New Free Tool Maps the Hidden Ad-Tech and Data-Broker Supply Chain
A new service called DecryptAds is giving consumers and researchers a way to see exactly who is harvesting data and running ads behind the websites and apps they use every day. Reported by KrebsOnSecurity on August 14, 2026, the free tool was built by Zach Edwards, who serves as its chief research officer while also working as a threat researcher at Infoblox, along with two co-founders. Rather than scanning a site for trackers in real time, DecryptAds aggregates and cross-references disclosure files that websites and apps are already required to publish — but that have gone largely unpoliced for years — to reveal relationships between publishers, ad exchanges, and data brokers that are invisible when those files are viewed in isolation.
Details
| Attribute | Value |
|---|---|
| Service name | DecryptAds (decryptads.com) |
| Founder / Chief Research Officer | Zach Edwards (also a threat researcher at Infoblox) |
| Cost | Free |
| Data sources | ads.txt, app-ads.txt, sellers.json, buyers.json disclosure files |
| Core function | Cross-references disclosure files to map ad-tech vendors and registered data brokers per domain or app |
| Notable features | Geo-risk flags for adversarial-nation ad partners, "Legal Dossier" ownership lookups, a "Quiet Removals Feed," and API access for researchers |
| Reported by | KrebsOnSecurity, August 14, 2026 |
How It Works
Websites that run programmatic advertising are required to publish an ads.txt file (or app-ads.txt for mobile and smart-TV apps) listing every ad-tech company authorized to sell their inventory, plus sellers.json and buyers.json files that document who is buying, selling, or reselling that inventory across the broader exchange ecosystem. Individually, these files are dense, static, and rarely read by anyone outside the ad-tech industry. DecryptAds continuously scrapes them at scale and correlates the results, turning scattered disclosures into a searchable profile of every advertising partner and data broker tied to a given domain.
Why This Was Hidden Until Now
Edwards told KrebsOnSecurity that "for years we've had almost no one policing these ads.txt and app-ads.txt files," meaning the raw transparency data has existed in public view without anyone systematically auditing it. Part of what makes the correlation newly possible is that California, Oregon, Texas, and Vermont have each passed laws requiring data brokers that buy or sell data on their residents to register with the state — giving DecryptAds a registry to match against the entities named in ad-tech disclosure files.
Case Study: ESPN and Opera
A DecryptAds lookup for espn.com surfaced 143 ad partners and 19 registered data broker domains, with almost half of those brokers collecting geolocation data and three disclosing collection of device fingerprints and other sensitive personal information. The analysis also flagged four ESPN ad partners based in Russia, China, or the UAE, including Between Digital — a firm that lists a New York address but is flagged in DecryptAds' dossier as Russian, with publisher payments processed through Alfa Bank, Russia's largest private commercial bank and an institution under U.S. sanctions since 2022. Edwards also noted that Between Digital is declared as both a publisher and a reseller on roughly two-thirds of its portfolio, a conflict-of-interest setup he said "creates opportunities to direct client spend at your owned and operated properties or client infrastructure." Separately, a lookup for Opera's browser properties identified 27 registered data brokers, including 15 ad-tech partners based in the UAE and six in China.
Impact Assessment
| Impact Area | Description |
|---|---|
| Consumer privacy | Surfaces previously opaque relationships between visited sites and dozens of ad-tech vendors and data brokers, including which ones collect geolocation or device-fingerprint data |
| Ad-tech accountability | Puts continuous, public scrutiny on disclosure files that have gone largely unaudited since the ads.txt standard was introduced |
| Geopolitical and supply-chain risk | Flags ad-tech vendors routing publisher revenue through sanctioned entities or adversarial-nation infrastructure, as in the Between Digital/Alfa Bank case |
| Regulatory momentum | Relies on, and strengthens the case for, state-level data broker registries (California, Oregon, Texas, Vermont) as a transparency mechanism |
Recommendations
For Privacy-Conscious Users
Look up the sites and apps you use most at decryptads.com to see which ad-tech vendors and data brokers are authorized to collect data from them. Pay particular attention to disclosed geolocation and device-fingerprint collection, and treat a high data-broker count or adversarial-nation partners as a signal to tighten ad-blocking, cookie, and app-permission settings for that property.
For IT/Security Teams Evaluating Vendor Exposure
Run your organization's public-facing domains and any embedded ad units through DecryptAds as part of third-party risk reviews. A vendor operating as both publisher and reseller on its own portfolio, or routing payments through a sanctioned financial institution, is a supply-chain red flag that warrants the same scrutiny given to any other third-party data processor.
For Website Operators
Audit your own ads.txt, app-ads.txt, sellers.json, and buyers.json files for accuracy and keep them current — these disclosures are now machine-readable and continuously monitored by outside researchers, not just filed away. Reassess relationships with ad-tech partners that have murky ownership structures, sanctioned payment processors, or large data-broker footprints before a DecryptAds-style lookup surfaces them to your users first.
Key Takeaways
- DecryptAds is a free service built by researcher Zach Edwards that cross-references public
ads.txt,app-ads.txt,sellers.json, andbuyers.jsondisclosure files to map ad-tech and data-broker relationships for any website or app. - These disclosure files are not new, but they have gone "almost unpoliced" for years — DecryptAds is one of the first tools to systematically audit them at scale.
- A lookup for espn.com found 143 ad partners and 19 data broker domains, with roughly half collecting geolocation data and three collecting device fingerprints.
- The tool flagged ad-tech vendors with ties to Russia, China, and the UAE on major sites, including one firm, Between Digital, whose publisher payments route through U.S.-sanctioned Alfa Bank.
- New state data-broker registration laws in California, Oregon, Texas, and Vermont are what make this level of cross-referencing newly possible.
- Consumers, security teams, and website operators can all use DecryptAds today to audit who is tracking them or their users.