Skip to content

Cart

Your cart is empty

Article: Strava Data Exposes U.S. Base Routines

A service member looks at a fitness app on a smartphone at the Pentagon on Feb. 1, 2018, as the Defense Department reviewed security risks involving GPS-enabled fitness applications after Strava data exposed activity at military installations around the

Strava Data Exposes U.S. Base Routines

PHOTO CAPTION: A service member looks at a fitness app on a smartphone at the Pentagon on Feb. 1, 2018, as the Defense Department reviewed security risks involving GPS-enabled fitness applications after Strava data exposed activity at military installations around the world.

More than 1,300 Strava users have publicly shared thousands of workouts from U.S. military installations across the Middle East, exposing recurring routes, exercise locations and patterns of daily activity despite years of Pentagon warnings about the security risks posed by fitness-tracking apps.

A Sky News investigation published Aug. 12 identified activity at U.S. military sites across the region, including bases that were later targeted by Iran. Stars and Stripes separately reviewed publicly accessible Strava activity and found recurring routes and other location information at bases in several countries in U.S. Central Command’s area of responsibility.

The information can reveal more than where someone went for a run. Repeated workouts can show where personnel gather, where they live, how they move around an installation and how those patterns change over time.

Some users also posted under their real names, potentially linking individual identities to specific military locations. Stars and Stripes found that some activities included photographs showing military clothing, equipment or the interior of fitness areas.

At Muwaffaq Salti Air Base in Jordan, publicly visible Strava activity was recorded as recently as July 16, one day before an Iranian attack on the installation killed three U.S. soldiers, according to Stars and Stripes.

However, neither the Sky News investigation nor subsequent reporting established that Iran used Strava data to select that target or any other U.S. military location. The publicly available information could aid surveillance or targeting, but any direct connection to specific attacks remains unproven.

The Pentagon has known about the risk for years.

In 2018, the Defense Department prohibited personnel from using geolocation features on government-issued and personal devices while in designated operational areas after Strava’s global heat map revealed activity around military installations and other sensitive locations.

The Pentagon warned at the time that smartphones, smartwatches and fitness trackers could expose personnel locations, routines and troop concentrations, creating unintended security risks for both individuals and military operations.

CENTCOM has since adopted additional restrictions.

The command told lawmakers that a Dec. 4, 2025 policy required personnel to disable unnecessary geolocation functions, regularly review privacy settings and limit public sharing. CENTCOM imposed its most restrictive theater-wide geolocation controls when the war with Iran began on Feb. 28, 2026.

Despite those controls, Stars and Stripes found publicly accessible activity from military locations recorded after the stricter rules took effect.

CENTCOM declined to explain whether the publicly visible activity complied with its policy, how the restrictions are enforced or whether personnel have been disciplined. The command said it does not discuss force-protection measures for operational-security reasons.

The issue extends beyond Strava itself.

CENTCOM told Congress earlier this year that it had received threat reporting about adversaries exploiting commercially available location information to monitor or target U.S. personnel in the region. A bipartisan group of lawmakers has pushed the Pentagon for additional safeguards governing how location data generated by service members and their devices can be collected, sold or exposed.

Strava told Sky News that the company provides privacy controls and expects people working in sensitive professions to use the protections available to them.

The latest findings show that nearly eight years after fitness-app data first triggered Pentagon-wide security concerns, publicly shared workouts are still revealing details about where U.S. personnel operate and how they move.

(Source: OAF Nation)

MORE FROM THE

OAF NATION NEWSROOM

FILE PHOTO: Russian President Vladimir Putin and North Korean leader Kim Jong Un attend a meeting in Beijing, China September 3, 2025. Sputnik/Alexander Kazakov/Pool via REUTERS /File Photo

Russia, North Korea Plan New World Order

Lavrov says Russia, North Korea fighting for 'new, righteous' world order

Read more
An Army ROTC cadet fires an M4 during Advanced Camp at Fort Knox, Kentucky, June 11, 2026. The Army recently rescinded a planned minimum standardized-test requirement for incoming ROTC cadets while the proposal undergoes further review.

Army Rescinds ROTC Test Requirement

Army Scraps Planned SAT, ACT or ASVAB Minimum for ROTC Cadets

Read more