Security1 publisher3 min readPublished Updated
A free graph of ads.txt now shows which data brokers your own site authorised
DecryptAds cross-references ads.txt, app-ads.txt and sellers.json into one searchable view. In ESPN's files it counts 143 ad partners and 19 registered data broker domains.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A powerful and free new service called DecryptAds (decryptads.com) has newly launched and scrapes and correlates adtech data to make it simple to learn about entities that track users.
- DecryptAds says it constantly scrapes the files websites and apps make publicly available to disclose companies permitted to run ads or collect user data: ads.txt (adtech companies and data brokers that may run ads or harvest data from the site), app-ads.txt (entities that can harvest data from or display ads on mobile and smart TV apps), and buyers.json/sellers.json (entities buying, selling or reselling ad inventory).
- The adtech information is already semi-public but is not easily parsed, and traditionally much of it has remained walled away in the hands of large advertising platforms.
- Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox.
- Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A free service called DecryptAds has launched, scraping and correlating the adtech disclosure files that websites and apps publish, and turning them into something you can query [1][2]. That matters for defenders because those files are permission lists the publisher wrote, so for the first time an outside party can hand any organisation a list of the data brokers and ad networks its own properties have authorised to collect from its users [2][1].
The underlying data has always been semi-public but hard to parse, and much of it stayed inside large advertising platforms [3]. The files in scope are ads.txt, which names the adtech companies and data brokers permitted to run ads or harvest data from a site; app-ads.txt, which does the same for mobile and smart TV apps; and buyers.json/sellers.json, which name the entities buying, selling or reselling inventory [2].
Zach Edwards, chief research officer at DecryptAds and a threat researcher at Infoblox, said he and two other founders built it because the data is only useful when cross-referenced [4][5]. "It's an adtech tool but we're trying to approach adtech from a security perspective," Edwards said, describing the intended users as privacy and security teams that have been "dramatically underserved" [6]. The stated use cases are tracing malicious ads back to their source, identifying ad networks in adversarial nations, and spotting AI-generated slop sites and apps [7]. The service's own explanation of why single-file review fails is the most useful part of the pitch: "Supply-chain integrity issues rarely live in a single file," it says, pointing to broken cross-references between ads.txt, app-ads.txt and sellers.json, cloned declaration sets on unrelated domains, seller removals that only make sense across exchanges, and supply paths in bid logs that never appear in any publisher's authorised-seller list [8].
The concrete example is worth reading as an audit template. According to DecryptAds, a search for espn.com returns 143 ad partners and 19 registered data broker domains declared in its ads.txt and app-ads.txt files [9]. Almost half of those brokers, so roughly nine, disclose collecting geolocation from visitors who are not blocking ads, and three disclose device fingerprints and sensitive personal information [10][2]. That broker detail exists at all because California, Oregon, Texas and Vermont recently passed laws requiring data brokers to register if they buy or sell data on residents of those states [11].
DecryptAds also flags partners based in geo-risk areas including China and Russia, plus countries with strong financial and political ties to them such as Cyprus and the UAE [12]. It says espn.com works with four entities based in Russia, China or the UAE [13], among them Between Digital, which lists a New York address but which DecryptAds flags as Russian on the basis that its publisher offers are processed through Alfa Bank, Russia's largest private commercial bank and a US sanctions target since 2022 [14][15]. KrebsOnSecurity reported that Between Digital and its founder did not respond to requests for comment before publication [16]. Searches for armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com show all six permit Between Digital to serve ads and track users, along with two UAE entities and one in Panama [17].
Worth watching: whether Between Digital replies [16]; and whether security teams treat their own ads.txt as an asset inventory item rather than a marketing artefact, since it is a file their organisation signs and publishes [1].