US military personnel have kept posting public Strava workout data from bases across the Middle East months after Central Command imposed its strictest geolocation controls of the Iran war. A Stars and Stripes review found repeated activity that can map recurring routes, daily routines and gathering spots.
The findings land eight years after the same app’s global heatmap first exposed sensitive installations and forced a Pentagon-wide ban. Public posts still appear, some with photos of Army fitness gear and one shot inside a base gym.
What the Latest Reviews Turned Up
Stars and Stripes examined publicly shared Strava entries linked to installations in several CENTCOM countries. Users recorded workouts that outlined frequently used paths and exercise areas over time. Some posts went further than GPS tracks.
Photographs showed people in US Army physical fitness clothing and military-style equipment. One geotagged activity included an image taken inside a base exercise facility. The review followed a Sky News investigation that identified more than 1,300 Strava users sharing thousands of workouts from US bases in the region.
At Jordan’s Muwaffaq Salti Air Base, activity was posted on July 16, one day before an Iranian attack killed three US soldiers. Sky News reported roughly 12,000 workouts shared from inside that base since January. No evidence ties the strike directly to the app data.
Taken together, the open posts do more than mark a single run. Recurring paths sketch where people exercise, when those loops tend to happen, and which facilities draw regular traffic. A photo inside a gym adds a fixed indoor point to the outdoor tracks.
| Location or detail | Finding | Source timing |
|---|---|---|
| Multiple CENTCOM bases | Repeated public Strava routes and patterns | Stars and Stripes, Aug 2026 |
| Muwaffaq Salti Air Base, Jordan | Post on July 16; ~12,000 workouts since January | Sky News / Stripes |
| Bahrain (5th Fleet area) | Navy contractor tracked leaving base then to hotel later hit | Sky News via Task & Purpose |
| Photos with posts | Army PT clothing, equipment, interior gym shot | Stars and Stripes |
CENTCOM declined to say whether the posts complied with its rules, how restrictions are enforced, or whether anyone faced discipline. “We do not discuss force protection measures for operational security reasons,” the command said.
The 2018 Heatmap That Forced the First Ban
In January 2018 researchers and analysts noticed Strava’s global heatmap lit up remote outposts and base perimeters. Previously obscure sites in places such as Niger stood out because service members ran the fences and logged the loops. Layouts of air defenses and firebases became visible through dense activity lines.
The Defense Department responded that August. A memo from the Deputy Secretary of Defense imposed an immediate 2018 prohibition on geolocation features on both government-issued and personal devices, applications and services while personnel were in designated operational areas.
Combatant commanders could authorize exceptions only after a threat-based OPSEC survey. The memo warned that the capabilities could expose personal information, locations, routines and personnel numbers, raising risk to the joint force. Training requirements followed. The vulnerability was never theoretical.
What the heatmap made plain was simple geometry. Enough logged loops turn a fence line into a bright edge. Enough overlapping routes outline a firebase without anyone publishing a map. The 2018 ban tried to cut that signal at the source by treating geolocation features as a theater-wide hazard rather than a personal choice.
- January 2018: Strava heatmap analysis reveals sensitive military sites worldwide.
- August 2018: DOD memo bans geolocation features in operational areas.
- December 4, 2025: CENTCOM issues updated geolocation policy requiring disable of unnecessary functions, privacy reviews and limits on public sharing.
- February 28, 2026: On the eve of the Iran war, Adm. Brad Cooper raises force protection to the highest level with the command’s most restrictive geolocation controls.
- July-August 2026: Public Strava posts from bases continue; Sky News and Stars and Stripes publish findings.
That sequence shows successive layers of rules. It also shows the gap between writing a policy and changing what troops do with their own phones and watches after hours.
CENTCOM Layers That Still Left Public Trails
Personnel in the CENTCOM area of responsibility fall under the Dec. 4, 2025 policy. It requires them to disable unnecessary geolocation functionality, periodically review privacy settings and limit public sharing of information. The command told Sen. Ron Wyden those details in CENTCOM responses to Sen. Ron Wyden.
Restrictions tightened further as the Iran war opened. Cooper ordered the highest force protection level and what officials later described to Congress as the most restrictive geolocation controls across the theater. Some publicly accessible Strava activity associated with military locations was still recorded after those rules took effect.
This continues a pattern already covered in earlier reporting on persistent Strava base maps. Lawmakers have pressed the Pentagon for stronger safeguards. A bipartisan group warned in May that commercially available location data could support missile and drone attacks, surveillance and countersurveillance. CENTCOM had already received threat reports about adversaries exploiting such data to monitor US personnel.
Each layer added duties without erasing the earlier ones. The 2025 letter spelled out privacy reviews and limits on public sharing. The February wartime order raised the force protection ceiling. Open trails still appeared in the Stars and Stripes and Sky News reviews months later.
Phones, Smart Glasses and the Wider Device Problem
Strava is only one channel. Last month US officials considered tighter cellphone restrictions in the Middle East, including requiring some deployed personnel to surrender devices. The concern sharpened after the July attack on Muwaffaq Salti.
A US service member recorded troops sheltering inside a bunker using Meta smart glasses. The footage was later posted online. Adm. Brad Cooper warned that publicly shared images and videos could reveal where Iranian missiles had landed and the damage they caused. He cited open-source posts that let adversaries measure strike success in near real time.
- Fitness apps that log and share GPS routes by default or through loose privacy settings
- Smartphone videos and photos that show bunker locations, damage or personnel density after strikes
- Smart glasses and wearables that capture first-person footage during attacks
- Commercially sold location data aggregated from apps and carriers that can track movements without any single “share” button
The Financial Times earlier reported that telecommunications records and commercial location data had already been used to track US personnel and contractors across the region. Crowds on X treated the Strava stories as confirmation that consumer tech remains an open-source goldmine; many noted that privacy toggles feel optional until a base takes hits.
We do not discuss force protection measures for operational security reasons.
CENTCOM said that in response to questions about the Strava posts. Strava itself told Sky News it offers privacy controls and expects people in sensitive professions to use them. The company did not detail how many military users actually flip those switches.
The same phone that logs a morning run can also film a bunker or leave a commercial location trace after the workout ends. Policy that treats apps one by one leaves the rest of the device stack untouched. That is why officials weighed broader cellphone limits after the July strike, not only another fitness-app reminder.
Congress Keeps Pushing While Casualties Mount
Since the war began on Feb. 28, 18 service members have been killed and 696 wounded in action, according to Pentagon figures cited in coverage. Iranian strikes hit multiple sites, including bases in Bahrain and Kuwait covered in prior reporting on Iranian strikes on bases in Bahrain and Kuwait.
In one Sky News case, a Navy contractor at Manama left the base after it was targeted early in the war. Days later the hotel where the contractor was staying was also hit. Location trails from fitness data can follow people off the installation.
Fourteen members of Congress wrote the Pentagon in May calling for common-sense safeguards after CENTCOM acknowledged the commercial-data threat. The military has known the basic problem since 2018. Training exists. Policies escalate with the threat level. Public posts keep appearing anyway.
The casualty figures and the open trails sit in the same wartime window. Lawmakers framed commercial location data as a tool that could support missile and drone attacks. The contractor path from base to hotel showed how a trail can outlast a single installation and point to where people sleep after the gates close.
| Pressure point | What already happened |
|---|---|
| Wartime losses | 18 killed and 696 wounded since Feb. 28 |
| Congressional letter | 14 members pressed Pentagon in May for safeguards |
| Off-base follow-on | Navy contractor path from Manama base to hotel later hit |
| Command acknowledgment | CENTCOM had received threat reports on commercial data use |
Why the Same Vulnerability Keeps Returning
Personal devices travel with troops. Fitness culture rewards logging miles and sharing them. Default settings and social features on apps like Strava make public routes the path of least resistance. Enforcement inside a sprawling theater is hard to verify without constant device checks that themselves create friction.
The 2018 ban was clear on paper. The 2025 CENTCOM letter added specific duties. The February 2026 wartime peak was described as the most restrictive yet. Stars and Stripes and Sky News still found the trails. Adversaries do not need to hack anything; they can scrape what users leave open.
French forces hit a parallel problem when a sailor’s Strava posts revealed the location of the carrier Charles de Gaulle. The pattern is not uniquely American. It is what happens when consumer location tools meet military life without airtight habits or hardware controls.
- Rules stack from DOD memo to CENTCOM letter to wartime peak controls
- Devices and fitness habits travel with the force into every rotation
- Public reviews still recover routes, photos and off-base trails
- Allied cases such as the Charles de Gaulle show the same consumer-app clash
Open Trails Outlast Written Restrictions
The reviews did not claim that any single workout caused a strike. They showed that public data still sketched routines after the strictest controls of the war were already in force. That gap is the story the successive policies have not closed.
Scraping open posts requires no breach of a military network. The Sky News count of more than 1,300 users and the roughly 12,000 workouts from Muwaffaq Salti illustrate how volume alone can outline a place. Photos of PT gear and a gym interior add confirmation that the tracks belong to the force living there.
Cooper’s warning about shared strike imagery pointed at the same habit in a different format. Whether the file is a GPS route or a bunker clip, the exposure path runs through personal devices and public platforms. Commercial location aggregates widen that path further by working even when a user never taps share.
When Fitness Culture Collides With Force Protection
Logging miles is social as well as physical. Apps reward the share. Bases concentrate people who train on the same loops at predictable hours. Those incentives did not vanish when the Dec. 4, 2025 duties or the February wartime order arrived.
Training and memos tell personnel to disable functions and review privacy settings. The Stars and Stripes findings show that some accounts still left routes and images in public view. Strava’s answer to Sky News placed the burden on users in sensitive professions without saying how many of them apply the controls.
Until that collision is resolved in daily practice, open workouts will keep drawing the same kinds of maps. The French carrier case and the CENTCOM base posts are different fleets facing one consumer pattern.
Until enforcement closes the gap between written rules and daily phone use, the next review will likely find the same routes drawn across the same sand.
