Home › Intelligence › Brief
BREACH BRIEF⚪ Informational ThreatIntel

New DecryptAds Service Maps Global Ad‑Tech Ecosystem, Exposes Tracking and Supply‑Chain Risks

DecryptAds scrapes and cross‑references ads.txt, app‑ads.txt, buyers.json and sellers.json files to reveal which ad‑tech companies and data brokers can serve ads or harvest data on any site or app. The visibility it provides supports vendor‑oversight controls and continuous‑monitoring programs needed for audit readiness.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 krebsonsecurity.com
⚪
Severity
Informational
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
2 recommended
📰
Source
krebsonsecurity.com

New DecryptAds Service Maps Global Ad‑Tech Ecosystem, Exposes Tracking and Supply‑Chain Risks

What Happened – A free service called DecryptAds aggregates the publicly‑available ads.txt, app‑ads.txt, buyers.json and sellers.json files that publishers and app owners publish. By cross‑referencing these files, the platform builds a searchable map of the ad‑tech companies and data brokers that can serve ads or harvest data on any given website or mobile app.

Why It Matters for Trust & Control Assurance

  • Demonstrates how fragmented ad‑tech disclosures can hide supply‑chain exposure; a continuous‑monitoring program can surface undocumented third‑party relationships.
  • Provides concrete evidence for vendor‑oversight controls (e.g., “maintain an inventory of all third‑party data processors”) that many frameworks require.
  • Enables security and privacy teams to validate that any ad‑tech partner aligns with your organization’s risk‑acceptance criteria before data is shared.

Who Is Affected – Digital publishers, mobile‑app operators, advertisers, and any organization that relies on third‑party ad‑tech services (media, e‑commerce, SaaS, and large enterprises).

Recommended Actions

  • Incorporate DecryptAds (or a similar data‑source) into your third‑party risk‑management workflow to keep an up‑to‑date inventory of ad‑tech partners.
  • Map each discovered partner against your internal vendor‑assessment criteria and document the findings as audit evidence.
  • Review the geographic and ownership attributes of ad‑tech entities to ensure compliance with regional privacy laws (e.g., GDPR, CCPA).

Source: https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/

Technical Notes – The service scrapes ads.txt (publisher‑level ad‑tech whitelist), app‑ads.txt (mobile/app whitelist), and buyers.json / sellers.json (ad‑inventory transaction logs). No vulnerability or exploit is disclosed; the risk stems from the visibility of hidden third‑party relationships that could be leveraged for malicious advertising or data‑brokerage.

Source: https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/

📰 Original Source
https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →