Public Workouts Are Revealing More Than Miles

Fresh reports say public Strava workouts are still revealing U.S. base activity in the Middle East, reviving a known security gap that the Pentagon flagged eight years ago.

Story Highlights

  • Pentagon warned in 2018 that fitness apps could expose bases and patrol routes.
  • Defense rules later restricted geolocation features for deployed personnel.
  • New reporting says public Strava posts still show routines at U.S. sites in the region.
  • Strava says data is aggregated and users control privacy settings.

Pentagon’s 2018 Warning And The Rules That Followed

In January 2018, the Pentagon said it was reviewing policy after analysts showed Strava’s heat map lit up U.S. bases and revealed running and patrol routes overseas. A Pentagon spokesman told National Public Radio that the department took the issue seriously and was assessing new training or rules to protect personnel. By August 2018, the Department of Defense restricted geolocation features for deployed personnel, citing a significant risk from fitness trackers and app-enabled devices.

Those steps aimed to close a simple but dangerous gap: public data from phones and wearables can show where troops live, work, and move. That insight does not require hacking. It only needs enough people to post workouts in the same places. Reporters and researchers documented how Strava’s global map sketched outlines of remote facilities, access roads, and routine loops runners prefer on base perimeters. The initial heat map episode became a textbook case of public data exposing sensitive sites.

What Is New: Public Posts Still Appear Around U.S. Sites

Fresh reporting indicates the risk is not fully closed. Stars and Stripes reported that service members and other users are still publicly sharing workouts from U.S. locations in the U.S. Central Command area, keeping patterns visible to anyone with an internet connection. The outlet noted that the Defense Department has wrestled with this problem since 2018 and that adversaries can use routine activity to build a picture of base life, shift changes, and traffic near sensitive areas.

This is the same pattern seen worldwide. French media and British outlets have tracked similar exposures among allied forces, and each time the root cause is the same: voluntary, public sharing of precise location trails over time. The issue is not one company alone. It is the clash between social features that reward posting and the strict needs of operational security. Military rules can tighten, but compliance has to be constant and clear to every user with a device.

Strava’s Position: Aggregated Data And User Controls

Strava says its heat map aggregates and anonymizes activity and excludes private workouts and user-defined privacy zones. The company has said users can keep workouts private and opt out of the global heat map. Strava has also said it will work with military and government officials to address sensitive areas that might appear on its maps. Company leaders have stated they do not monitor people without consent and have not seen evidence of hacking tied to the heat map.

Those statements confirm an important point for readers: exposure happens when users choose public settings in or around sensitive sites. That does not lessen the risk. Aggregated dots still outline bases in remote desert regions where only troops run. A privacy box unchecked one time can add another line on a map. For adversaries who watch open sources and stitch small clues together, that is enough to narrow targets and time windows.

Why This Matters For Security And Accountability

Operational security starts with strict rules and ends with daily discipline. The Defense Department’s 2018 policy change made sense, but new posts suggest gaps in training, enforcement, or both. Clear orders, command checks, and default device settings matter. So does fast coordination with platforms to mask sensitive zones when needed. American families expect that routine tech will not put their loved ones at risk on deployment. That is a reasonable, basic standard in 2026.

Conservatives should also see the bigger fight here. Big Tech often builds for growth first and safety second. When profit leans on sharing and streaks, privacy becomes the user’s burden. Our troops should not carry that burden alone in war zones. Washington can press for default-off location sharing near U.S. and allied sites, while commanders enforce no-excuses rules down the chain. Protecting our service members is not optional policy. It is the job.

What To Watch Next

Watch for updated Defense Department guidance and clear metrics on compliance in the U.S. Central Command theater. Look for platform-level changes that harden privacy by default near known bases, not only optional settings buried in menus. Expect Congress to demand answers on training lapses and whether app companies will geofence sensitive areas on their own. The mission is simple: stop painting targets with our own data. Our troops deserve better, and so do the families who wait at home.

Sources:

redstate.com, npr.org, cnn.com, taskandpurpose.com, x.com, avnet.org, engadget.com