Reports have surfaced suggesting Iranian forces might be using data shared by Strava users at U.S. military bases in the Middle East to target American forces. Strava is a fitness app that tracks activities like running, cycling, and swimming.
The Pentagon initiated a review in 2018 regarding its personnel’s use of fitness apps due to concerns that adversaries could utilize the information to assess personnel movements and day-to-day operations.
The Pentagon concluded these apps posed a security risk and restricted their use without prior approval.
Despite these measures, Sky News analysis indicates Strava data continues to be shared by numerous individuals at U.S. military bases, potentially exposing frontline personnel in the conflict with Iran. An expert, Jonathan Hackett, noted that “lax enforcement and lack of awareness” contribute to the sharing of sensitive location data, which Iran may exploit to track U.S. troop movements.
Sky News identified more than 1,300 users sharing workouts at U.S. military bases, often under their real names, making them potential targets for espionage and attacks. Following U.S. and Israeli airstrikes on Iran on February 28, Iran struck back at American bases in the Middle East. Among them was a naval base in Manama, Bahrain, attacked on March 1, but it had already been evacuated.
Sky News discovered a Strava account belonging to a U.S. Navy contractor who had logged runs around the naval base shortly before the retaliatory strikes. At Jordan’s Muwaffaq Al Salti Air Base, personnel posted hundreds of tracked runs, which continued during a ceasefire in April. These runs began or ended at the barracks on the eastern side of the base, a location targeted by Iran on July 17, resulting in the deaths of three soldiers.
The issue extends beyond U.S. forces. British soldiers have also shared sensitive data at RAF Akrotiri in Cyprus, and Strava users traced jogs inside Israel’s Dimona nuclear research center, increasing vulnerability to Iranian attacks.
According to a report by French newspaper Le Monde, Secret Service agents and American security personnel posted runs on Strava, inadvertently revealing operational routines. A French officer disclosed the location of an aircraft carrier heading towards the Middle East.
The investigation highlighted how fitness data can delineate sensitive military positions, including Israeli forces near Gaza and French President Emmanuel Macron’s security detail near official residences.
Mapulus, a location intelligence platform, noted that consumer apps could generate intelligence-grade data, transforming personal tracking into a global surveillance tool. A case of open-source intelligence demonstrates how everyday data can become a national security weakness.
A Dutch newspaper reported Peter Reesink, head of the Netherlands’ military intelligence service, kept a public Strava account for years, revealing his home address, holiday timings, and locations, breaching defense ministry guidelines.
Strava emphasized its commitment to user privacy and encouraged those in sensitive roles to utilize available privacy controls to limit content exposure.
