A New Lens Into the Ad-Tech Supply Chain
A newly launched free service called DecryptAds (decryptads.com) is making it dramatically easier to see exactly who is harvesting data and running ads on the websites and apps people use every day. Built by threat researcher Zach Edwards — who also works at security firm Infoblox — alongside CEO Kasey Best and a third co-founder, the tool continuously scrapes the ads.txt, app-ads.txt, sellers.json, and buyers.json files that publishers are required to make public, then cross-references them to surface adtech relationships that were previously scattered across thousands of disconnected files. KrebsOnSecurity first reported on the service on August 14, 2026. In one flagship example, DecryptAds found that ESPN.com works with 143 ad partners and 19 registered data broker domains — nearly half of which collect geolocation data, and three of which harvest device fingerprints and other sensitive personal information.
Details
| Attribute | Value |
|---|---|
| Service | DecryptAds (decryptads.com) |
| Launched | August 2026 |
| Founders | Zach Edwards (Chief Research Officer), Kasey Best (CEO), plus one additional co-founder |
| Edwards' day job | Threat researcher, Infoblox |
| Data sources parsed | ads.txt, app-ads.txt, sellers.json, buyers.json |
| Access model | Free web lookups; API access available for researchers |
| Reported by | KrebsOnSecurity, August 14, 2026 |
| Flagship example | ESPN.com — 143 ad partners, 19 data broker domains |
| Flagged geo-risk regions | China, Russia, Cyprus, UAE |
What Happened
Ad-tech transparency has technically existed for years through the ads.txt and app-ads.txt standards, which require publishers to publicly list which companies are authorized to sell ads or collect data on their behalf. In practice, this "semi-public" data has remained walled off — spread across millions of individual text files with no easy way to search, correlate, or interpret it. DecryptAds changes that by continuously crawling those disclosure files across the web and mobile app stores, then building a searchable, correlated database that flags supply-chain anomalies invisible in any single file.
The tool's most attention-grabbing finding involves Between Digital, an adtech firm that lists a New York address but which DecryptAds flags as Russian-owned. According to the service's dossier, Between Digital's publisher payments are processed through Alfa Bank, Russia's largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 following Russia's invasion of Ukraine. DecryptAds found that Between Digital serves ads and tracks users on several major U.S. military news sites, including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com — alongside two other ad partners based in the UAE and one registered in Panama, a jurisdiction known for ownership secrecy.
DecryptAds also flagged Opera, the browser that has been Chinese-owned since 2016, as working with 27 data brokers — including 15 based in the UAE and six in China.
How the Tool Works
Parsing the public disclosure files. DecryptAds' crawlers continuously pull ads.txt and app-ads.txt files, which list every ad-tech company a site or app has authorized to monetize its traffic, along with sellers.json and buyers.json files published by ad exchanges themselves. Individually, these files are dense and largely unreadable to non-specialists. DecryptAds parses them at scale and links entries across files to reconstruct the full chain of intermediaries sitting between a visitor and the ad displayed on their screen.
Geo-risk flagging and legal dossiers. For every adtech entity it indexes, DecryptAds builds a "legal dossier" showing corporate registration history, known aliases, domain ownership records, and — critically — the entity's true country of operation, which frequently differs from the address listed in its disclosure filings. Entities based in China, Russia, Cyprus, and the UAE are flagged as elevated geo-risk. The service also maintains a "quiet removals" feed that tracks when ad exchanges silently drop partners without public disclosure, a pattern researchers associate with entities cut loose after being caught facilitating fraud or malvertising.
The ESPN and military news findings. Applying these correlations at scale is what produced the ESPN.com and military-news-site results: a mainstream U.S. publisher and a cluster of Department of Defense-adjacent news outlets were both found to be routing ad traffic and user data through entities with financial or ownership ties to sanctioned Russian banking and foreign jurisdictions — relationships that would have been effectively impossible for an ordinary reader, or even most IT teams, to detect by manually reading raw ads.txt files.
Impact Assessment
| Impact Area | Description |
|---|---|
| Consumer privacy | Ordinary users can now see, in plain terms, how many ad-tech and data broker entities track them on a given site or app — often dozens per domain. |
| National security exposure | Ad networks tied to sanctioned Russian financial institutions were found serving ads on U.S. military news outlets, raising foreign-influence and ad-fraud-funding concerns. |
| Malvertising risk | Edwards noted that low-quality "AI slop" content farms tend to onboard the weakest, least-vetted ad partners, making them a disproportionate source of malicious ad delivery. |
| Publisher accountability | Sites can no longer assume their ads.txt disclosures go unread — DecryptAds turns scattered compliance filings into a searchable public record of who a publisher does business with. |
| Research and journalism | Investigative reporters and OSINT researchers gain a free, queryable dataset for tracing adtech ownership chains that previously required manual, file-by-file correlation. |
Recommendations
For Everyday Users
- Run your frequently visited sites and mobile apps through DecryptAds to see how many ad-tech and data broker partners they work with, and whether any are flagged as geo-risk.
- Deploy a capable ad blocker on every device — uBlock Origin Lite for desktop browsers, Adblock Plus on iOS, and NoScript to block unapproved JavaScript from executing at all.
- Consider network-level blocking with a Pi-hole to catch tracking and ad requests that slip past browser-based blockers, particularly from mobile apps that don't respect browser extensions.
- Prefer browser access over installing a dedicated mobile app when both options exist — in-app tracking is harder to block and easier for weakly vetted ad SDKs to exploit.
For Researchers and Journalists
- Use DecryptAds' API access to automate large-scale correlation of ads.txt, app-ads.txt, and sellers.json/buyers.json data across a sector or watchlist of domains rather than manually diffing files.
- Treat the "quiet removals" feed as an early indicator worth monitoring — silent partner drops from ad exchanges often precede or follow fraud and malvertising disclosures.
- Corroborate DecryptAds' legal-dossier ownership findings (such as the Between Digital/Alfa Bank link) against independent corporate registries before publishing, as the tool aggregates public records rather than performing original legal verification.
For Privacy and Security Teams
- Audit your own organization's ads.txt and app-ads.txt files through DecryptAds to confirm every listed partner is still active and legitimate — stale or unauthorized entries are a known malvertising vector.
- Flag any authorized ad-tech partner with ownership or payment ties to sanctioned entities or high-risk jurisdictions for removal, particularly on sites serving government, defense, or critical-infrastructure audiences.
- Factor ad-tech supply-chain exposure into vendor risk assessments — a single "quality" publisher can route user data through dozens of downstream brokers with no direct contractual relationship to the site itself.
Key Takeaways
- DecryptAds, built by researcher Zach Edwards and CEO Kasey Best, launched in August 2026 as a free tool that parses public ads.txt, app-ads.txt, sellers.json, and buyers.json files to reveal who tracks users on any site or app.
- ESPN.com alone was found to work with 143 ad partners and 19 registered data broker domains, illustrating how deep and largely invisible modern ad-tech supply chains have become.
- Between Digital, an adtech firm flagged as Russian-owned despite listing a New York address, processes payments through sanctioned bank Alfa Bank and serves ads on multiple U.S. military news sites.
- DecryptAds' geo-risk flagging highlights adtech partners based in China, Russia, Cyprus, and the UAE — jurisdictions researchers consider elevated risk for data misuse or foreign influence.
- Low-quality "AI slop" content farms tend to onboard the least-vetted ad partners, making them a disproportionate source of malvertising — a strong argument for blanket ad blocking rather than selective trust.
- Individuals should pair DecryptAds lookups with layered defenses — uBlock Origin Lite, Adblock Plus, NoScript, and Pi-hole — while researchers and security teams can use the tool's API and legal dossiers to audit adtech supply chains at scale.