Skip to main content
Security

Bluetooth tracker mailed to Dutch warship exposes location for 24 hours, prompting security review

Warship at sunset in the sea Image: Primary
A Dutch warship's location was exposed for 24 hours after a journalist mailed a postcard containing a hidden Bluetooth tracker to the vessel, highlighting vulnerabilities in naval operational security. The HNLMS Evertsen, a $585 million air-defense frigate part of a NATO carrier strike group centered on the French carrier Charles de Gaulle, received the postcard after the Dutch Ministry of Defense published instructions online for communicating with personnel aboard naval ships. Dutch journalist Just Vervaart of regional media network Omroep Gelderland followed the published directions and concealed a tracker in mailed correspondence. The tracker allowed monitoring of the ship's movements for approximately one day as it sailed from Heraklion, Crete, toward Cyprus. While only tracking the single vessel, knowledge of its position as part of a carrier strike group in the Mediterranean could have exposed the entire fleet to targeting, according to security analysts. Navy officials discovered the device within 24 hours during mail sorting and disabled it. In response, Dutch authorities have banned electronic greeting cards on ships, which unlike packages were not subject to X-ray screening. The incident reveals how low-cost consumer tracking technology. Bluetooth trackers like Apple AirTags cost around $29, with generic versions available for as little as $10 for two. can compromise military security without requiring physical access to vessels. This is not the first operational security lapse involving NATO naval forces. Last month, a French officer aboard the Charles de Gaulle posted running data to Strava that revealed the carrier's Mediterranean location through open-source intelligence methods. In 2024, the USS Manchester, a U.S. Navy littoral combat ship, was found to have an unauthorized Starlink terminal installed for six months before discovery; sailors had used the covert internet connection, labeled "STINKY," while at sea. Military analysts note that seemingly innocuous technologies. social media check-ins, fitness tracking apps, and consumer tracking devices. create open-source intelligence vulnerabilities by revealing personnel locations, schedules, and habits. While such data exposure may pose minimal risk to civilians, it provides adversaries with valuable information for confirming or inferring military movements and capabilities.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Tom's Hardware and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Google issues Chrome update for actively exploited V8 flaw

Google has released an emergency Chrome update for CVE-2026-85046, a high-severity type-confusion vulnerability in the browser's V8 JavaScript and WebAssembly engine, according to Cybersecurity News. The report says Google is awar...

Capital
Capital

Anthropic nears $15 billion revolver ahead of IPO filing

Anthropic is set to finalize an expansion of its revolving credit facility to $15 billion, according to people familiar with the matter cited by Bloomberg. Morgan Stanley is leading the process, with Goldman Sachs, JPMorgan Chase ...

Infrastructure
Infrastructure

Firmus commits $300 million for Australia-US cable capacity

Australian AI cloud firm Firmus will invest $300 million to secure up to 150Tbps of dedicated capacity for 25 years on SubCo's planned APX East submarine cable system. The 16-fiber-pair cable, first announced in January, is inten...

AI
AI

G42 explores majority US ownership to protect chip access

Abu Dhabi-based AI company G42 has held exploratory talks about potentially selling a majority stake to American companies, according to people familiar with the matter. The reported discussions are aimed at securing the company's...

Infrastructure
Infrastructure

Meta brings Kuna AI-optimized data center online

Meta's Kuna, Idaho, data center is now serving traffic, according to the company's data-center development vice president. The facility is Meta's second AI-optimized site to come online and represents an overall investment of $1.2...

Infrastructure Policy
Infrastructure Policy

Russia bans crypto mining in Moscow region through 2032

Russia's government has banned cryptocurrency mining and mining-pool participation in Moscow, the surrounding region and parts of Kursk through the end of 2032 under Government Decree No. 936. The measure is intended to reduce pre...