Eight years after fitness applications exposed American troop locations and sensitive base layouts, service members are still broadcasting location data across the Middle East.
Despite military restrictions and repeated operational security warnings, hundreds of personnel continue leaving digital breadcrumbs that hostile governments can study.
A Sky News investigation found that more than 1,300 Strava users recorded workouts at military sites within the United States Central Command area.
Those activities stretched across several countries, and many of the identified locations were later struck by Iran, including attacks that killed American troops.
Here's What They're Not Telling You About Your Retirement
Strava allows users to record workouts, routes, distances, and locations, sometimes in real time. That may be convenient for tracking a morning run, but around an active military installation it can also hand adversaries a remarkably detailed picture of daily life.
The danger has been public knowledge since 2018, when Strava activity maps revealed a previously undisclosed American base in Niger.
The same data exposed air defense positions, firebases, installation layouts, and predictable routes created by troops running around base perimeters.
Following those revelations, the Department of War prohibited troops and civilian personnel from using geolocation features on work and personal devices in operational areas.
This Could Be the Most Important Video Gun Owners Watch All Year
Yet personnel continued logging workouts before Operation Epic Fury began and while combat operations against Iran were underway.
At Muwaffaq Salti Air Base in Jordan, troops regularly posted running routes through Strava.
Activity paused in March, then resumed in April with routes concentrated near barracks, effectively highlighting where American personnel were housed.
That housing area was targeted when fighting resumed in July, killing three soldiers.
The available reporting does not establish that Strava data directed the strike, but publicly displaying troop patterns near a target under active threat is an operational security failure that requires no elaborate explanation.
Strava and CENTCOM did not immediately answer requests for comment regarding the exposed information. Strava told Sky News that it provides privacy controls and expects “people working in sensitive professions to leverage the controls available to them.”
That response places responsibility squarely on users who knowingly work around sensitive facilities.
Privacy settings are not much of a safeguard when personnel ignore them, and a written policy is little more than paper armor when commanders fail to ensure compliance.
Since the war began, 18 American service members have been killed. Pentagon casualty figures also show 696 troops wounded in action during Operation Epic Fury or in “overseas operations,” the War Department term for hostilities occurring on or after July 7.
Sky News also examined Strava information associated with a Navy contractor in Manama, Bahrain, home to the United States Fifth Fleet headquarters.
The contractor departed the base after it was attacked during the opening hours of the war, but days later the hotel where the contractor was staying was also targeted.
Again, the reporting does not prove the fitness data caused either strike. Still, an application that can trace a person from a military headquarters to temporary lodging creates exactly the kind of pattern enemy intelligence services are paid to exploit.
In May, 14 members of Congress warned the Pentagon that foreign powers were using commercially available location information to track or target American troops in the Middle East.
The lawmakers called on the Department of War to establish stronger safeguards protecting service members and their privacy.
Their letter cited CENTCOM guidance issued on Dec. 4, 2025, directing troops to disable unnecessary geolocation services and regularly review device privacy settings.
The policy included escalating restrictions, with the highest level taking effect on Feb. 28, 2026, when Operation Epic Fury began.
CENTCOM commander Adm. Brad Cooper later warned that Iran was studying “reactions, photos, and footage from the cellphones of our troops” to evaluate strike results and improve targeting. Reuters reported that tighter enforcement could include requiring personnel to surrender their phones in some circumstances.
This is not exclusively an American problem, either.
In March, a sailor aboard the French aircraft carrier Charles de Gaulle revealed the flagship’s precise location during a voyage by posting running activity through Strava.
The recurring exposure shows that issuing another memo will not solve a discipline problem. Troops operating within reach of Iranian missiles should not be advertising barracks, routes, schedules, or relocation patterns to anyone with an application and an internet connection.
America’s enemies do not need spies inside every installation when careless users publish usable intelligence for free.
The War Department and commanders in the field must treat unauthorized location sharing as the serious security breach it is, before another workout map becomes part of an enemy targeting folder.
Join the Discussion
COMMENTS POLICY: We have no tolerance for messages of violence, racism, vulgarity, obscenity or other such discourteous behavior. Thank you for contributing to a respectful and useful online dialogue.