Home World News Security Risks of Fitness Apps at Military Bases

Security Risks of Fitness Apps at Military Bases

Security Risks of Fitness Apps at Military Bases

Reports suggest Iranian forces may have used data from fitness app Strava, shared by users at U.S. military bases in the Middle East, to target American forces. In 2018, the Pentagon initiated a review of fitness app use by its personnel. The concern was that such apps, which track running, cycling, and swimming routes, could be exploited by adversaries to understand personnel movements, forming a ‘pattern of life.’ The Pentagon determined these apps posed a security risk, banning their use without permission.

Despite this, Sky News analysis indicated continued sharing of Strava data by hundreds of users at U.S. military bases, potentially compromising frontline personnel against Iran. Special operations expert Jonathan Hackett attributed this to ‘lax enforcement and lack of awareness,’ suggesting Iran might track U.S. troop movements.

“Lax enforcement and lack of awareness are the main issues,” Hackett said to Sky News.

Sky News discovered over 1,300 Strava users sharing workouts at U.S. military bases, often using real names. This presents potential risks for targeting or espionage. After joint U.S. and Israeli airstrikes on Iran began on February 28, **Tehran retaliated with attacks on American bases, notably hitting a naval base in Manama, Bahrain, on March 1. Sky News identified a Strava account of a U.S. Navy contractor who recorded runs at this base up to a week before the conflict.

At Jordan’s Muwaffaq Al Salti Air Base, U.S. personnel shared numerous runs on Strava. After an April ceasefire, runs continued, starting or ending at the barracks on the base’s eastern corner, a target in Tehran’s July 17 attack, resulting in the deaths of three soldiers.

The issue is not limited to U.S. troops. Sky News noted that British soldiers from RAF Akrotiri in Cyprus, another Iranian target, shared sensitive data. Additionally, investigations found jogging records inside Israel’s Dimona nuclear center and revealed sensitive operational routines of Israeli soldiers near Gaza.

French newspaper Le Monde’s ‘#StravaLeaks’ investigation highlighted similar risks. One instance involved revealing the location of a Middle East-bound aircraft carrier. Fitness data further exposed military positions in conflict zones, including details about French President Emmanuel Macron’s security jogging activities.

Location intelligence firm Mapulus explained that consumer technology can produce intelligence-grade data, transforming personal fitness tracking into a global surveillance network. They described this as a classic open-source intelligence (OSINT) case, where consumer data becomes a national security threat.

Highlighted cases included Peter Reesink of the Netherlands’ military intelligence service, who maintained a public Strava account. He inadvertently revealed personal details such as his home address and holiday locations, violating his ministry’s guidelines.

Strava assured it values user safety and privacy, offering robust privacy controls. They urge users in sensitive professions to employ these controls to restrict content appropriately.

Leave a Reply

Your email address will not be published.