
A recent investigation by Sky News has uncovered disturbing security concerns surrounding the publicly available data of over 1,300 Strava users, who have shared their workout routines from various U.S. military installations across the Middle East. This information, potentially accessible to adversaries, has raised concerns that it may have assisted Iran in tracking and targeting American personnel.
The released data provided a window into sensitive operational details, including exact routes, timings, daily routines, troop movements, and deployment patterns. Furthermore, the information revealed the presence of U.S. military personnel at bases that were not previously identified on public maps. Notably, many personnel utilized their real names while recording activities, despite the Pentagon having implemented restrictions on geolocation features for deployed personnel following similar security concerns in 2018.
A closer examination of the data revealed several notable patterns that appeared to correspond with subsequent Iranian attacks on U.S. military targets. Data collected before the war showed that Strava activity suggested U.S. personnel were withdrawing from certain locations, providing valuable insight into troop movements and potential vulnerabilities.
Specific incidents documented by Sky News include a U.S. Navy contractor who continued to log runs at an evacuated naval base in Bahrain before switching to record runs at the Crowne Plaza hotel. This location was struck six days later by Iranian forces, wounding two Pentagon employees. Another instance involved the Muwaffaq Al Salti Air Base in Jordan, where post-ceasefire activity indicated that 76% of recorded workouts began or ended near barracks on the eastern side of the base. On July 17, Iranian forces launched a strike on these very barracks, resulting in the deaths of three U.S. soldiers.
These findings underscore the importance of prioritizing the security and confidentiality of sensitive operational information, including recreational activities. The Pentagon will need to reassess the risks surrounding the use of location-tracking features and take measures to better safeguard deployed personnel’s personal data to prevent similar security breaches in the future.
