2026-09-15
Four Apache helicopters were destroyed over a geotagged photo in 2007 — the Army's warning about it still gets repeated every year
In 2007, a new fleet of AH-64 Apache helicopters arrived at a U.S. aviation unit's base in Iraq. Soldiers photographed them on the flightline and put the pictures online. Steve Warren, an intelligence officer at the Army's Maneuver Center of Excellence, later explained what happened next: "from the photos that were uploaded to the internet, the enemy was able to determine the exact location of the helicopters inside the compound and conduct a mortar attack, destroying four of the AH-64 Apaches." No one had leaked coordinates on purpose. The phones and cameras the soldiers used had simply done what they were built to do — write a GPS tag into each photo file, silently, the moment the shutter closed — and the photos carried that tag with them straight through to a public web page.
The warning that followed, and the one that's still being repeated
The Army made the incident public specifically to make a point about geotagging, and that point has been repeated in Army-published guidance ever since — not as history, but as a live warning. An army.mil article from the Army's most recent OPSEC Awareness Month, published May 7, 2025, tells service members and their families the same thing the 2007 incident already proved: "Turn off geotagging and location-based social networking on phones and digital cameras," and "closely review photos or videos before posting to ensure sensitive or personal information is not released." The 2025 version widens who it's aimed at, too — it's addressed as much to people who never deploy anywhere as to the soldiers who do: "Even seemingly innocent posts about a family member's deployment or redeployment date can put them at risk," the article warns, because "small bits of information can be assembled to make big pictures." A spouse's homecoming photo, posted from a driveway or an airport gate, carries the same embedded GPS tag a flightline photo does — the risk the Army is describing isn't about who's holding the camera, it's about what the file quietly records regardless of who that is.
A different kind of tracking — and where the line actually sits
It's worth being precise here, because a more recent, more widely reported military story is often folded into the same conversation and it describes a different mechanism entirely. On New Year's Day 2023, a Ukrainian strike on a school housing Russian troops in Makiivka killed dozens of soldiers; Russia's own Ministry of Defence blamed "the switching on and massive use... by personnel of mobile phones in a reach zone of enemy weapons," saying it let the enemy "track and determine the co-ordinates of the soldiers' location for a missile strike." In 2025 the Marine Corps Commandant cited that incident directly in a warning that a Marine's phone "can get you killed." That's a real and current risk, but it's a network one: an active phone, powered on, gives off a signal a sufficiently equipped adversary can locate in real time, whether or not a single photo is ever taken. The 2007 Apache case is a file one: a GPS coordinate written once, into a JPEG, sitting inert until that specific file is shared. NearScrub has nothing to say about the first kind of risk — it can't turn a phone's radio off, and it isn't built to. It exists entirely for the second kind: the coordinate already sitting inside a photo file someone is about to post, forward, or upload.
"Turn off geotagging" and "wipe the tag" are two different fixes
The Army's own guidance actually names two separate defenses, and it's worth keeping them separate because they solve different moments. "Turn off geotagging... on phones and digital cameras" is a device setting: change it, and the next photo that camera takes never gets a coordinate written into it in the first place. That's the stronger fix where it's available, but it does nothing for a photo that's already been taken — an old flightline photo, a homecoming picture someone else snapped and sent over, a photo shot on a device where geotagging was never turned off, or a picture taken before anyone thought to check the setting. For that photo, the file already has the tag, and the only way to get rid of it is to strip it out of that specific file after the fact — which is the "wipe EXIF data from a photo you've shot" step, not the "never capture it" one. NearScrub is built for exactly that second moment: it reads a JPEG or PNG already sitting on a device, removes the embedded GPS coordinate along with the rest of the EXIF, XMP, and IPTC block, and does it entirely in the browser tab — no upload, nothing sent anywhere — before that file goes to a group chat, a social post, or a photo-sharing site.
Who this actually reaches, and what NearScrub can't do
Nothing about this mechanism is military-specific — an AH-64 flightline and a family's driveway carry the identical file format and the identical tag, which is exactly why the Army's 2025 warning now names family members' posts by name rather than only soldiers'. Anyone sharing a photo taken on a phone or camera with location services on is carrying the same coordinate the 2007 incident turned into a mortar strike, just usually with lower stakes attached. NearScrub's part in that is narrow and worth stating plainly: it strips the GPS tag (and other metadata) from a JPEG or PNG file someone hands it, locally, before that file leaves the machine. It cannot reach a photo that's already been posted somewhere and copied by other people. It can't flip a phone's geotagging setting off for the next photo — that's still a setting the device owner has to change themselves. And it has no bearing at all on the network-level tracking a live, powered-on phone can expose, which is a different problem with a different fix. What it does do is close the specific gap both the 2007 incident and the 2025 warning describe: a coordinate sitting quietly in a file, waiting for someone to share it without checking.