Reports suggest Iran may have used data shared by Strava users at U.S. military bases in the Middle East to target American forces. In 2018, the Pentagon initiated a review regarding its personnel’s use of fitness apps like Strava, which track running, cycling, and swimming activities. The concern was that adversaries could use such information to discern a ‘pattern of life’ of personnel movements.
The Pentagon concluded these apps posed a security risk and restricted their use without prior approval. However, analysis by Sky News indicated that Strava data continues to be shared by hundreds of users at U.S. military bases, potentially compromising American personnel engaged against Iran.
Special operations expert Jonathan Hackett cited ‘lax enforcement and lack of awareness’ as reasons for the ongoing sharing of sensitive location data, which Iran might be using to monitor U.S. troop movements. Attempts were made by Newsweek to get comments from Strava and the Pentagon outside regular office hours.
“Lax enforcement and lack of awareness” contribute to data exposure, said Jonathan Hackett.
Sky News uncovered that over 1,300 Strava users had shared workout data from U.S. military bases, often using real names, which could make them targets for attacks or espionage. After joint U.S. and Israeli airstrikes on February 28, Iran struck back, targeting American bases, including a major naval base in Manama, Bahrain, on March 1, although it was evacuated in advance.
The report identified a Strava account belonging to a U.S. Navy contractor who recorded runs around this naval base until a week before hostilities began. Prior to the conflict, U.S. personnel at Jordan’s Muwaffaq Al Salti Air Base frequently posted runs on Strava. Activity resumed during an April ceasefire, although routes were adjusted. Tehran attacked the base on July 17, resulting in the death of three soldiers.
The issue is not exclusive to U.S. troops. British soldiers have shared data from RAF Akrotiri in Cyprus, a site targeted by Iran. Furthermore, Strava users tracked jogs inside Israel’s Dimona nuclear research center, a frequent target of Iranian actions.
In March, Le Monde reported that American security personnel, including Secret Service agents, posted their runs on Strava, potentially exposing operational details. One French officer even disclosed the location of an aircraft carrier directed towards the Middle East.
The #StravaLeaks investigation revealed that fitness data outlined sensitive military positions, including Israeli soldiers near Gaza and French President Emmanuel Macron’s security detail jogging near official sites. The geospatial data company Mapulus highlighted that consumer technology generates intelligence-grade data, which can evolve into a global surveillance network, describing it as a classic case of open-source intelligence (OSINT).
Dutch newspaper de Volkskrant reported Peter Reesink, head of the Netherlands’ military intelligence service (MIVD), maintained a public Strava account for years. This revealed his home address and holiday locations, defying military guidelines.
Strava indicated that it takes users’ safety and privacy seriously, offering extensive privacy controls. The company expects individuals in sensitive roles to use these controls and appropriately manage their content.

New & Notable Product Launches this Month
ByteDance and Motion Picture Association Strengthen AI Copyright Safeguards
Proposed Federal Tax to Address Data Center Electricity Consumption
Raytheon to Boost Tomahawk Missile Production Amid Stockpile Concerns
Robots Learn Disassembly: A New Skill for Industrial Use
Protecting Yourself from Fake Streaming Scams