U.S. military personnel are continuing to publicly share fitness-tracking data that reveals patterns of life at bases across the Middle East, months after U.S. Central Command imposed what it has described as its most restrictive geolocation controls in the region, a Stars and Stripes review has found.
The review identified users of the Strava fitness app who repeatedly recorded and publicly shared workout details from bases in several countries within CENTCOM's area of responsibility.
The activity logs included recurring routes and exercise locations that, over time, exposed patterns in personnel's movements.
Some posts went further, including photographs of individuals in Army physical fitness clothing or military-style equipment; one activity geotagged to a military site included a photo taken inside a fitness area.
The Stars and Stripes findings follow a Sky News investigation published Wednesday that identified more than 1,300 Strava users sharing thousands of workouts from U.S. military installations across the Middle East.
That reporting found the publicly available data could reveal concentrations of personnel and details of their daily routines at sites later targeted by Iran, though it stopped short of establishing that Iran had used Strava data to select targets.
One example cited in that reporting: publicly accessible Strava activity was posted at Muwaffaq Salti Air Base in Jordan on July 16, one day before an Iranian attack on the installation killed three U.S. soldiers.
CENTCOM declined to say whether the Strava activity identified by reporters complies with its geolocation rules, how those rules are enforced, or whether any personnel have faced discipline over violations. "We do not discuss force protection measures for operational security reasons," the command said in an email Thursday.
Concerns about fitness-tracking apps exposing sensitive military activity are not new. The Defense Department has wrestled with the issue since at least 2018, when researchers found that Strava's global heat map of aggregated user activity could reveal patterns at military installations and other sensitive sites worldwide.
In response, the department barred personnel from using geolocation features on both government-issued and personal devices, apps and services while in designated operational areas, warning that such features could expose personal information, locations, routines and troop numbers.
More recently, officials have turned their attention to a related problem: the passive collection of geolocation and other data by apps and devices, which is often sold in aggregate to advertisers.
CENTCOM told Congress this spring that it had received threat reporting on adversaries exploiting commercially available location data to target or monitor U.S. personnel in the region, and said it had warned force protection personnel across the theater accordingly.
Under a geolocation policy the command issued Dec. 4, 2025, personnel in its area of responsibility are required to disable unnecessary geolocation functions, periodically review privacy settings and limit public sharing of information, CENTCOM told Sen. Ron Wyden, D-Ore.
The rules tightened further this year: on the eve of the Feb. 28 launch of the Iran war, CENTCOM commander Adm. Brad Cooper raised the command to its highest force protection level, a move that included what officials later told Congress were the command's most restrictive geolocation controls across the theater.
Some of the publicly accessible Strava activity identified in the review was recorded after those tightened restrictions took effect.
A bipartisan group of lawmakers has continued pressing the Pentagon for additional safeguards after CENTCOM acknowledged that adversaries were exploiting commercially available location data.
In May, the lawmakers warned that such data could be used to enable missile and drone attacks as well as surveillance and countersurveillance efforts against U.S. forces.
In response to questions this week about the Strava data, CENTCOM did not provide a copy of its Command Policy Letter Number 25-10, the United States Central Command Geolocation Policy, when it was requested. Command officials had not responded to additional questions as of Friday.