WASHINGTON — Publicly available workout data from fitness-tracking app Strava is raising renewed security concerns after an investigation found that military personnel have continued to publish exercise routes from sensitive installations and deployment areas.
A Sky News investigation published on August 12 found more than 1,300 Strava users sharing workouts from or near U.S. military bases in the Middle East. Many of the accounts used real names, while the publicly visible routes could reveal where personnel were exercising, their routines and changes in activity around military facilities. Security experts cited by Sky News said such information could potentially be combined with other intelligence to track U.S. personnel and movements.
Strava Data Linked to U.S. Bases in Middle East
The investigation examined activity around several U.S. military facilities during the conflict with Iran.
At the main U.S. naval base in Manama, Bahrain, Sky News identified a Strava account linked to a U.S. Navy contractor who had regularly recorded runs around the base. The activity stopped for two days after personnel began leaving the facility. The account then showed runs around the courtyard of the Crowne Plaza hotel, where some personnel had reportedly relocated.
Six days later, Iran attacked the hotel. Two U.S. Department of Defense employees were reportedly wounded, according to the Sky News investigation. However, the investigation did not establish that Strava data was specifically used by Iran to select the hotel as a target.
A similar pattern was identified at Jordan's Muwaffaq Al Salti Air Base. Before the conflict, U.S. personnel had regularly published runs across the installation. Activity resumed in April after a pause in March, but Sky News found that the routes had become concentrated in one area.
According to the investigation, 76% of the later activities began or ended near barracks on the eastern side of the base. Iran attacked those barracks on July 17, killing three U.S. soldiers. Sky News also found publicly accessible Strava activity at the base on July 16, one day before the attack.
Sky News reported that the data can provide what intelligence analysts describe as a "pattern of life" by combining large numbers of individual activities. Such information can reveal regular movements, concentrations of personnel and changes in deployment patterns.
British and Israeli Locations Also Exposed
The investigation found that the problem extends beyond U.S. forces.
Sky News identified about 12,000 workouts recorded inside RAF Akrotiri in Cyprus since January 2026. The investigation also identified British personnel sharing activities from the base and tracked some profiles across deployments in the Middle East.
Separate reporting in April found that 519 British military personnel, contractors and family members had publicly recorded Strava activities at sensitive UK military sites. The locations included Faslane, home to Britain's nuclear deterrent, and Northwood, the headquarters of the UK's military command.
Sky News also identified three Strava users recording runs inside Israel's Dimona nuclear research facility. The facility is considered highly sensitive and has previously been a target of Iranian attacks.
French Military Has Faced Similar Problems
French military operations have also been affected by publicly shared fitness data.
In March 2026, a French Navy officer using Strava publicly uploaded a workout recorded during the deployment of the aircraft carrier Charles de Gaulle. The data allowed the ship's location in the Mediterranean, northwest of Cyprus, to be identified. Le Monde matched the Strava activity with satellite imagery and located the carrier and its escort group.
The French military acknowledged that publishing the workout did not comply with existing operational security instructions and said appropriate measures would be taken.
Earlier investigations also identified Strava activity connected to France's Île Longue naval base, where the country's nuclear-armed ballistic-missile submarines are based. Analysis of activity gaps was reported to have provided indications of submarine patrol periods.
Pentagon Has Warned About Fitness Tracker Risks Since 2018
The security problem is not new. In 2018, a Strava global activity map exposed patterns around military facilities, including a previously undisclosed U.S. installation in Niger.
The Pentagon subsequently prohibited Department of Defense personnel from using geolocation features on government and personal devices, applications and services in designated operational areas, unless authorized under specified conditions.
The Defense Department had already warned in January 2018 that fitness trackers could reveal the locations and routines of military personnel. Officials advised personnel to use the strictest privacy settings and warned that publicly available fitness data could expose military locations and potentially assist targeting.
Despite those restrictions and repeated warnings, publicly accessible fitness activity has continued to appear at sensitive military locations.
Public Data Can Reveal More Than a Single Location
The main security concern is not limited to identifying where one person is exercising.
When multiple users repeatedly publish GPS-based workouts, the information can show where personnel are concentrated, their regular routines and changes in activity over time. It can also provide indications of movements between military facilities and changes in the number of people present at particular locations.
Sky News said its investigation did not establish that Iran specifically used Strava information to select the targets described in its report. The available data nevertheless demonstrates how publicly shared commercial location information can potentially be combined with other intelligence sources.
Strava said it takes user safety and privacy seriously and provides privacy controls. The company also said it expects people working in sensitive professions to use those controls and appropriately limit what they publish.
The continued appearance of military activity on public fitness platforms therefore remains an operational-security concern, particularly when individual workout records can be combined to reveal movements and patterns around military facilities.
——— End of Article ———