Menu

Potential Security Risks from Strava Data at U.S. Military Bases

1 hour ago 0

There are concerns that Iran’s forces may have used data shared by Strava users at U.S. military bases in the Middle East to target American forces. The Pentagon initiated a review in 2018 regarding the use of fitness apps like Strava by its personnel. These apps, which monitor routes and times for activities such as running and cycling, could inadvertently share sensitive information.

The Pentagon’s analysis concluded that these apps pose a security risk, leading to a ban on their use without prior approval. Despite these precautions, Sky News reported that data from Strava was still being shared by numerous users at U.S. military bases. This potentially compromises American personnel engaged in operations against Iran.

“Lax enforcement and lack of awareness” contributed to the sharing of location data, according to special operations expert Jonathan Hackett. Iran likely utilized this data to track U.S. troop movements across the Middle East, as he told Sky News.

Sky News discovered over 1,300 Strava users who shared workouts from U.S. military bases, often using their real names, making them potential targets for attacks or espionage. Following a joint U.S. and Israeli airstrike on Iran on February 28, Iran retaliated by hitting American bases across the Middle East. One such location was a major naval base in Manama, Bahrain, hit on March 1, although it had been evacuated.

Sky News identified a U.S. Navy contractor’s Strava account at the Manama site, which recorded runs up until a week before conflict broke out. Similarly, before the war, U.S. personnel at Jordan’s Muwaffaq Al Salti Air Base recorded numerous runs on Strava. During an April ceasefire, activity on Strava resumed but was more localized. The barracks, which became a starting and endpoint for runs, were attacked by Iran on July 17, resulting in three soldiers’ deaths.

Troops from other countries were also found sharing sensitive data. British soldiers posted activities from RAF Akrotiri in Cyprus, a known target of Iran. Additionally, three Strava users in Israel’s Dimona nuclear research center leaked location data, a frequent target of Iranian attacks.

French newspaper Le Monde reported Secret Service agents and other American security personnel also disclosed operational routines through Strava. The paper’s #StravaLeaks investigation highlighted how fitness data mapped sensitive military positions. This included Israeli soldiers near Gaza and French President Emmanuel Macron’s security team jogging near his residences.

Location intelligence and geospatial platform Mapulus acknowledged the security vulnerabilities posed by consumer technology that generates intelligence-grade data. They stated that “personal fitness tracking, at scale, becomes a global surveillance network.”

According to Mapulus, “This is a classic case of open-source intelligence (OSINT): everyday consumer data becoming a national security vulnerability.”

Dutch newspaper de Volkskrant reported that Peter Reesink, head of the Netherlands’ military intelligence service, maintained a public Strava account. His activities from 2018 to 2025 revealed personal locations, breaching defense ministry guidelines.

Strava responded to Sky News, emphasizing its commitment to users’ safety and privacy. The company highlighted their extensive privacy controls and urged individuals in sensitive roles to use these features to limit the sharing of their content appropriately.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *