Unites States and British military personnel have continued to use Strava to record and sync workouts at military bases in the Middle East despite potential security breaches.
According to a pair of separate reports that uncovered data from the Muwaffaq Al Salti Air Base in Azraq, Jordan, the popular fitness app was still being frequently accessed to upload runs, swims, bike ride and other workouts amid heightened tensions surround the Iran War.
Sky News first unveiled its findings last week on more than 1,300 user profiles, with many at several Middle East installations showing workouts on the platform before the start of the war on February 28. Hundreds of monthly runs were uploaded and displayed on the profiles with some of the activities displayed on locations that were not publicly available as established bases on mapping services like Google Maps.
And while there has been no confirmed direct link to Iran using Strava data to target U.S. military personnel, typical profiles are often associated with social media accounts while some workouts contain embedded photos and video that reveal the faces of soldiers and their colleagues and show visible landmarks of buildings and other facilities in addition to detailed maps.
Strava has settings that can hide profiles, originating and ending points of runs and bike rides, follower preferences that only allow certain users to see activities and a more direct privacy setting that does not allow anyone to see synced data.
Access to thousands of profiles could be used to establish a pattern of when soldiers and staff are likely to exercise or when a large group is congregated in a single area at the same time. As the conflict with Iran escalated through March, a noticeable drop in Strava activity was recorded in and around Muwaffaq Al Salti.
But after a two-week temporary cease fire between the U.S. and Iran was mediated by Pakistan, and later extended, Sky News reported noted a drastic change in behavior as Strava use resumed. Over 75 percent runs and other workouts took place in a specific region near the housing region on the eastern portion of the base.
It is unclear if United States Central Command ordered sweeping restrictions on Strava and other apps that use geolocation parameters as part of their core function from February through April. When contacted for a statement on its policy on Strava, CENTCOM said via email on Friday that it does not comment on “force protection measures for operational security reasons.”
In its own report that was also published last week, American military newspaper Stars and Stripes noted similar findings, with workout data showing people wearing Army fitness clothing in areas that were clearly identifiable as American installations in the Middle East.
On July 17, two service members were killed at the Muwaffaq Salti Air Base when ballistic missile and drone strike penetrated air defenses and wounded multiple other personnel and cause major damage to the facility which is also used by allied forces.
Defense officials have struggled to curb the use of fitness watches, workout apps and the sharing of map days since 2018 when widespread reports revealed that Strava’s heat map showed massive activity in sensitive and previously undisclosed military outposts in Afghanistan, Djibouti and Syria along with long-rumored bases in Nevada.
The Department of Defense would later restrict the use of any geolocation tools on both personal and government-issued devices while in sensitive locations.
Inside of Congress, a move to press defense officials on implementing tougher restrictions prompted a bipartisan statement from 14 members on May 28 directed at Kirsten A. Davies, DoD chief information officer. The letter explicitly references how information from a range of apps, not only fitness platforms, could be obtained by data brokers and sold to third parties and “exploited by adversaries to target attacks such as missiles, drones and roadside bombs, as well as for counterintelligence purposes.”
“Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes,” the letter read” “That foreign adversaries are still able to buy location data collected from the phones of U.S. personnel serving in military hotspots is a direct result of DoD leadership’s failure to prioritize this threat and implement common sense cyber defenses recommended by federal cybersecurity experts.”
Meanwhile, the Sky News report also revealed that British soldiers on active duty at RAF Akrotiri in Cyprus were also sharing massive amounts of data from their Strava accounts, with more then 12,000 from the base alone since early January and even a handful of run activities within Israel’s Dimona nuclear research facility.
Strava explained that the safety of anyone using and syncing data to its platform is a continued priority and was clear that it has distinct privacy controls in place to limit the disclosure of sensitive data.
“As stated in our Terms of Service, we expect people working in sensitive professions to leverage the controls available to them and appropriately limit their content,” the company said in a statement.







