More than 1,300 service members shared thousands of public workouts from U.S. bases in the Middle East, and a July 16 post at Muwaffaq Salti preceded a barracks strike that killed three soldiers.
A public workout posted from Muwaffaq Salti Air Base on July 16, 2026, was the kind of data the Pentagon flagged as an adversary-readable surface eight years ago. The next day, Iran struck the eastern barracks of that Jordan base, killing three American soldiers. The base had not been the only one telling the same story.
An investigation into commercial fitness-app data in the Middle East, cited in reporting this week, found more than 1,300 Strava users sharing thousands of workouts from U.S. military installations across the region, most under their real names, with routes precise enough to map movements between bases and identify activity at installations not labeled on public maps. The reporting drew on shared data: exact routes, exact times, and a pattern that included the two strike sequences the source names explicitly.
Muwaffaq Salti is the cleaner trail. Hundreds of workouts from the base appeared publicly before the war began; the stream stopped when fighting started in February. Posts resumed during the April ceasefire. Of the new workouts, 76% began or ended near barracks on the eastern side of the base, a pattern consistent with a unit relocation. A July 16 workout was publicly accessible. On July 17, those barracks were hit. The reporting is explicit that investigators found no evidence Iran used Strava to select the target, only that the information was public before the strike. The temporal sequence does the work, and the institutional answer has to be one that does not depend on motive.
The second sequence is a Navy contractor at U.S. Fifth Fleet Headquarters in Manama, Bahrain. His runs from the naval base stopped about a week before the war. Two days later, his Strava feed showed him running laps in the courtyard of the Crowne Plaza hotel, where personnel had been relocated. Six days after that, Iran bombed the hotel during attacks on the naval base, wounding two Pentagon employees. Again, the source notes the trail was public before the strike. The takeaway is the same: an institution running on publicly available data, with no operational lockout.
In 2018, Strava's global heatmap inadvertently exposed the locations of secret U.S. bases; the Pentagon responded with guidance to service members about the risk of commercial location data. USCENTCOM (U.S. Central Command, which oversees American forces in the Middle East) has since received multiple threat reports on adversary exploitation of that data, according to reporting the source describes. Eighteen service members have been killed since the war began. The open question is what an institution with a documented warning record actually did to close the loop, and where the chain of decisions broke.
The fix levers are specific and largely procurement or policy, not training alone. They include mandatory commercial-fitness app restrictions on devices that touch military networks, pre-deployment device wipe and reissue, real-name enforcement against the kind of public-by-default settings that made the data visible, geofencing that suppresses public posting from installation footprints, and a chain of commander-level accountability that ties a public workout to an after-action review. The eight-year record is long enough to ask which of those an institution tried, and where each one was lost.
The 2018 warning produced guidance. Guidance does not write itself to the device a service member takes home and back. A fitness app that is free, runs on the same phone that holds a deployment calendar, and posts by default to a public map is the kind of surface a COTS (commercial off-the-shelf) threat does not have to build, because the market builds it. The question for the institution is not whether a few soldiers were careless, and not whether Iran used the data, but whether the chain of decisions between a 2018 warning and a July 2026 barracks strike is one any institution could call a fix. It is the part of the record that is auditable, and the part the public has not yet seen.