Iranian forces may have used publicly available data from the Strava fitness app to track US military personnel wearing fitness devices and identify potential targets for strikes on American facilities in the Middle East, Sky News reports.

According to the broadcaster, more than 1,300 users posted workout data from US bases. Such records can reveal daily routines at military sites, show personnel movements and expose changes in deployment patterns. In some cases, the activity data points to locations that do not appear on publicly available maps.

Sky News journalists identified the account of a US Navy contractor who had regularly uploaded running data from a base in Manama, Bahrain, before the military operation against Iran began. After being evacuated, the contractor started recording workouts near the Crowne Plaza hotel. Six days later, Iranian forces struck the hotel, injuring two Pentagon employees.

A similar case was reported at the US Muwaffaq al-Salti Air Base in Jordan. Before hostilities began, American servicemen had uploaded hundreds of training routes to Strava. During the ceasefire, 76 percent of those routes either started or ended near barracks in the eastern part of the base.

On July 17, the Iranian military struck those barracks, killing three US servicemen.

US Central Command, or CENTCOM, did not comment to Sky News on the incidents.

Experts interviewed by the broadcaster said Strava data could have been used for intelligence purposes. They warned that the app creates serious security risks because workout routes are often linked to users’ real names and social media profiles.

US authorities had already warned in 2018 that Strava data could expose the locations of military personnel. Restrictions on geolocation features were introduced afterward.