Eight years after public location data on fitness apps such as Strava revealed U.S. troop locations and maps of bases, hundreds of service members in the Middle East are still sharing their information on them despite efforts by the military to prohibit that.
This week, Sky News published the results of an investigation showing that more than 1,300 separate users of the fitness tracker app Strava logged workouts at military sites in the U.S. Central Command area of responsibility, across multiple countries. Many of those locations were later targeted by Iran in some attacks that have been deadly.
The app, a popular fitness tracker that lets users log workouts, including real-time routes and locations. In 2018, features on Strava mapping global activity by users revealed a previously unknown American base in Niger, as well as locations of air defense positions and firebases in the Middle East. Specific layouts of some installations were also exposed, with troops running around the perimeters of those sites. In the wake of the exposures in 2018, the Department of Defense banned troops and civilian personnel from using geolocation features on their work or personal devices.
However, personnel continue to use the app, in both the lead up to the start of the Iran war and during it. The public data also revealed communal habits. At Muwaffaq Al Salti Air Base in Jordan troops regularly posted their runs. After a pause in March, they resumed in April but concentrated around barracks. The base’s housing was targeted in July when fighting restarted, killing three soldiers there.
Strava and CENTCOM did not immediately respond to requests for comment about the data. However, Strava told Sky News it offers privacy controls for users and expects “people working in sensitive professions to leverage the controls available to them.”
Since the start of the war, 18 service members have been killed. According to the Pentagon’s casualty data, 696 service members have been wounded in action, either during Operation Epic Fury or in “overseas operations,” the term the Department of Defense is using for hostilities on or after July 7.
In one specific instance, Sky News looked at the Strava data for a Navy contractor at Manama, Bahrain, where the U.S. 5th Fleet is headquartered. That contractor left the base after it was targeted in the opening hours of the war. A few days later, the hotel the contractor was staying at was also targeted.
In May, 14 members of Congress wrote to the Pentagon saying that foreign powers were using commercially available location data to track or target troops in the Middle East and called on the Department of Defense to enact safeguards to protect troops and their privacy.
According to the letter from Congress, a Dec. 4, 2025 guidance from CENTCOM told troops to disable geolocation services when not needed and regularly review each device’s privacy settings. The policy involves several escalating restrictions, the highest of which was put into effect on Feb. 28, 2026, when Operation Epic Fury began.
Last month, Reuters reported that CENTCOM’s commander had warned troops that Iran was using “reactions, photos, and footage from the cellphones of our troops” to measure successes of its strikes and help target personnel. Adm. Brad Cooper called for increased efforts to enforce operational security. Reuters reported that in some cases that could involve personnel handing in cell phones.
Location tracking apps have been a recurring problem not just for the U.S. military. This March, the French Navy’s flagship, the aircraft carrier Charles de Gaulle, had its exact location revealed mid-voyage after a sailor posted his runs on the app.
Loading comments…
Comments couldn’t be loaded. Please refresh the page.