Digital privacy guide for military families.
Short answer
Military families face a threat profile that no generic privacy guide addresses. Deployment schedules, home addresses, children’s school routines, and the emotional patterns of a household managing separation are information that is ordinary for a civilian family and operationally useful to adversaries. The guidance that reaches service members rarely reaches the family at home, and that information gap is the actual operational vulnerability.
The threat landscape for military families
Foreign intelligence collection against military personnel and their families is documented, ongoing, and increasingly automated. Machine learning tools scan public social media at scale, extracting deployment patterns, unit associations, home addresses, and family composition from posts that individually appear harmless. The aggregated profile is what becomes operationally useful.
The service member receives security briefings. Those briefings are reasonably thorough and cover what the member should and should not post, say, and carry. What they do not cover is the family at home, whose social media accounts are often public, whose posts confirm deployment windows, and whose daily routines establish predictable patterns that surveillance can exploit.
This is not a niche threat. The Department of Defense has formally acknowledged that data broker databases, social media scraping, and commercial location data are threat vectors for personnel security. The acknowledgment has not been matched with consistent guidance to families.
Social media: the highest-priority area
The combination of deployment timing, home address exposure, children’s school details, and absence windows posted on social media creates a complete operational picture from public sources. Nine specific post categories appear most frequently in open-source intelligence reports as high-value collection targets. Knowing which post categories raise the risk is what lets a family adjust the habits that produce them.
The discipline that addresses this is straightforward: audit account privacy settings so all accounts default to private, establish a delay habit where nothing deployment-related is posted in real time, and have the conversation with children and extended family who may post without understanding the implications. In practice, the family member with the highest posting volume is often also the one with the least exposure to OPSEC briefings. The specific risks created by social media during deployment include home address exposure, absence windows, and emotional vulnerability signals that enable social engineering.
Data brokers: the address problem
Data brokers compile home addresses, phone numbers, vehicle registration, employer information, and family member details from public records. For active military families, the commercial availability of the home address creates a specific risk that is more immediate than the generic privacy concern a civilian might have. The specific data broker risk for military families and what to do about it is documented in detail. The short version: submit opt-out requests to the major people-search sites now, and set a quarterly calendar reminder to resubmit because profiles reappear.
The most effective long-term mitigation is a substitute address for anything that creates a public record. A PO box or commercial mail service for vehicle registration, voter registration where the state allows a safety substitute, and any service requiring a physical mailing address prevents the home address from continuously re-entering broker databases from new public records.
Device and account security
A password manager with unique credentials for every account prevents a single breach from cascading through all accounts. For a family managing shared access during deployment, the comparison of 1Password and Bitwarden for military families covers the specific features that matter: shared vaults, Travel Mode for border crossings, and emergency access when one partner is unreachable.
Two-factor authentication on every account that offers it. Use an authenticator app rather than SMS where possible. SMS codes are interceptable through SS7 vulnerabilities and SIM swapping, neither of which requires sophisticated capability to execute. An authenticator app generates codes locally and removes the interception risk entirely.
Photo metadata is a specific and underappreciated risk. Every photo taken on a smartphone embeds GPS coordinates, timestamp, and device model by default. A photo shared in a family group to show the service member is fine includes the precise location where it was taken. Disable location data in the camera app before deployment. On iPhone: Settings, Privacy, Location Services, Camera, set to Never.
Location sharing during deployment
Location sharing creates a persistent data record with operational implications. The specific guidance on location sharing tools and protocols for military families covers when sharing is appropriate, which tools minimise the data record, and when sharing should stop. The key principle: continuous passive sharing creates more exposure than intentional point-in-time sharing. Define the protocol before departure, not during the deployment.
Before the next deployment: the checklist
Set all social media accounts to private. Review who follows each account. Enable two-factor authentication everywhere. Set up a password manager with a shared family vault. Submit opt-out requests to the major data broker sites. Disable location data in camera apps. Establish a delay habit for deployment-related posts. Have the conversation with children and extended family. Build a threat model together so everyone understands what they are protecting and why.
None of this is technically difficult. Most of it takes an afternoon. Having the conversation as a family is the hardest piece of the work, and the one that determines whether the rest holds. A threat model built as a family changes what everyone chooses to share, not just the service member.
Frequently asked questions
Does the military provide this guidance to families?
Some units provide OPSEC briefings that include family guidance. The consistency varies significantly by unit, by branch, and by how seriously individual command takes the dissemination beyond the service member. The realistic working assumption for a family is that the guidance has not been passed on, and to build the baseline accordingly.
Is this relevant for National Guard and Reserve families?
Yes. Guard and Reserve families often have less access to the OPSEC culture of active duty installations and more integration with civilian communities where security habits are not the norm. The threat profile is the same during activation periods. Baseline habits established well before activation hold up far better than ones improvised the week a deployment order arrives.
Should children’s social media accounts be locked down differently?
Yes, with two specific concerns beyond what applies to adults. First, school-related platforms (class directories, sports rosters, district apps) often publish a child’s name, school, and sometimes home address by default, and these need to be audited at the start of every school year. Second, children frequently post about a deployed parent without recognising the operational implications, and the conversation has to happen before the deployment, not during. Lock down accounts to friends-only, disable location services on the device’s camera and apps, and review what is publicly searchable on the child’s name at least once per quarter.
What about extended family members who post about the deployment?
The exposure created by a grandparent or sibling posting deployment dates, homecoming photos, or unit identifiers is often larger than what the immediate family produces, because extended family is rarely briefed and frequently posts publicly. The conversation that needs to happen before deployment includes asking explicit family members not to publish dates, photos with unit insignia, or geotagged content while the service member is deployed. Most extended family will respect the request once it is framed as a security concern rather than a preference, but the request has to be made directly and specifically.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
