A groundbreaking report by the Citizen Lab has unveiled widespread use of an advertising-based global geolocation surveillance system named Webloc by various law enforcement and intelligence agencies worldwide, including Hungarian domestic intelligence, the national police in El Salvador, and numerous departments across the United States. This powerful tool, originally developed by Israeli firm Cobwebs Technologies and now marketed by its successor Penlink, harvests a continuous stream of location data and personal identifiers from hundreds of millions of mobile devices, raising significant concerns about privacy, civil liberties, and the potential for warrantless surveillance.
The Webloc System: A Deep Dive into Ad-Based Surveillance
Webloc operates on a principle that blurs the lines between digital advertising and sophisticated surveillance. It leverages the vast, often unregulated, ecosystem of mobile apps and digital advertising to continuously collect sensitive user data. According to Citizen Lab researchers Wolfie Christl, Astrid Perry, Luis Fernando Garcia, Siena Anstis, and Ron Deibert, Webloc provides access to an incessantly updated flow of records originating from up to 500 million mobile devices globally. These records encompass device identifiers, precise location coordinates, and various profile data points, all systematically harvested from mobile applications and the sprawling digital advertising industry.
The system, officially introduced by Cobwebs Technologies in October 2020, was initially promoted as a "cutting-edge location intelligence platform that gathers and analyzes web data fused with geospatial data points, using interactive layered maps to connect the digital world with physical data." In essence, Webloc allows its clients to analyze the behaviors and movements of vast populations by tapping into data that most users unknowingly generate through their everyday smartphone usage. This includes not only real-time tracking but also the ability to retrospectively monitor locations, movements, and personal characteristics of entire populations for up to three years into the past. Penlink’s own website highlights Webloc’s utility for "investigating and interpreting location-based data to support your cases," further indicating its application in investigative work. Disturbingly, the system also boasts capabilities to infer location from IP addresses and, critically, identify the individuals behind these devices by aggregating their home and workplace addresses, transforming anonymous data points into personally identifiable information.
A Growing Roster of Users: Domestic and International Agencies
The Citizen Lab report meticulously identifies a broad spectrum of governmental entities that have been attributed to the use of Webloc. Internationally, this includes the domestic intelligence apparatus of Hungary and the national police force of El Salvador, suggesting a global reach for the technology’s deployment in state surveillance operations.
Within the United States, the list of customers is extensive and spans various levels of government and law enforcement. Federal agencies such as Immigration and Customs Enforcement (ICE) and the U.S. military are noted users, indicating the tool’s integration into national security and border enforcement operations. At the state level, the Texas Department of Public Safety and DHS West Virginia have reportedly utilized Webloc. The system’s adoption also extends to prominent urban and regional law enforcement bodies, including the New York City district attorneys’ offices and police departments in major cities like Los Angeles, Dallas, Baltimore, Tucson, and Durham. Furthermore, its presence is documented in smaller municipalities and counties, exemplified by the City of Elk Grove and Pinal County, illustrating the pervasive nature of this technology across diverse jurisdictional scales. The breadth of these clients underscores a significant trend: the increasing reliance of government agencies on commercially available, often opaque, surveillance technologies to augment their investigative and intelligence-gathering capabilities.

From Cobwebs to Penlink: A Corporate Evolution and Entanglement
The journey of Webloc is intrinsically linked to the corporate evolution of its original developer, Cobwebs Technologies. Founded in Israel, Cobwebs established itself as a purveyor of sophisticated digital intelligence tools. The company’s trajectory saw a significant shift in July 2023 when it merged with Penlink, a long-standing provider of "mission-critical communications and digital evidence collection and analysis software" to law enforcement agencies globally, founded in 1986. Following this merger, Penlink became the primary vendor for Webloc, integrating it as an add-on product to its existing social media and web intelligence system, Tangles.
This corporate consolidation highlights a broader trend in the surveillance industry, where specialized tech firms merge to offer comprehensive digital investigative platforms. Penlink, with its established global network, provides an expanded market reach for Webloc’s capabilities. However, this transition also inherits the historical baggage and controversies associated with Cobwebs Technologies, which have drawn significant scrutiny from privacy advocates and human rights organizations.
A History of Controversy: Cobwebs Technologies and Ethical Red Flags
Cobwebs Technologies is not new to controversy. In December 2021, the company was publicly deplatformed by Meta (formerly Facebook) as one of seven "cyber mercenaries." Meta’s investigation revealed that Cobwebs Technologies operated approximately 200 accounts on its platforms, which were used to conduct reconnaissance on targets, engage in social engineering tactics to infiltrate closed communities and forums, and trick individuals into divulging personal information. This aggressive and deceptive online activity directly contravened Meta’s policies on coordinated inauthentic behavior and surveillance.
Meta’s findings indicated that Cobwebs Technologies’ customers were located in various countries, including Bangladesh, Hong Kong, the United States, New Zealand, Mexico, Saudi Arabia, and Poland. Critically, Meta noted that in addition to activities related to law enforcement, it observed "frequent targeting of activists, opposition politicians, and government officials in Hong Kong and Mexico." This revelation paints a concerning picture of a technology designed for law enforcement being potentially repurposed for political surveillance and repression, a common fear associated with the proliferation of such powerful tools.
Furthermore, corporate records and public information reviewed by Citizen Lab reveal an unsettling connection between Cobwebs Technologies and another controversial Israeli spyware vendor, Quadream. This link is traced through Omri Timianker, the founder and former president of Cobwebs Technologies, who now oversees Penlink’s international operations. Quadream itself gained notoriety for its sophisticated mobile spyware, which was implicated in various human rights abuses, and the company is suspected to have ceased operations in 2023, possibly due to increased scrutiny and regulatory pressure. These connections raise serious questions about the ethical underpinnings and operational standards within certain segments of the commercial surveillance industry.
The Mechanics of Mass Tracking: How Webloc Operates

Webloc’s operational sophistication lies in its ability to aggregate and analyze vast quantities of data. The system’s core functionality revolves around the continuous monitoring of unique mobile advertising IDs (MAIDs), geolocated IP addresses, and connected devices. These identifiers, routinely generated and shared within the digital advertising ecosystem, become critical data points for surveillance.
As detailed in various reports from outlets like 404 Media, Forbes, and the Texas Observer, Webloc is designed to track phones without requiring a warrant. A procurement notice highlighted the tool’s "ability to automate and continuously monitor unique mobile advertising IDs, geolocated IP addresses, and connected devices analysis." This automated, continuous collection of data allows agencies to build comprehensive profiles of individuals’ movements, routines, and associations over extended periods. The system’s capacity to infer locations from IP addresses adds another layer of tracking, even when direct GPS data might be unavailable. By correlating these data points with other publicly or commercially available information, Webloc can reportedly identify individuals by their home addresses and workplaces, effectively de-anonymizing vast datasets and linking digital footprints to physical identities. This extensive data collection and analysis capability equips agencies with an unprecedented level of insight into public and private lives.
The Legal and Ethical Quagmire: Warrantless Surveillance and Privacy Concerns
The widespread deployment of Webloc by government agencies, particularly without clear legal frameworks or judicial oversight, presents a profound challenge to established norms of privacy and civil liberties. The ability to track individuals and entire populations for years into the past, without a warrant, directly clashes with constitutional protections in many democracies, such as the Fourth Amendment in the United States, which guards against unreasonable searches and seizures.
Civil liberties advocates argue that ad-based surveillance tools like Webloc exploit a legal loophole. While direct government access to location data typically requires a warrant based on probable cause, purchasing the same data from commercial data brokers, who collect it without individual consent for advertising purposes, circumvents these protections. This "data broker loophole" allows law enforcement to conduct what amounts to mass surveillance through commercial channels, bypassing judicial review and democratic accountability.
The implications are vast. Such systems can be used to monitor political protests, track journalists, target minority groups, or suppress dissent, as suggested by Meta’s findings regarding Cobwebs’ activities in Hong Kong and Mexico. The lack of transparency surrounding the acquisition and use of this data further exacerbates concerns, making it difficult for individuals to know if their data is being collected, how it is being used, or to seek redress. The very nature of this surveillance — covert, pervasive, and often without individual suspicion — represents a significant erosion of the right to privacy and the presumption of innocence.
Official Responses and Industry Scrutiny
In response to the Citizen Lab report, Penlink issued a statement asserting that the findings "appear to rely on either inaccurate information or a misunderstanding about how we operate, including practices that Penlink does not engage in following our acquisition of Cobwebs Technologies in 2023." The company also claimed compliance with U.S. state privacy laws. This response, while acknowledging the report, seeks to distance the current Penlink operation from past practices attributed to Cobwebs Technologies prior to the merger. However, it does not explicitly deny the existence or capabilities of Webloc as described, nor does it detail specific changes in data acquisition or usage policies that would definitively address the concerns raised by Citizen Lab.

Citizen Lab, in turn, reiterated its findings, stating, "Our research shows that intrusive and legally questionable ad-based surveillance (i.e., without a warrant or adequate oversight) is being used by military, intelligence, and law enforcement agencies down to local police units in several countries across the globe." This highlights the core disagreement: whether such ad-based data collection, when repurposed for surveillance, can ever be considered legally or ethically sound without robust oversight.
The broader surveillance industry faces increasing scrutiny. The revelations surrounding Pegasus, Predator, and other sophisticated spyware have brought the "cyber mercenary" market into sharper focus, leading to calls for stricter regulation and export controls. The Webloc case adds another dimension to this debate, illustrating how seemingly innocuous commercial data streams can be weaponized for pervasive surveillance.
Global Reach and Geopolitical Implications
The Citizen Lab’s analysis of corporate records and other public information revealed 219 active servers associated with Cobwebs product deployments. A significant concentration of these servers is located in the U.S. (126), followed by the Netherlands (32), Singapore (17), Germany (8), Hong Kong (8), and the U.K. (7). Additionally, potential product servers were detected in various countries across Africa, Asia, and Europe. This geographical distribution underscores the global infrastructure supporting Webloc and similar surveillance tools.
The presence of servers in countries with varying human rights records and legal protections amplifies concerns about the potential for misuse. While U.S. agencies might operate under certain constitutional constraints (even if circumvented by the data broker loophole), the use of such tools by regimes with less regard for civil liberties poses a grave risk. The involvement of Hungarian intelligence and El Salvador’s national police, both operating in contexts where democratic institutions and human rights are sometimes challenged, serves as a stark reminder of the geopolitical implications of commercial surveillance technologies. These tools can empower authoritarian tendencies, facilitate political repression, and undermine democratic processes by providing governments with an invisible and potent means of monitoring their populations.
The Future of Digital Privacy: Navigating the Surveillance Economy
The Webloc revelations represent another critical chapter in the ongoing struggle for digital privacy in an increasingly data-driven world. The commercial availability of such powerful surveillance tools to a wide array of government agencies, often without transparent legal frameworks or adequate judicial oversight, poses an existential threat to individual liberties. The fusion of the advertising economy with the surveillance state creates a potent, largely unregulated, ecosystem where personal data becomes a commodity for tracking, monitoring, and potentially controlling populations.
As technology continues to advance, the onus falls on policymakers, legislators, and civil society to demand greater transparency, establish robust legal protections, and enforce strict accountability for both the developers and users of these systems. Without concerted efforts to regulate the data broker industry, close legal loopholes, and ensure judicial oversight, the promise of digital connectivity risks devolving into a pervasive and inescapable surveillance reality, where the movements and lives of millions are continuously tracked, analyzed, and potentially exploited without their knowledge or consent. The Webloc case serves as a clarion call for urgent action to safeguard privacy in the digital age.
