A fitness tracking app has inadvertently revealed sensitive information about the locations and staffing of military bases and spy outposts worldwide. The data was released by Strava in a data visualisation map showing all activity tracked by its users, who record and share their exercise routines.
The map, published in November 2017, includes over 3 trillion individual GPS data points from more than 1 billion activities. While intended to show popular running routes in cities, military analysts noticed that it also exposes the exercise patterns of active service personnel, potentially compromising operational security.
Nathan Ruser, an analyst with the Institute for United Conflict Analysts, first highlighted the issue, noting that US bases are clearly identifiable. In conflict zones such as Afghanistan, Djibouti and Syria, where Strava users are almost exclusively foreign military personnel, bases stand out brightly on the map. The internal layout of forward operating bases in Helmand province, Afghanistan, can be discerned from tracked jogging routes.
Even outside conflict zones, sensitive details emerge. A lone cyclist's route from Area 51 in Nevada is visible, and RAF Mount Pleasant in the Falkland Islands is brightly lit, reflecting exercise regimes of British personnel. Popular swimming spots nearby are also marked.
Strava described the heatmap as 'the largest, richest, and most beautiful dataset of its kind,' highlighting its ability to show events like the Burning Man festival. However, the company did not address the security implications for military users.