Apps presented as useful tools for American military communities often rely on outside software that users cannot identify from an app-store page. Researchers examining over 220 military-focused apps found components connected to companies in China, Russia and several other countries. The issue is not proof that every component is spying; it is that the software supply chain remains largely invisible to the people carrying the phones.

The findings were reported on July 20, 2026, by a team spanning Florida International University, Purdue University and West Point. Their sample covered uniform guides, promotion-exam preparation, banking, dating and other services advertised to service members or military families. The apps came from Google Play listings and recommendations posted in military communities on Reddit.

The researchers inspected the code packaged inside each app and surveyed 103 active-duty personnel, reservists, veterans, Defense Department civilians and family members. Their sample was not limited to government software; commercial products promoted within military communities were also part of the review. That combined method separated two questions that app-store disclosures tend to blur: what software is actually present and how military-affiliated users feel about the data practices it enables.

Most Military-Focused Apps Included Outside Software

Nearly 64 percent of the apps contained third-party software development kits, or SDKs. Developers use these prebuilt components for advertising, analytics, mapping, storage and notifications instead of creating every function themselves. An SDK may collect behavior or location information and pass it to another company, depending on how the developer configures it.

The disclosure gap extended beyond the presence of outside code. Forty percent of the tested apps collected or shared more information than their Google or Apple store notices described. Google and Facebook supplied the most common SDKs, reflecting their large roles in digital advertising, but the audit identified 76 distinct components associated with companies across China, Russia, Israel, India, Germany and other countries.

In about seven of every 100 apps, the auditors found an outside component linked to a country the Pentagon classifies as an adversary. Twelve contained Huawei’s HMS Core, which can provide location mapping, advertising delivery and image or video storage. Several of those apps served state National Guard organizations. Two other apps were made by Russian companies and incorporated Yandex advertising technology.

Code Origin Creates Risk Without Proving Data Transfer

The audit did not observe information traveling from the tested apps to Huawei servers. That boundary is essential: finding a company’s code is not the same as documenting an active transfer to that company. The concern comes from capability and control. SDKs can receive remote updates, and functions that appear inactive during one test may behave differently after a later release.

Developers may not know every dependency embedded in their product. In one case, the study found that Huawei code reached an app through a commercial notification tool rather than through a deliberate choice by the app’s creator. A familiar vendor can therefore carry another vendor’s component several layers down the chain, leaving both the developer and the user without a clear view of the final package.

Location exposure makes that opacity more consequential for military users than for a typical consumer audience. Earlier investigations traced commercial app data to service members’ homes, their children’s schools and off-base locations where troops were not supposed to appear. U.S. Central Command has also acknowledged receiving threat reports about adversaries using commercial location data to track or target American personnel in the Middle East.

Store Labels Omit the Information Users Wanted Most

More than 83 percent of survey participants used at least one app with data behavior that made them uncomfortable, and the average participant used more than three. Between 76 and 83 percent reported extreme discomfort with code originating in China, Russia, Iran or North Korea. Yet neither Google’s Data Safety section nor Apple’s Privacy Labels identifies the country behind software components bundled into an app.

Military branding appeared to lower suspicion even when the code deserved the same scrutiny as a civilian product. Almost two-thirds reported scant or nonexistent guidance from military institutions on personal apps. Among those who had been briefed, nearly three-quarters judged the advice inadequate. The Pentagon declined Wired’s request for comment.

Generic instructions to delete a suspicious program do not solve a supply-chain problem that users cannot see. An earlier FBI warning about dangerous smartphone apps focused on user action after risk was identified. The military-app study points to an earlier failure: stores and institutions provide no simple way to identify the origin of code before installation.

Device Warnings and Independent Audits Solve Different Gaps

Survey participants ranked phone-level alerts for foreign or unidentified components as both effective and acceptable. They also supported independent checks of privacy disclosures, tighter restrictions on foreign code in military-marketed products and a federal limit on data brokers buying or selling information about military-affiliated people. These measures act at different points: a warning informs the user, an audit tests the developer’s claim and a legal restriction limits what can be traded later.

A country label alone would still be an incomplete security judgment. U.S. advertising SDKs can collect sensitive location data, while a foreign component can sit dormant without sending information abroad. The stronger standard is traceability: developers should know every dependency they ship, stores should expose material origins and permissions, and military institutions should define which capabilities are unacceptable on personal devices used around sensitive facilities. Without that chain of responsibility, military branding offers reassurance that the underlying code has not earned.