you can actually interrogate. And what it reveals isn't surprising to anyone who has looked hard at adtech, but it will be genuinely shocking to everyone else: that the permissioned surveillance infrastructure underneath American media properties routinely includes firms from countries the US government considers adversaries.
The national security angle here is underreported. Congressional attention has focused narrowly on Chinese-owned apps, treating data collection risk as a function of app ownership. The adtech supply chain problem is more diffuse and harder to legislate, but the exposure is comparable. A Russian adtech firm collecting geolocation data from ESPN visitors has the same data as a Chinese-owned app doing the same — the collection mechanism is just less visible.
The other risk worth watching: the malvertising detection use case. If DecryptAds can identify AI-generated slop sites and flag high-risk ad partners at scale, it becomes a threat intelligence resource that security teams can integrate into their tooling. Watch for threat intel platforms to start ingesting this data. The service launched free; the sustainable business model is probably enterprise API access, which would put this data inside the SIEM and SOC workflows where it can actually drive detections.
One gap: the service shows what's declared, not what's actually happening. Undisclosed data collection — the stuff that doesn't appear in any ads.txt file — remains invisible. That's a limitation worth naming clearly.
— HackWire Editorial
---
## Related Coverage