Your Apple Watch & the Surveillance Economy
6 comments
In This Story
A Former CIA Case Officer on Flock Cameras, Data Brokers, & the Surveillance Economy Watching All of Us
Last month, Apple announced several updates to the Apple Watch, most notably Audio Intelligence features Live Rewind and Siri Recap, two applications that essentially record “ambient audio” and have the capability to generate daily transcripts of the wearer's conversations. According to Apple, these are opt-in services, where users have to balance privacy and convenience, the inevitable trade-off. But the fact that this is now a marketed feature, not a leaked vulnerability, tells you something about where we've actually arrived: a post-privacy world.
The new Apple Watch features are just the latest example of technology, developed theoretically to make our lives better, that encroaches on our privacy. Flock Cameras, fitness trackers, smart doorbells, and camera glasses all follow the same arc. Flock's plate readers were sold to fight local crime but log every passing car, and agencies far beyond the buying town have searched that data. Strava's 2018 heat map exposed the layout of military bases. Ring turned porches into a police-accessible camera network, and Meta's glasses put a discreet recorder on a stranger's face. All were pitched as convenient commercial products, not surveillance. We are all guilty (myself included) of just clicking the terms and conditions without reading the fine print.

Strava’s public “Heat Map” feature shows the routes taken by its users, and the data has been used to expose the location of several secret US Military bases in 2018. (Photo Credit: The Guardian)
The Apple Watch is just one vector but arguably the most public and personal one, since it sits against your skin and collects health data, sleep data, heart rate, and now ambient audio that legacy devices never touched. But it is one thread in something much larger. We live in a surveillance economy, a fully operational, commercially funded one, and the watch on your wrist is just the entry point people notice first because it is one they chose to buy.
Data Brokers - Leaving CIA
When I left CIA, I quickly found my phone (Signal) ringing from various recruiters. My previous occupation as a CIA Case Officer was unknown to the outside world, but word travels fast in certain circles. I would often entertain the outreach with a call or coffee, out of pure curiosity.

Whether we like it or not, our data is for sale, and the buyers might surprise you. (Photo Credit: CNN)
During a meeting in a northern Virginia conference room, I was briefed on a project to procure commercially available data sets to be repackaged and sold to both US government and commercial clients. At the time, these data sets were mostly geolocational data from cell phone applications but also “alternative data sets” like shipping manifests and telecom data records. None of it was classified or stored on government servers; all of it was for sale.
The model was simple: procure the disparate data sets, repackage them and offer some processing power if needed, and sell them many times over. The legal logic was just as tidy: the data was commercial and did not require a warrant or court order; for the most part, the individuals had consented to the collection when they downloaded an application on their phone. While this company dealt solely in data collected outside of the United States borders, the same capability was being done in the United States for advertising purposes. As a (former) CIA Case Officer, the private entity assumed (correctly) that I would be well suited to identifying and negotiating the transfer of data sets for an unspecified use. This was my first firsthand view into the commercial surveillance economy.
Isn't an iPhone the Same Risk as a Smartwatch?

While phones present their own risks, wearables like smartwatches can be even more problematic. (Photo Credit: W.O.E./James Rupley)
At W.O.E., we focus on the risk of Smartwatches and wearables, because that is within our wheelhouse (“Watches” of Espionage), but they do represent a unique challenge (or opportunity). When worn, the watch's mic is always within arm's reach of your voice, unlike a phone that might be in your pocket or in the next room. It also collects more data: heart rate, sleep, even hand movements some studies say can reveal passwords. While today, data brokers focus primarily on easily interpretable data, soon this type of “alternative” data could be used for either marketing or surveillance purposes. Most importantly, unlike a phone, though, a smartwatch is easily replaced with an analog tool that cannot be hacked.
Data + Artificial Intelligence + Processing Power
When I worked at CIA, Targeting Officers had to sift through various data sets manually to make connections and build patterns of life. But a lot has changed in a short period. None of the individual pieces here are new; phone data, fitness data, toll records, and plate scans have all existed for years. What's new is the aggregation. AI has collapsed the cost of stitching it all together; work that used to take a team of analysts days now takes a machine seconds. This change is parallel in the private sector; using AI, commercial entities can build complete profiles on individuals from disparate data sets for marketing purposes.
Surveillance Capitalism - Government vs Private Sector

While the FBI (probably) isn’t watching you, big corporations definitely are. (Photo Credit: Harvard Business School)
For most, the fears of government surveillance are most concerning. That said, in my experience having worked at CIA and closely with FBI, today these concerns are largely unfounded (“That’s exactly what a former CIA would say!”). Despite what your favorite podcaster will tell you to believe in between Athletic Greens ads, if you aren’t breaking the law, the FBI has neither the mandate nor the manpower to care what you're doing. And no, despite what Hollywood tells you, CIA cannot spy on Americans domestically; this is something that was taken very seriously and heavily scrutinized when I was at CIA.
The commercial side is a different story: if you provide consent when you approve the terms and conditions when downloading an application, there is no right to privacy. Advertisers are tracking your every move and monetizing it, building a profile of who you are, what you want, and when you're most likely to buy. This isn't hypothetical; it's happening now on (almost) every app on your phone (or watch).
And this data doesn't expire. It gets stored, sold, and resold indefinitely. Just because it isn't being used against you today doesn't mean it couldn't be tomorrow, and it doesn't mean a foreign government hasn't already paid to find out. The US government's concerns are not entirely unfounded; there are checks and balances in place today, but that isn't a permanent guarantee; it's a snapshot of the current political moment. An authoritarian government decades from now could reach back and use data collected about you today, long after you assumed it was irrelevant or gone.
Counterintelligence Risks of Smartwatches & Fitness Trackers

(Photo Credit: CENTCOM)
In an April 2026 letter to Congress, CENTCOM confirmed it had received "multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater," the first time the U.S. military has confirmed adversaries buying commercial data to target troops in an active war zone. The Financial Times separately reported that actors linked to Iran used purchased advertising data to track American phones in Iraqi Kurdistan, identifying which hotels housed U.S. personnel after forces evacuated their main bases. There are currently few, if any, restrictions on commercial entities selling this data overseas, and a simple cut-out would make this difficult to enforce.
But Iran, or anyone else, doesn't even need to buy anything to get the same result. Much of this information has been sitting in plain sight for years, posted voluntarily by the wearers themselves. In 2018, a fitness app called Strava's public heatmap exposed a previously unknown U.S. base in Niger. In 2020, a Bellingcat researcher faked a run at the British Special Air Service base in Hereford and identified 14 operators, using nothing but the app's default settings. By 2022, an Israeli NGO replicated the trick at scale, unmasking roughly 100 personnel across six bases, the same year cyclist Moriah Wilson was murdered by a woman who tracked her through Strava.

Russian submarine commander Stanislav Rzhitsky was shot dead in 2023 after being tracked using his publicly uploaded Strava data.
As we have previously discussed, a Russian submarine commander was assassinated via his own Strava run in 2023, and protective details for Macron, Trump, Biden, Putin, and the Swedish Prime Minister all leaked their principals' movements the same way. Almost all of it traces back to the same source: a smartwatch, worn constantly, syncing GPS and heart rate data to an app by default. This information is open source and voluntary. A bad actor doesn't need a broker for that; it just needs someone to not check their privacy settings.
Flock, Tolls, Tires, & the Car You Cannot Hide

Flock cameras have gone viral in recent months because of the privacy issues they present. (Photo Credit: The Boston Globe)
Arguably the most public and forefront example of the commercial surveillance state is Flock cameras. License plate reader technology has been around for years, but for whatever reason, this one company has gone viral. With an estimated 120,000 cameras nationwide capturing about 20 billion vehicle images per month (according to Flock Safety), the system is marketed for law enforcement, logging billions of plate scans across the country, but that same infrastructure could just as easily be repurposed for commercial use.
A newer sensor called SignalTrace, made by defense contractor Leonardo, takes it further, fingerprinting a vehicle by the Bluetooth, Wi-Fi, and RFID signals leaking out of it, your phone, your earbuds, and especially your wearable, since a Whoop, Fitbit, Oura, or Apple Watch broadcasts constantly and rarely gets switched off. Toll transponders do the same job quietly, logging your route every time you pass a reader.
Deleted Doesn't Mean Gone

Apple famously denied access to the San Bernardino shooter’s phone in 2015, though the FBI eventually hacked into it anyway using a zero-day exploit provided by a contractor.
Many applications, including the new Apple Watch technology, insist that data is not stored or transmitted, and to be fair, Apple has a good track record on privacy. The company famously refused an FBI order to build a backdoor into the San Bernardino shooter's iPhone in 2016, a stance it held even under direct pressure from the federal government.
That said, when Nancy Guthrie went missing from her Arizona home in February 2026, footage that appeared deleted from her Google Nest doorbell was later recovered by the FBI, pulled from what the agency described as residual data sitting in backend systems.
Deleted, in some consumer technology, doesn't necessarily mean erased. It usually just means hidden from you, the user, while the data itself could be somewhere on a company's servers whether it intended to or not. That's worth remembering every time an app or a device promises your data isn't being kept.
Final Thoughts
If you went back 20 years and described the surveillance capitalism state we are living in today, people would be shocked. But these transitions have occurred slowly over time and often outside the public eye. Flock cameras tracking your moves and Apple watches listening in on your conversations are just the latest and most public examples of this new reality.
Live Rewind and Siri Recap aren't the threat; they're the preview. This is just the beginning of the post-privacy world, and we will continue to see more sensors, cheaper processing, and easier aggregation, and enticing products convincing us to hand this information over. Minority Report, or “predictive policing,” may not be as far off from the truth as we'd like to think, and the real version arrived quieter than the movie ever imagined. The worst part is that there is no single agency, no court oversight, just a marketplace where anyone with money, foreign or domestic, gets a seat at the table.
One simple step is to wear a mechanical watch. A Seiko can’t be hacked; it doesn't ping a server, doesn't build a profile, and doesn't hand your location, heart rate, and interests to a company that swears it's just for convenience. Besides, you look a lot cooler with a Turtle on your wrist in your Christmas card photos.
This Dispatch has been reviewed by the CIA’s Prepublication Classification Review Board to prevent the disclosure of classified information.
All statements of fact, opinion, or analysis expressed are those of the author and do not reflect the official positions or views of the US Government. Nothing in the contents should be construed as asserting or implying US Government authentication of information or endorsement of the author's views.
If you enjoyed this article, please consider signing up for our weekly free newsletter for further updates HERE.
At Watches of Espionage, all of our content is directly supported by our shop. To learn more about our collection of purpose-built tools designed for our community, click HERE.

6 comments
I have never owned a smart watch and never will. I would like to think that this article points out the main reason why, but I would be fooling myself as I know the iPhone and really any connected device is doing this stuff already.