U.S. personnel at Middle East bases kept posting public Strava workouts that map recurring routes, barracks clusters and daily patterns months after Central Command imposed its strictest geolocation rules. A Stars and Stripes review and a Sky News investigation together identified more than 1,300 users sharing thousands of activities from installations across the CENTCOM area, some after the highest force-protection order took effect.
The data includes photographs of Army fitness clothing and interior gym shots. At one Jordanian air base, activity appeared the day before an Iranian strike killed three American soldiers.
What the Public Workouts Still Show
Stars and Stripes found recurring routes and exercise spots that outlined movement patterns over time at bases in several CENTCOM countries. Some posts went beyond GPS tracks. Users uploaded images of people in physical training gear or military-style kit. One geotagged activity included a photo from inside a fitness facility.
Sky News reported the same core finding: more than 1,300 Strava users sharing thousands of workouts from U.S. military installations. Many posted under real names. That turns anonymous heat into identifiable pattern-of-life data. Concentrations of personnel and daily rhythms become visible at sites Iran later struck. The outlets did not prove Iran selected targets from the app.
- 1,300+ users with public base-linked activities
- Thousands of individual workouts logged inside installations
- Real names attached to many profiles, raising individual targeting risk
- Post-restriction activity still appearing after FPCON Delta
Crowd discussion on X treated the episode as an eight-year rerun. Analysts noted the greater danger now sits with named individuals rather than crude base outlines alone. Low-sophistication open-source collection remains available because users keep the default public settings.
Interior photos and kit images add a layer the early heat maps lacked. A single geotagged gym shot can confirm that a named profile belongs to someone living and training on that installation, not a passerby. Aggregated over weeks, the same feeds sketch who clusters where and when those clusters shift.
How the Rules Tightened Then Failed to Stick
The Defense Department first confronted fitness-tracker exposure in 2018 after Strava’s global heat map lit up remote bases and patrol routes. Officials banned geolocation features in operational areas. CENTCOM later layered its own orders.
- August 3, 2018, Deputy Defense Secretary memo prohibits DoD personnel from using geolocation features on government and personal devices, apps and services while in designated operational areas, citing risks to personal information, locations, routines and personnel numbers.
- December 4, 2025, CENTCOM Command Policy Letter Number 25-10 requires personnel to disable unnecessary geolocation functions, periodically review privacy settings and limit public sharing.
- February 28, 2026, On the eve of the Iran conflict, Adm. Brad Cooper ordered FPCON Delta, the highest level, imposing what CENTCOM later called its most restrictive geolocation controls across the theater.
- Spring 2026, CENTCOM told Congress it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil U.S. personnel and had warned force-protection officers.
The 2018 prohibition on geolocation features in operational areas remains the foundational order. Yet some publicly visible Strava activity associated with military sites was recorded after the 2026 restrictions took hold. CENTCOM declined to say whether the posts complied with policy, how rules are enforced, or whether anyone faced discipline. “We do not discuss force protection measures for operational security reasons,” the command said.
Each step narrowed written permission. Delta was framed as the tightest theater-wide standard yet. Public feeds still filled in after that order, which is the gap investigators keep measuring against the paper trail.
Two Bases, Clear Patterns, Later Strikes
Specific cases illustrate the gap between order and practice. At Muwaffaq Salti Air Base in Jordan, publicly accessible Strava activity was posted on July 16. The next day an Iranian attack on the installation killed three U.S. soldiers. Reporting around the Sky News work described a shift: before the February war start, runs spread across the facility; after an April ceasefire window, roughly 76 percent of logged runs began or ended at barracks in the eastern corner. Iran struck those barracks.
| Location | Key Strava Detail | Related Event |
|---|---|---|
| Muwaffaq Salti Air Base, Jordan | Activity posted July 16; later concentration of runs at eastern barracks | Iranian strike July 17 killed three U.S. soldiers |
| Naval facility area, Manama, Bahrain | U.S. Navy contractor logged runs near base, then courtyard loops at Crowne Plaza hotel after relocation | Hotel hit in March 1 Iranian strikes; two Pentagon employees reported injured |
| Multiple CENTCOM sites | Recurring routes, real-name profiles, interior photos | Bases later targeted in the wider Iran conflict |
In Bahrain, most personnel had moved off the main base into residential buildings and hotels ahead of hostilities. One contractor’s public track shifted from the installation to the Crowne Plaza courtyard. Six days later that hotel was struck. Security experts called the overall data set a clear risk even without proof of direct Iranian use of the app.
The Jordan sequence compresses the problem into two calendar days: a public post, then a lethal strike on the same installation. The Bahrain sequence stretches longer, following a relocation that the track itself advertised. In both places the feeds did not need to invent targets. They refined where people already were.
Experts and Lawmakers See an Unfixed Threat
Joseph Jarnecki, a research fellow at the Royal United Services Institute, said it was “completely plausible” that Iran monitored American personnel movements via Strava. Virpratap Vikram Singh of the International Institute for Strategic Studies called the data “definitely a security threat,” noting that unlike bulk commercial location sets it often ties to full names and social profiles. That detail helps confirm the right person or seniority level.
Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes.
That language comes from a May bipartisan group of lawmakers led by Sen. Ron Wyden and Rep. Pat Harrigan. They pressed the Pentagon after CENTCOM acknowledged adversary use of commercial location data. The bipartisan letter urging DoD commercial data safeguards listed missile, drone and countersurveillance risks and demanded basic steps such as disabling advertising IDs.
- Disable smartphone advertising IDs on government devices (still incomplete at the time of CENTCOM’s spring answers)
- Replace tracking-heavy browsers with privacy-focused alternatives
- Enforce consistent geolocation disablement that actually works on commercial products
- Close the gap between written guidance and real-world public posts
CENTCOM’s written answers to Wyden supplied the CENTCOM geolocation policy letter details from December 2025. Personnel may still carry personal smartphones. Guidance tells them to turn off unneeded geolocation, review settings and limit sharing. The command noted that turning features off does not always fully disable them on commercial devices, so users must apply broader privacy measures. Escalating restrictions tie to FPCON levels; Delta brought the tightest theater-wide controls.
The expert split is practical rather than theoretical. Bulk commercial sets can sketch a base. Named Strava profiles can help an adversary decide which building or which person matters. Lawmakers treated that distinction as reason enough for safeguards that still read as unfinished in CENTCOM’s spring replies.
Why Public Posts Keep Appearing
Strava told Sky News it takes user safety and privacy seriously and offers extensive controls. The company said people in sensitive professions are expected to use those controls to limit public content. That places the burden on individual service members and contractors who may treat the app like any other fitness tool.
Common consumer devices remain widespread. Many troops and support staff still reach for common consumer fitness trackers still in wide use that sync automatically to Strava or similar platforms. Default privacy settings favor sharing. Training slides and policy letters compete with habit and unit culture that prizes physical readiness logs.
CENTCOM received threat reports, briefed force-protection personnel, and raised the FPCON. Public data still appeared. The command has not released the full text of Policy Letter 25-10 or answered how many violations it has logged. That silence leaves the enforcement picture incomplete while the wider Middle East conflict fronts with Iran keep bases under active threat.
Automatic sync does the quiet work. A runner finishes a loop, the watch hands the track to the phone, and the phone hands it to a public feed unless someone has already locked every setting. Policy assumes that last step. Consumer design often skips it.
The 2018 Warning That Never Fully Landed
Researchers spotted the original Strava heat-map problem in early 2018. Remote bases in Afghanistan, Syria and elsewhere glowed because deployed personnel were among the few users in those areas. Jogging routes traced fence lines and living areas. The Pentagon responded within months with the operational-area ban. Warnings about personal information, routines and headcount exposure were explicit.
Eight years later the same class of data remains public in an active theater. Passive collection and resale of location data to advertisers add another layer of exposure that policy letters only partly address. Lawmakers note the department has known about commercial location tracking of U.S. personnel since at least 2016 briefings. The pattern repeats: discovery, memo, training, then new public examples when conflict intensifies.
| Period | What Became Visible | Institutional Response |
|---|---|---|
| Early 2018 | Global heat map lit remote bases and patrol routes | Operational-area geolocation ban within months |
| December 2025 | Ongoing need to limit sharing on personal devices | CENTCOM Policy Letter 25-10 on disablement and reviews |
| February-Spring 2026 | Public workouts after FPCON Delta; threat reports to Congress | Tightest theater controls; force-protection warnings |
The 2018 glow showed outlines. The later feeds add names, interior shots and post-ceasefire barracks concentrations. The department’s knowledge window, counted from those 2016 briefings, is now measured in years rather than surprise discoveries.
Named Profiles Change the Collection Problem
Anonymous heat once told an outsider where a base was busy. Named profiles tell an outsider which accounts keep returning to the same corner of that base. Analysts on X flagged that shift when the new investigations landed: the danger moved from crude outlines toward people who can be cross-checked against other open records.
A contractor who leaves a naval facility and starts logging courtyard loops at a hotel hands over both the old site and the new one. A run cluster that tightens on eastern barracks after a ceasefire window hands over a preference map. Real-time or near-real-time posts add timing without any special access.
- Full names link workouts to social profiles and possible rank cues
- Recurring start and end points mark living areas over time
- Relocation tracks advertise moves from bases into hotels
- Kit and gym photos help confirm the poster belongs on site
None of that requires proving a single adversary opened the app on a given night. It only requires that the feeds stay public while other intelligence already points at the same installations.
Guidance Still Leans on Individual Settings
CENTCOM’s December 2025 letter and its later answers to Congress describe a system that still allows personal smartphones in the theater. Users are told to disable unneeded geolocation, review privacy settings, and limit what they share. The command also stated that toggling features off does not always fully disable them on commercial products.
That admission matters for enforcement. If the switch is incomplete, compliance depends on wider habits: locked profiles, limited sharing, and awareness that a fitness log can outlive a single workout. Strava’s posture, as described to Sky News, points the same direction. Controls exist; sensitive users are expected to apply them.
Lawmakers wanted structural fixes that do not rely on perfect individual discipline every day. Their list began with advertising IDs on government devices, still incomplete when CENTCOM answered in the spring, and ran through browsers and geolocation behavior that works the same way across commercial products. Written FPCON escalation can tighten the rules. It cannot, by itself, rewrite default share settings on watches already in pockets.
What the Gap Leaves Exposed
Named profiles convert base footprints into dossiers. An adversary can watch a contractor leave a naval facility, appear at a hotel courtyard, and mark the new location. Aggregated runs highlight which barracks fill after a ceasefire. Real-time or near-real-time posts give timing cues. Even if Iran never opened Strava, the data lowers the cost of confirming other intelligence.
Force-protection measures that stay classified cannot erase open postings. Until public sharing stops or privacy defaults change for high-risk users, the reckoning continues each time a new investigation scrapes the same feeds. The troops logging miles for readiness keep drawing the map of their own vulnerability.
Orders, briefings and Delta-level controls stacked up across eight years and still met public workouts on the far side. The remaining exposure is not a missing memo. It is the distance between those memos and the feeds anyone can still open.
