Strava records from US bases put soldiers at risk
Strava, you traitor.

Image by Getty/NurPhoto
- About 1,300 Strava users at US military bases in the Middle East shared workouts that exposed routines and locations.
- Sky News reported the data may have helped Iran track US personnel before attacks.
- Some users posted under real names, increasing risks that service members and contractors could be identified and targeted.
- Strava said users in sensitive jobs should use privacy controls, while US officials have warned about the app since 2018.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Despite Strava already being condemned as a threat to one’s security and privacy because of its public workout-sharing feature, not all of its users can give it up.
1,300 users from US military bases in the Middle East have been sharing their workouts on the platform, the information that could’ve been used by Iran to target American forces.
Strava is known for allowing users to share their runs, hikes, cycles, and other workouts with others. These posts also disclose their location and timing.
Thousands of such activities were recorded inside US military bases in the Middle East, according to Sky News.
The news site learned that such data revealed personnel's daily routines not only at military bases but also outside base areas, revealing the locations of bases not available on public maps.
What’s also concerning is that this information was shared by users under their real names and surnames, thereby making them potential targets.
According to Jonathan Hackett, special operations expert and author, Iran is “almost certainly” using Strava and similar apps to track US soldiers in the Middle East.
After analyzing data available on Strava, Sky News revealed that this information may have been used by Iran to target US soldiers.
Iran launched attacks on US bases across the Middle East on March 1st, 2026. One of these bases was based in Manama, Bahrain.
It was reported that most of the personnel were moved to residential buildings and hotels.
According to Sky News, one US Navy contractor’s Strava data showed him running near the base before the attack. A few days later, he was noticed running around the courtyard of the Crowne Plaza hotel.
After 6 days, Iran bombed the same hotel, suggesting that Strava was used to as a source to track US personnel.
The spokesperson for Strava told Sky News that the company takes privacy and security seriously, citing its Terms of Service, which “expect people working in sensitive professions to leverage the controls available to them and appropriately limit their content."
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Strava: a security risk since 2018
The risks Strava poses shouldn’t come as a surprise, as the Pentagon has banned soldiers from using Strava’s location-tracking features without permission when on duty since 2018.
The same year, Strava was called a “security risk” by the White House.
It has previously been reported that the fitness app may disclose the whereabouts of world leaders, such as the US President Donald Trump or former US President Joe Biden, because their security personnel decide to record their workouts for everyone to see.
Journalists also used Stava to locate a French aircraft carrier, after one of its sailors recorded runs on the deck and shared them on the fitness app.
Strava’s users have also been encouraged not to reveal too much, as the photos they share on the app may give away exactly where they tend to run and even lead to their home address being located.