An Unexpected Digital Loophole Reveals the Locations of U.S. Military Bases
U.S. and allied military personnel continue to share their location data and movements through the fitness-tracking application Strava, despite a ban imposed by the U.S. Department of War.
The Pentagon has prohibited the use of similar applications without prior authorization for nearly eight years, creating an intelligence loophole that could enable Iran and other hostile powers to identify military bases and track patterns of troop deployment across the Middle East.
In 2018, the Pentagon launched a comprehensive review after warning that data collected by the application could be used to map the daily “pattern of life” of military personnel. It subsequently tightened restrictions, although their enforcement has remained inconsistent.
According to an analysis conducted by the British network Sky News, more than 1,300 Strava users were identified as sharing workout activities originating from U.S. military bases in the region. Most of them use their real names, potentially making them vulnerable to tracking or targeting.
Special operations expert Jonathan Hackett said the continued leakage of location data reflected “poor compliance with the rules and a lack of awareness,” adding that it was likely that Iran had already exploited such information.
Joseph Gurney, a cyber researcher at the Royal United Services Institute, described the use of such open-source information for targeting operations as “entirely plausible,” noting that these data points can be combined with other information to support operational decision-making.
The Risk Extends Beyond Washington
The issue is not limited to U.S. forces. The investigation also identified British military personnel posting their fitness activities from RAF Akrotiri in Cyprus, which itself had been targeted by Iranian attacks.
Three users were also found to have recorded running routes inside Israel’s Dimona nuclear facility, which has repeatedly been considered a potential target for attacks.
In March, the French newspaper Le Monde revealed that members of the U.S. Secret Service and American security personnel had posted workouts on Strava that exposed aspects of their operational routines. A French officer had also revealed the location of an aircraft carrier deployed to the Middle East.
In the Netherlands, the newspaper de Volkskrant reported that the head of Dutch military intelligence, General Peter Reesink, had maintained a public Strava account for years. This allowed any follower to track his cycling and running routes and potentially deduce the location of his home and holiday destinations, in a blatant violation of Dutch Ministry of Defence guidelines.
Geospatial intelligence platform Mapulous has stressed that consumer technology is now generating data that can reach the level of military intelligence. It warned that “what begins as personal fitness tracking can, at scale, become a global surveillance network.” The case represents a classic example of open-source intelligence in which consumers’ everyday data can turn into a national security vulnerability.
In response to the investigation, Strava said it takes the safety and privacy of its users extremely seriously and provides extensive control tools. The company said it expects people working in sensitive professions to make appropriate use of these tools to restrict their content, ultimately leaving responsibility in the hands of individuals and the institutions concerned.









