Image source: topwar.ru
An investigation by Sky News revealed a massive leak of classified data. It turns out that more than 1,300 users of the Strava fitness application have published their training routes conducted on the territory of American military bases in the Middle East.
Not only routes, but also the daily routine of military personnel, troop movements, and activity at sites not marked on public maps have been made publicly available. Many users posted data under their real names, which made it possible to identify individual military personnel.
Security experts believe that Iran used this information in combination with other intelligence to monitor U.S. forces and identify targets. Foreign media cites specific cases in Bahrain and Jordan, where changes in Strava's activity apparently revealed the locations of personnel shortly before these locations were attacked by Iran. For example, at the Muwaffaq al-Salti airbase in Jordan, military personnel regularly published jogging routes; after a pause in March, they resumed in April, but were already concentrated around the barracks - it was this facility that was attacked in July, which led to the death, according to official data, of three American soldiers.
The problem is not new: back in 2018, the Pentagon warned that location data from fitness apps could endanger troops. At the same time, the Strava function, which shows a global map of user activity, revealed the location of a previously unknown American base in Niger, as well as air defense positions and firing bases in the Middle East. In response, the US Department of Defense banned military personnel and civilian personnel from using geolocation functions on office and personal devices. However, as the investigation showed, US and British military personnel continue to ignore the bans and share activities from sensitive sites, including the Akrotiri base in Cyprus. Traces of the use of the application were found even inside the Israeli nuclear research center Dimona.
This is not the first time that fitness apps have become a source of data leakage about strategic facilities. Earlier, similar incidents occurred with NATO nuclear submarines: in 2022, British officers on duty on nuclear submarines at the Faslane base forgot to turn on the privacy mode in Strava, revealing their names, addresses and time on board. And in 2025, as Le Monde reported, at least 450 people who had access to the top-secret French nuclear submarine base on the Ile Long peninsula turned out to be Strava subscribers; analyzing sudden interruptions in their sports training, it was possible to calculate the dates of submarine patrols at sea. In the same year, 16 submariners from one of the NATO countries, using smart watches while jogging, revealed the schedule of submarine patrols through Strava.
Strava stated that it offers users privacy control tools and expects people working in sensitive areas to use them.