A sports app has exposed US military bases?
The incident that soldiers publicly share their running routes via fitness apps has backfired again. UK media Sky News recently broke a major story, revealing that over 1,300 Strava users publicly uploaded their activity tracks while on US military bases. In theory, these public datasets could be used as intelligence by Iran to strike US military bases.
Even some of these activity tracks perfectly align with the locations of Iranian attacks, making it impossible not to draw associations.
01 Went for a run, and details of the military base got "blown up"?
Strava is a highly popular fitness social app overseas, which is very user-friendly for sports enthusiasts and has strong social attributes. One of its core functions is to record and upload various sports routes, and some users even use it to draw patterns on the map with their tracks while running or cycling.
So how did the investigative journalists from UK's Sky News use it to investigate the US military?
"The core method" does not require any hacking skills, since some Strava users themselves have posted the most critical information online: location, time and identity. The investigation is to cross-screen a large number of clues, starting from public data, and connect users' personal homepages, social media accounts, running routes and timelines together.
In this way, the investigation team found more than 1,300 users who posted fitness records at US military bases in the Middle East, and even some unmarked military facilities, most of whom used their real names when using the app. Then by comparing the activity records of these users, they analyzed who were US soldiers, when they moved around the base, and where they would go if they evacuated, so as to infer the operation rhythm of the base.
Simply put, if you know a person is a member of the US military, the place where he regularly runs is likely to be a training ground, and people who take similar routes with him are likely to be other military personnel. If you know the location of the base, you can filter out which users are likely related to the US military based on a large number of nearby activity tracks. By cross-combining these clues, you can further speculate on the intelligence inside the base.
So did Iran really use this batch of data to attack US military bases? No party has confirmed that Iran has used these data so far, but if you launch an attack according to these public tracks, you can indeed hit the target.
One relatively typical record is related to a base in Bahrain.
This base was bombed by Iran after the conflict broke out, but before the bombing, the internal personnel had already evacuated to nearby hotels. However, those hotels were also bombed later. British journalists were curious about how Iran knew the US military had moved to nearby hotels. There are many possible sources of intelligence, but they turned their attention to Strava users, and unexpectedly found real "clues".
Investigators from the British media confirmed that one Strava user was a US Navy contractor, who often ran around the base when there was no war. After the war broke out, he suddenly updated a new running route, which was located in the courtyard of a nearby hotel, and 6 days after his update, the hotel was also attacked by Iran.
Therefore, investigators inferred that it is very likely that Iran's intelligence agency also observed such accounts, and thus "chased to strike".
Another scenario is to analyze where people are located in the base through the running tracks of a group of people.
For example, a base in Jordan used to have hundreds of check-in records, which basically stopped after the war broke out at the end of February. The records resumed after the ceasefire in April, but compared with the previously scattered running tracks, 76% of the later routes started or ended at the same barracks. Later, the two sides exchanged fire again, and in July Iran directly attacked this location, killing 3 US soldiers.
What is everyone's attitude towards the suspicion of this "leak"?
Strava itself has privacy settings, and it calls on users to pay more attention to their own identities, not to enable location services casually, and to turn off positioning if necessary. The Pentagon said it would not take charge of this matter, and suggested asking U.S. Central Command.
Some military experts expressed their speechlessness about this, and some believe that Iran certainly has the possibility to use these data. After all, modern military intelligence analysis aggregates multiple sources of intelligence, especially this kind of easily accessible public information, which is too good to be wasted.
What really worries experts is that now people can infer the "pattern of life" in military intelligence at very low cost.
Generally speaking, it means using multi-dimensional information to figure out the "daily routine" of the target. Once the pattern is broken and anomalies appear, further valuable intelligence can be formed.
Similarly, using public information on the Internet to figure out the daily routines and patterns of netizens in a certain area, if abnormal situations occur, it may become valuable intelligence. Just like the military personnel in Bahrain who suddenly changed to a hotel to continue running, the sudden change of location may mean that they collectively changed their gathering place.
In fact, the US military intelligence system itself used to take this set of "pattern of life" analysis as its unique skill, which was widely used in the Iraq War and the Afghanistan War in the past, and it can be regarded as a traditional craft. But at that time, the cost was obviously much higher. To obtain information, people almost had to use satellites, reconnaissance planes, communication monitoring, surveillance personnel, relevant technical personnel and so on.
Compared with the plot in movies and TV shows that a team of hackers work on the task, scraping public Strava data on the Internet obviously has a lower cost. The darkly humorous thing is that the enemies of the US military may not use Strava to record their daily fitness activities, but the US military itself uses it a lot.
Just imagine, in the Middle East desert, you can find a group of real-name European and American users running around fixed facilities. What are they doing there?
It's really hard to guess!
It is ridiculous that the whole incident is actually an old story that has been brought up before. Because using Strava to find US military bases caused a huge news back in 2018.
Strava launched a "Global Heatmap" in 2017, which is a large aggregation of users' activity track information over the past two years or so.
But in 2018, Nathan Ruser, a student majoring in international security at the Australian National University, found the problem, and he started to use this map to find "American soldiers".
The method is very simple. Although the heatmap is anonymous, many military bases are located in sparsely populated areas where few local people use fitness apps. So when some sensitive areas are mostly blank but only a certain part is very bright, it is very suspicious.
Following this idea, he found US military bases in Syria, and described them as "lit up like Christmas trees".
This discovery caused a huge stir back then. Other analysts and media journalists followed this idea and uncovered a string of locations of military bases around the world.
The US military's reaction to this incident at that time was that after considering it for more than half a year, it issued a ban requiring that the positioning functions of electronic devices, apps and other things must be turned off when entering combat zones.
In other words, the relevant ban has been in place for eight years. Why did similar incidents still happen in 2026?