The fitness app Strava is once again leaking sensitive military data, this time from U.S. bases across the Middle East, including locations that have recently been targeted by Iran. According to Sky News, U.S. service members stationed in the region have been logging their runs and workouts on the app, which exposes public activity data, revealing which bases are active and the movements of individual personnel.
This exposure comes at a particularly tense time, as Iran has either attacked or threatened U.S. facilities in the region in recent months, including Al Udeid Air Base in Qatar. The data showing which sites are occupied and how personnel move around them provides exactly the kind of pattern-of-life information that a hostile actor seeks. Sky News reports that this activity remains visible despite years of warnings about the app’s privacy issues.
This problem is not new. Strava’s global heatmap first revealed the layout of remote U.S. bases back in 2018, and the company pledged at that time to strengthen privacy settings and collaborate with defense officials. Nearly a decade later, the same behavior persists.
Source: Sky News
So What
This breach, unlike the 2018 leak, does not specifically identify highly sensitive individual locations. However, it still reveals which military bases are active in the region and the areas that are under occupation, providing some operational value to adversaries, although likely limited. A key concern is that this is a known, avoidable error that the military should have addressed years ago. The greater risk appears to be to individual troops; hostile actors could potentially use Strava activity data to trace a service member back home and target their family. This situation involves low sophistication but carries significant potential risks.
Follow us to join the intelligence community!
