
New reporting shows U.S. troops are still revealing base activity in the Middle East through Strava workouts, eight years after Pentagon warnings and a formal clampdown.
Story Snapshot
- The Pentagon banned geolocation features for deployed troops in 2018, citing “significant risk.”
- Recent reports say hundreds of users still share workouts from U.S. bases in the Middle East.
- Public maps can expose patrol routes, shift patterns, and base perimeters to anyone online.
- Strava says data are aggregated and users control privacy, but sensitive activity still surfaces.
What is happening and why it matters now
Reporters and analysts are again finding public Strava runs tied to U.S. sites in the Middle East, despite years of warnings. In 2018, the Department of Defense barred geolocation features for deployed personnel after its mapping showed base activity and troop routines. Military Times-style outlets and regional coverage now describe ongoing sharing from areas under United States Central Command. This matters because public patterns can expose guard rotations, living areas, and routes to adversaries scanning open sources.
The core risk is simple. When many people post public workouts near a small site, the traces outline roads, walls, and daily rhythms. In 2018, experts showed how bright clusters on Strava’s “heat map” aligned with known or unlisted military facilities in conflict zones. That same mapping logic still applies. Even without names, the repeated paths draw a picture of where people are and when they move. That picture is free to anyone with a browser.
What the Pentagon did and where gaps remain
After the first flare-up, Pentagon leaders announced a review and then restricted geolocation features for deployed personnel and sensitive sites. The policy drew a clear line: do not use location sharing in war zones and high-risk areas. But policies often lose to habits and defaults. Troops change units, new phones ship, and app settings reset. Some service members still leave workouts public, either by choice or by confusion, which keeps creating fresh data points.
Operational security training addresses phones, watches, and apps. Yet personal devices remain part of daily life on base and on rest days. This is a human factors problem as much as a tech problem. People want to track miles, beat goals, and connect with friends. Those normal choices can add up to a precise map. That gap between rules and routine is where open-source data keeps leaking.
What Strava says and what users can control
Strava says its heat map is aggregated and anonymized, with tools to hide workouts and set privacy zones. The company says it works with governments on sensitive areas and that users can opt out of heat mapping. Those steps can help. But they depend on each person using the settings the right way, every time. When users leave the defaults on, or forget after a move or update, public traces return and rebuild the bigger picture.
Over 1,300 U.S. military personnel inadvertently revealed sensitive base locations in the Middle East through fitness app Strava, which tracks workout routes. Iran reportedly exploited this data to monitor and target U.S. #Strava
— WW3 Watchtower (@WW3Watchtower) August 16, 2026
Strava also told reporters in 2018 that it did not monitor people without consent and had no evidence of hacking or direct harm tied to its maps. That statement addressed one fear but not the larger concern. Adversaries do not need to hack a server if users post patterns in plain sight. The absence of a known attack chain does not remove the risk of giving away routines in active conflict zones.
What this shows about government, tech, and trust
The renewed leaks highlight a familiar breakdown. A major defense rule exists on paper, but real life behavior and platform design still expose Americans to avoidable risk. Conservatives see this as proof that agencies cannot police basic security while focusing on culture wars and bureaucracy. Liberals see it as proof that profit-driven tech puts engagement over safety. Both sides see a system that warns, “Do not share,” yet cannot stop the sharing.
Washington can tighten guidance again, but enforcement will be hard without simpler defaults. Clear base-level blocks for geolocation, device settings locked by command, and automatic privacy for known sensitive grids could cut exposure. Strava can expand protected zones and make private the default near conflict sites. Until leaders and companies align on those steps, open data will keep sketching our footprints across the sand.
Sources:
redstate.com, npr.org, cnn.com, taskandpurpose.com, x.com, bbc.com, engadget.com


























