Menu

Strava Data Risks Among Military Personnel

2 hours ago 0

Iranian forces might have exploited data shared by Strava users stationed at U.S. military bases in the Middle East to target American personnel. This revelation has led to closer scrutiny of fitness apps used by military members.

In 2018, the Pentagon initiated a review regarding the use of fitness apps such as Strava. These apps track running, cycling, and swimming routes and times. The Pentagon’s concern was that adversaries could use this data to map personnel deployments and movements, potentially compromising security through what is termed a “pattern of life” analysis.

The Pentagon’s investigation found these apps presented security risks, leading to a ban on their use without prior approval. Despite this ban, Sky News reported that Strava data continues to be shared by numerous users at U.S. military installations, risking exposure to hostile entities.

Jonathan Hackett, a special operations expert, explained that “lax enforcement and lack of awareness” contribute to the ongoing sharing of location data. This data possibly aids Iran in tracking U.S. troop movements throughout the region.

Sky News analysis discovered more than 1,300 Strava users shared workouts from U.S. bases, many using real names, creating potential targets for attacks or espionage. Following U.S. and Israeli airstrikes on Iran starting on February 28, Tehran launched retaliatory strikes on several American bases.

A significant naval base in Manama, Bahrain, was among those hit on March 1. Fortunately, it had been evacuated. Sky News identified a Strava account belonging to a U.S. Navy contractor who had logged runs around the base just a week before the conflict began.

U.S. personnel from Jordan’s Muwaffaq Al Salti Air Base also shared runs on Strava before and during a ceasefire in April, with routes later linked to an Iranian attack that resulted in fatalities.

British soldiers similarly exposed sensitive data from RAF Akrotiri in Cyprus, targeted by Iran. Meanwhile, activities from Israel’s Dimona nuclear research center, a frequent target, were tracked by Strava users, causing concern about potential data breaches.

Le Monde in France highlighted risks posed by Secret Service agents and others revealing operational routines on Strava. They discovered that a French officer’s data revealed locations of military assets deployed towards the Middle East.

This situation emphasizes the vulnerability of everyday consumer data, which can transform into intelligence-grade information. Mapulus, a location intelligence platform, noted this as an example of open-source intelligence (OSINT).

The openness of consumer data shared online poses serious national security challenges. The case of Peter Reesink, head of the Netherlands’ military intelligence service, illustrates the risks. He kept a public Strava account for years, inadvertently exposing his location and patterns.

Strava assured users about its commitment to safety and privacy, citing extensive controls available for users to manage their data. Nevertheless, people in sensitive roles should apply these controls to limit exposure.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *