![]()
DecryptAds: a new way to see who tracks you through ads
KrebsOnSecurity covers DecryptAds, a free new service that collects, correlates and explains adtech data that is technically public but normally hard to use. Websites and apps publish files such as ads.txt, app-ads.txt, buyers.json and sellers.json to declare who may show ads, resell inventory or collect data. A single file rarely tells the full story. DecryptAds tries to connect those declarations so users, security researchers and operations teams can see the advertising supply chain behind a site or app.
The article matters because it treats adtech as a security topic, not only a privacy annoyance. A weak or abusive ad partner can deliver malvertising, redirect visitors to phishing pages, collect sensitive data or help monetize networks of low-quality AI-generated sites. When one publisher has hundreds of advertising partners, the question is no longer simple consent. It becomes a supply-chain integrity problem.
Why this matters
Before tools like this, ads.txt and app-ads.txt were mostly read by advertising specialists. Normal users almost never opened them. Security teams also struggled because seller IDs, reseller relationships, exchanges and company names are scattered across many sources. DecryptAds turns that scattered data into searchable dossiers, country-risk warnings, ownership hints and a quiet-removals feed. That makes it useful for investigations.
The article uses espn.com as an example. DecryptAds reports 143 ad partners and 19 registered data broker domains in ESPN’s ads.txt and app-ads.txt data. Some broker visibility now exists because California, Oregon, Texas and Vermont require certain data brokers to register if they buy or sell consumer data from those states. DecryptAds also says almost half of those brokers collect geolocation data from ESPN visitors who are not blocking ads, while several disclose device fingerprints or sensitive personal information. A visitor may think they are reading sports news, but the advertising chain behind the page can be much larger.
5 concrete points from the source
- DecryptAds scrapes and correlates ads.txt, app-ads.txt, buyers.json and sellers.json.
- The service is designed for security use cases: malvertising tracing, geo-risk review and AI-slop detection.
- For espn.com, it found 143 ad partners and 19 registered data broker domains.
- The tool flags geo-risk partners in places such as Russia, China, the UAE, Cyprus and other sensitive jurisdictions.
- Its quiet-removals feed tracks sellers that disappear from sellers.json files without public disclosure.
Practical risk
Malvertising often starts with ordinary browsing. A malicious ad can push a fake support alert, a phishing login page, a drive-by download or a deceptive installer. KrebsOnSecurity notes that these attacks are increasingly common on newly generated AI slop sites rather than only on large mainstream destinations. The reason is simple: low-quality content farms often use cheap advertising partners and do not pay for strong ad-quality controls.
Organizations should also care about brand and compliance risk. If employees browse low-quality sites and are redirected to malware, the incident may begin outside corporate systems but still affect corporate devices. If a company runs advertising on its own sites, a poorly controlled ads.txt or app-ads.txt file may allow data to flow through partners that do not match internal policy, customer promises or regulatory obligations.
Checklist
- Users: run a reputable ad blocker, keep browsers updated and do not install software from pop-up ads.
- IT teams: include malvertising in the threat model instead of treating ads as only a marketing issue.
- Website owners: audit ads.txt and app-ads.txt regularly, remove unnecessary resellers and verify sellers.json relationships.
- Compliance teams: review data brokers, geolocation collection, fingerprinting and third-party jurisdictions.
- SOC teams: watch for suspicious redirects, new ad domains, browser warnings and downloads that originate from web sessions.
Conclusion: DecryptAds is useful because it makes a hidden advertising supply chain easier to inspect. The KrebsOnSecurity article shows that adtech can involve personal data, malware delivery, fraud, AI slop and geopolitical risk. The right approach is to review ad partners like software dependencies: know who participates, where they operate, what data they collect, whether exchanges have removed them and whether they really need to be authorized. Source: KrebsOnSecurity – https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
