Iran may have exploited fitness tracking app Strava to target US military bases.
The app lets users broadcast precise routes and timing data from their runs, bike rides and swims, with thousands of these activities recorded within bases on the frontline of the conflict with Tehran.
Read Also: Iconic British attraction set to exit home after 60 years in blow to thousands
Leaked information exposed daily operational rhythms, troop movements between facilities, some of which do not appear on publicly available maps, and patterns of personnel deployment and withdrawal.
The vast majority of users were posting under their real names, effectively marking themselves as potential targets for attack or espionage, reports Sky News.
Read Also: WATCH: A-Level student shocked as she opens her results live on GB News
Read Also: One dead and several injured after explosion rocks Europe's largest port
One case involved a US Navy contractor stationed at a major naval facility in Manama, Bahrain. The base had been largely emptied ahead of the conflict, with staff relocated to civilian accommodation across the city.
The contractor had been regularly tracking runs around the installation until a week before hostilities began. After a two-day gap in activity, his Strava profile showed him running laps in the courtyard of the Crowne Plaza hotel.
Six days later, when Iran launched its retaliatory strikes against US bases on March 1, the hotel was also hit. Two Pentagon employees were reportedly injured in the attack.
Joseph Jarnecki, a research fellow at the Royal United Services Institute, said it was “completely plausible” that Iran had used Strava to monitor where American personnel were being moved.


The fitness app data also revealed a dangerous shift in routines at Muwaffaq Al Salti Air Base in Jordan.
Before the war started on February 28, hundreds of runs were being posted across the entire facility.
When personnel began logging activities again during the April ceasefire, their habits had visibly changed. Some 76 per cent of all runs now started or finished at a single point, the barracks situated in the base’s eastern corner.
On July 17, Iran struck those very barracks, killing three American soldiers.
By aggregating hundreds or thousands of individual workouts, it is possible to construct what intelligence analysts refer to as a “pattern of life”, the predictable rhythms of daily military operations.
LATEST DEVELOPMENTS
- Donald Trump ‘smuggled away in catering van’ to escape assassination threat on Air Force One
- Iran and Israel announce end of strikes against each other after Donald Trump’s intervention
- US launches new round of strikes against Iran as Strait of Hormuz again closed

Virpratap Vikram Singh, a military expert at the International Institute of Strategic Studies, called the Strava data “definitely a security threat”, noting that unlike commercially available location information, it is often tied to individuals’ full names and social media profiles.
He said: “This is the type of information that would be especially valuable in confirming that you’re targeting the right person, that you’re going after someone of the right seniority.”
Serving British soldiers were also found sharing workouts from RAF Akrotiri in Cyprus, a base that has itself been targeted by Iran, with 12,000 exercise sessions logged from within the facility since January.
Some of these users could be tracked on deployments across the wider region, including to installations absent from public maps.

Three Strava accounts were even recording jogs inside Israel’s Dimona nuclear research centre, the nation’s most sensitive site and a repeated target of Iranian strikes.
GB News has contacted Centcom, the military command in charge of the Middle East.
The breach persists despite the Pentagon warning troops more than seven years ago that Strava data could “be used to target individuals” and prohibiting the use of location-tracking features without authorisation while deployed. A White House official acknowledged in 2018 that the app’s data was “really clear” as a security risk.
A spokesman for Strava said the company takes the safety and privacy of its users very seriously and provides extensive privacy controls, along with information about how to use them.
The spokesman told Sky News: “As stated in our Terms of Service, we expect people working in sensitive professions to leverage the controls available to them and appropriately limit their content.”
Our Standards:
The GB News Editorial Charter








