Eight years after the United States military first warned that commercial fitness app data could expose troop movements and endanger personnel, the problem remains unsolved. A new investigation by Sky News found that more than 1,300 Strava users have shared workout data from sensitive U.S. military installations across the Middle East — revealing patrol routes, daily routines, troop movements, and activity at bases that do not appear on any public map.
Many of those users posted under their real names.
The data is not hidden. It is publicly accessible to anyone with a Strava account and the knowledge to look for it. Security analysts told Sky News that Iran could have cross-referenced this fitness tracking information with other intelligence streams to monitor American forces in real time and identify potential targets for attack. Sky News further identified instances from Bahrain and Jordan where real time military operations relocation of personnel through changes in posted Strava workouts were conducted before those locations were then attacked by the Iran-aligned forces.
These concerns have been known for some time. The Pentagon issued some very clear statements on the use of fitness apps in 2018, after Strava’s workouts were posted on a military fitness tracking heat map. New policies were put in place and new guidelines were issued.
As of 2026, workouts and runs from classified bases are still posted on Strava — including RAF Akrotiri in Cyprus. Sky News also documented posted workouts from Strava from the Dimona nuclear research facility in Israel.
The real question is, why can’t the agency charged with the protection of our U.S. service members implement a basic digital discipline policy when corporate security teams have likely put similar policies into practice years ago?