Iran was tracking everything. A USA Navy contractor was stationed at the American naval base in Manama, Bahrain.
He was a runner. He used Strava, the fitness tracking app that millions of people use to log their workouts. Every morning he logged his runs from the base. His route, his timing, his distance. All of it was public on his Strava profile, visible to anyone who looked.
Then things changed at the base. US military personnel were moved out of the naval facility to residential buildings and hotels as a security precaution. The contractor moved with them to the Crowne Plaza hotel.
He kept running.
Two days after the move, his Strava account showed him running laps around the courtyard of the Crowne Plaza hotel.
Six days later, Iranian ballistic missiles struck the same hotel during a wave of attacks on US bases across the Middle East.
Two Pentagon employees were wounded.
Iran launched attacks on US bases across the Middle East on March 1, 2026. According to an investigation by Sky News, a US Navy contractor’s Strava data showed him running near the naval base before the attack. A few days later, he was noticed running around the courtyard of the Crowne Plaza hotel. After six days, Iran bombed the same hotel, suggesting Strava was used as a source to track US personnel. Cybernews
He never posted military coordinates. He never shared classified information. He never told anyone where he was.
He posted a morning run.
What Was Actually Happening With That Data
Strava is a fitness app. You log a run, a cycle, a swim. The app records your GPS route, your start time, your finish time, your pace, and your location. It then displays all of this on a map visible to anyone who views your public profile.
This is the feature. This is what makes Strava useful. You can see where you ran. Your friends can see where you ran. You can discover routes other people have run near you.
A Sky News investigation published in August 2026 found more than 1,300 Strava users sharing workouts from or near US military bases in the Middle East. Many of the accounts used real names, while the publicly visible routes could reveal where personnel were exercising, their routines, and changes in activity around military facilities. The Defense News
1,300 individual accounts. Each one innocent on its own. A person logging their run. But when you aggregate 1,300 accounts from the same location, something different emerges.
By aggregating hundreds or thousands of individual workouts, it is possible to construct what intelligence analysts refer to as a “pattern of life”: the predictable rhythms of daily military operations. MSN
The pattern of life is the intelligence. Not any single run. The aggregate of when people run, where they cluster, when the runs stop, and where they appear next.
At the Muwaffaq Salti Air Base in Jordan, 76% of Strava accounts were located at the barracks during the ceasefire. When fighting briefly resumed in July, Iran attacked those very barracks, killing three US military personnel. Wionews
The data was public. The pattern was visible. The attack hit exactly where the data said the people were.
This Is Not New. The Pentagon Knew in 2018.
The most uncomfortable part of this story is not that it happened. It is that it was predicted, warned against, and then allowed to continue for eight years.
According to a letter from Congress, a December 4, 2025, guidance from CENTCOM told troops to disable geolocation services when not needed and regularly review each device’s privacy settings. Task & Purpose
That guidance came out in December 2025. The Pentagon had already issued a similar warning in 2018. Seven years between warnings. The same app. The same problem. The same risk. Still happening.
Why? Because the app is useful. People enjoy logging their fitness. The social element is motivating. And the gap between “this is a security risk in theory” and “this is affecting me specifically right now” is wide enough for most people to continue doing what they enjoy.
This is not a military failure in isolation. It is a human behaviour pattern that applies to everyone who has ever posted a location tag, checked in on social media, or shared a photo with geolocation metadata.
The soldier who posted his runs and the professional who tags their office building in a LinkedIn post are operating on the same mental model: this is normal, everyone does it, nothing bad will happen from sharing this.
Sometimes that is true. Sometimes the hotel gets bombed.
It Went Beyond Fitness Apps
The Strava investigation revealed something broader than just workout data.
The investigation found that the problem extends beyond US forces. Sky News identified about 12,000 workouts recorded inside RAF Akrotiri in Cyprus since January 2026. The Defense News
In France, at least 450 people with access to the sensitive nuclear submarine base on the Île Longue peninsula were identified as Strava subscribers in 2025, with gaps in their exercise activity potentially revealing deployment patterns. Defence Industry Europe
In the UK, personnel serving aboard nuclear submarines exposed names, addresses, and periods spent aboard vessels after failing to apply privacy settings.
In March 2026, the French Navy’s flagship aircraft carrier Charles de Gaulle had its exact location revealed mid-voyage after a sailor posted his runs while at sea.
And before any of this, in 2023, a Secret Service agent’s Strava profile revealed the location of a hotel where President Biden subsequently stayed in San Francisco for high-stakes talks with Chinese President Xi Jinping. A few hours before Biden’s arrival, the agent went jogging from the hotel, with Strava tracing his route. Fortune
A fitness app showed the world where the US President was going to sleep before he arrived.
The Secret Service agent was not being careless. He was going for a run. He had used Strava on his personal account for months or years. He did not think about the implications in that specific moment, because most people never think about implications until after the consequence arrives.
This Is Not Just a Military Problem
If you are reading this thinking, “I am not in the military, this does not apply to me,” I want to gently push back on that.
The mechanism that made those soldiers vulnerable is the same mechanism that exists in your morning run, your daily commute logged on Google Maps, the photo you posted from outside your office building, the LinkedIn check-in that mentioned the hotel you are staying at for a conference, and the Zomato order that shows your home address.
None of these feel like security risks. And for most people, most of the time, they are not.
But consider this.
You are a senior executive at an Indian company working on a sensitive government contract. You run every morning near your office. Your Strava is public. Anyone following your account can see that you arrive at a specific office building every morning at 8:15 and leave by 8:45.
You are a finance professional who approved a significant transaction and now has people who are unhappy about it. Your Google Maps timeline, if your account were accessed, shows your daily routine down to the minute.
You are an IT professional at a bank who has access to core systems. Your fitness data shows you are at the office every day except Thursdays, when you work from home in a suburb your Strava route reveals by name.
No classified information. No sensitive documents. Just a morning run, a commute, a daily routine. Aggregated into a picture of your life that tells anyone watching exactly where you will be and when.
Security experts warned the data was “definitely a security threat”, noting that unlike commercially available location information, Strava data is often tied to individuals’ full names and social media profiles. GB News
Commercial location data is often anonymous. Strava, Instagram, LinkedIn: these are tied to your name, your photo, your employer, your professional network. The combination of precise location and verified identity is what makes public fitness data qualitatively different from a mobile advertising ID that advertisers cannot link to a specific person.
What Your Fitness App Is Actually Sharing
Most people who use Strava, Nike Run Club, Garmin Connect, Fitbit, Apple Fitness, or Google Fit have not read the privacy settings in detail. They set up the app, accepted the defaults, and started running.
The defaults on most of these platforms are public or semi-public. Your routes, your times, your start and finish locations, and often your home location inferred from where your runs consistently begin, are visible to other users or to anyone who looks.
The data you are sharing includes:
Your precise GPS route, accurate to a few metres. Your start time and finish time, creating a record of your daily routine. Your pace and effort data, which over time reveals your fitness level and training patterns. Your location history, which over months reveals where you live, where you work, and where you go regularly. And in many cases, your full name, profile photo, and connections to other users who share the same locations.
When you share a photo on Instagram with location enabled, you share one data point. When you log 200 runs over a year, you share 200 data points that together reveal the shape of your entire daily life.
What to Do Right Now
These steps take about fifteen minutes. They change your exposure significantly.
On Strava:
Go to Privacy Controls in your settings. Set your profile visibility to Followers Only or Private. Set your activity visibility to Only Me for any routes that start or end at your home, office, or any sensitive location. Enable the privacy zones feature, which obscures the start and end of your routes within a radius you define. This is specifically designed to hide your home and workplace from your route data.
On all fitness apps:
Review the default sharing setting for every app you use. Check whether your routes are being published to a public feed. Review whether photos you take during workouts are being automatically tagged with location data.
On your phone:
Review which apps have location access set to Always On. This means the app can access your location at any time, even when you are not using it. Change these to While Using the App for every fitness and social app. Turn off precise location for apps that do not need it. Most apps work with approximate location.
On social media:
Disable automatic location tagging on photos. Go back through recent posts and check whether geotagged photos reveal your regular locations. Think before posting from sensitive locations, your workplace, a government building, a critical infrastructure site, or anywhere you would not want to be tracked.
Before travelling for work:
Put your fitness apps into private mode before you leave. Do not post workout routes from hotel locations or conference venues until after you have moved on. The pattern the Bahrain contractor created was not a single post from a hotel. It was a visible transition from base to hotel, visible to anyone watching his account.
What IT Heads and CTOs Should Tell Their Teams
For anyone managing a team in a corporate environment, the Strava story has a specific takeaway.
Your employees’ personal fitness apps are not your responsibility to control. But your employees’ awareness of what those apps reveal is something your organisation can influence.
A single internal communication, a short note explaining what the Strava case showed and what the privacy settings look like, is a proportionate response. Not a policy document. Not a mandatory training module. A plain-language note that says: here is what happened to a Navy contractor who logged his morning run in the wrong place. Here is how to check your settings. Here is what we ask you to think about when you are travelling for work or working from sensitive client locations.
The employees who work from client sites, who travel to sensitive facilities, who hold roles with security implications beyond the ordinary, deserve to know that their morning run is a data stream. They can make the right choices once they know that.
Final Thought
The Navy contractor in Bahrain was not irresponsible. He was doing what 400 million Strava users do every day. He logged his run. He shared it. He thought nothing of it.
The problem is not the app. The problem is the gap between what people think they are sharing and what they are actually sharing.
They think they are sharing a workout. They are sharing a timestamped, GPS-accurate record of where they were, when they were there, and how their routine changed when their circumstances changed.
The Strava-Iran story is the clearest demonstration this year of what publicly shared location data can become when someone with a purpose aggregates and analyses it. A morning run became targeting intelligence. A hotel became a strike.
For most of us, the consequences of public location data will never be that stark. But the mechanism is identical. What we share publicly can be used in ways we never imagined by people we never considered.
Check your Strava settings today. It takes five minutes.
Note: This blog references the Sky News investigation published August 12, 2026, and follow-up reporting by RedState, Cybernews, Defence Industry EU, and WION News. The Crowne Plaza hotel incident and Jordan barracks data are drawn from these verified sources. No classified information was used in this blog. All references are to publicly reported events based on publicly available Strava data. This blog is for digital awareness and educational purposes.

