Marines in a row performing push-ups on a ship’s flight deck.

Marines perform push-ups on the flight deck of the amphibious assault ship USS Makin Island during a physical training session marking the Marine Corps' birthday, Nov. 10, 2016. Fitness-tracking apps like Strava have repeatedly been shown to expose the movements and routines of U.S. troops at bases overseas, a vulnerability lawmakers say the Pentagon still hasn't fully addressed despite restricting geolocation use in operational areas nearly a decade ago. (Brandon Maldonado/U.S. Marine Corps)

By SHATYRA COX 
STARS AND STRIPES

U.S. personnel using fitness-tracking apps are publicly sharing location data that can reveal details about life at military bases across the Middle East, months after U.S. Central Command imposed restrictive geolocation controls across the theater.

A Stars and Stripes review found that users of the Strava app repeatedly recorded and publicly shared details of their workouts at bases in several countries in the CENTCOM area of responsibility.

The details included recurring routes and exercise locations that revealed patterns in users’ movements over time.

Some included more than just time and location data, such as photographs of people in Army physical fitness clothing or military-style equipment. One activity geotagged to a military location included a photograph from inside a fitness area.

The independent findings follow a Sky News investigation published Wednesday that identified more than 1,300 Strava users sharing thousands of workouts from U.S. military installations across the Middle East.

CENTCOM declined to say whether the publicly available Strava activity complies with its geolocation rules, how those restrictions are enforced or whether personnel have been disciplined for violations.

“We do not discuss force protection measures for operational security reasons,” the command said Thursday in an email.

The publicly available fitness data could reveal concentrations of personnel and aspects of their daily routines at sites later targeted by Iran, Sky News reported. But it did not establish that Iran had used Strava data to select targets.

At Muwaffaq Salti Air Base in Jordan, publicly accessible Strava activity was posted on July 16, one day before an Iranian attack on the installation killed three U.S. soldiers.

A group of sailors jogging together on a ship’s flight deck.

Sailors run on the flight deck of the amphibious assault ship USS Iwo Jima during a group workout in the U.S. 5th Fleet area of operations, April 5, 2018. Fitness-tracking apps like Strava have repeatedly been shown to expose the movements and routines of U.S. troops at bases overseas, a vulnerability lawmakers say the Pentagon still hasn't fully addressed despite restricting geolocation use in operational areas nearly a decade ago. (Dary M. Patten/U.S. Navy)

The Defense Department has been grappling with the risks posed by fitness trackers since at least 2018, when researchers discovered that exercise data on Strava’s global heat map could reveal activity at military installations and other sensitive locations.

DOD responded by prohibiting personnel from using geolocation features on government-issued and personal devices, applications and services while in designated operational areas.

It warned at the time that geolocation capabilities on devices such as smartphones, smartwatches and fitness trackers could pose risks to U.S. personnel or operations by exposing personal information, location, routines and personnel numbers.

More recently, officials have raised concerns about the passive collection of geolocation data and other information on such devices or their applications. The data are then sold in aggregate, often to advertisers.

CENTCOM told Congress this spring that it had received threat reports concerning adversaries’ exploitation of commercially available location data to target or monitor U.S. personnel in theater.

The command had warned military force protection personnel across the region about the threat, it told lawmakers.

Personnel in CENTCOM’s area of responsibility are also subject to a geolocation policy issued Dec. 4, 2025, requiring them to disable unnecessary geolocation functionality, periodically review privacy settings and limit public sharing of information, the command told Sen. Ron Wyden, D-Ore.

The restrictions became more stringent earlier this year.

On the eve of the Feb. 28 launch of the Iran war, CENTCOM commander Adm. Brad Cooper ordered the command to the highest force protection level, imposing what it later told Congress were its “most restrictive geolocation controls across the theater.”

Some publicly accessible Strava activity associated with military locations was recorded after those restrictions took effect.

Sailors doing squats together on a ship’s flight deck.

Sailors take part in a high-intensity interval training class on the flight deck of the amphibious assault ship USS Makin Island, Feb. 19, 2023. Fitness-tracking apps like Strava have repeatedly been shown to expose the movements and routines of U.S. troops at bases overseas, a vulnerability lawmakers say the Pentagon still hasn't fully addressed despite restricting geolocation use in operational areas nearly a decade ago. (Michael Gomez/U.S. Navy)

A bipartisan group of lawmakers has continued to press the Pentagon to adopt additional protections after CENTCOM acknowledged that adversaries were exploiting commercially available location data.

In May, the legislators warned that such information could be used for missile and drone attacks, surveillance and countersurveillance.

In response to questions this week about the Strava data, CENTCOM did not provide a copy of Command Policy Letter Number 25-10, United States Central Command Geolocation Policy, upon request. Officials had not responded to additional questions as of Friday.

Featured on Instagram