US military fitness training
Credit: Wikimedia Commons (CC)

Eight years after the United States military first warned that commercial fitness app data could expose troop movements and endanger personnel, the problem remains unsolved. A new investigation by Sky News found that more than 1,300 Strava users have shared workout data from sensitive U.S. military installations across the Middle East — revealing patrol routes, daily routines, troop movements, and activity at bases that do not appear on any public map.

Many of those users posted under their real names.

The data is not hidden. It is publicly accessible to anyone with a Strava account and the knowledge to look for it. Security analysts told Sky News that Iran could have cross-referenced this fitness tracking information with other intelligence streams to monitor American forces in real time and identify potential targets for attack. Sky News further identified instances from Bahrain and Jordan where real time military operations relocation of personnel through changes in posted Strava workouts were conducted before those locations were then attacked by the Iran-aligned forces.

These concerns have been known for some time. The Pentagon issued some very clear statements on the use of fitness apps in 2018, after Strava's workouts were posted on a military fitness tracking heat map. New policies were put in place and new guidelines were issued.

As of 2026, workouts and runs from classified bases are still posted on Strava — including RAF Akrotiri in Cyprus. Sky News also documented posted workouts from Strava from the Dimona nuclear research facility in Israel.

The real question is, why can't the agency charged with the protection of our U.S. service members implement a basic digital discipline policy when corporate security teams have likely put similar policies into practice years ago?

Personal data broadcasting is a serious concern and threat to U.S. service members. Potential adversaries need not hack into classified networks, as personnel are broadcasting personally identifiable information by voluntarily posting to public leaderboards of fitness apps. China, Russia, and Iran have been employing sophisticated open source intelligence collection operations for years, and are no doubt correlating this data.

The inability to contain service members from posting to fitness apps does not demonstrate a technology gap in the Pentagon. Strava, like most apps, has configurable privacy settings. If mandated, personal devices could be prohibited from use in sensitive areas. The failure is cultural, and is a combination of lax oversight, digital discipline, and a workforce that has not taken Digital Operational Security (DOPSEC) as seriously as physical protections.

With video images of Iranian strikes on American facilities routinely coming out of the Middle East during the Iran war, it is obvious the American military is failing at basic operational security.

This leadership gap is a clear and present threat to the safety and lives of our service members, and should be corrected immediately.

'NO AD' subscription for CDM! Sign up here and support real investigative journalism and help save the republic!