New Zealand Defence Force Fitness App Intelligence Risks Exposed
Military personnel using fitness applications like Strava have inadvertently exposed deployment locations, patrol routes, and daily operational patterns across international military installations. A 1News investigation uncovered 565 user accounts logging workouts at New Zealand Defence Force (NZDF) camps and overseas posts, including sites in the Middle East, South Korea, and Antarctica. While military bases remain public knowledge, security experts warn that aggregated fitness data creates a detailed “pattern of life” that foreign adversaries can exploit for intelligence gathering.
Global Exposure at Sensitive Military Sites
The investigation identified hundreds of public profiles tracking military movements across 13 countries and territories. Australia recorded the largest overseas footprint, with personnel logging workouts near surveillance and signals intelligence operations at bases like Edinburgh and Townsville. Other profiles traced activity to Joint Base Pearl Harbor-Hickam in Hawaii, Camp Humphreys in South Korea, and camps in Egypt’s Sinai Peninsula where NZDF personnel serve with the Multinational Force and Observers.
Strava Leaderboards Expose Military Personnel Names
Strava’s public “segments” feature allows anyone to view leaderboards for running and cycling routes mapped across defence properties. Researchers found 41 public segments at defence sites, including routes inside Whenuapai Air Base, Ohakea Air Base, and Linton Military Camp. Cole Proebstel, a former New Zealand Army intelligence specialist and founder of ALCON Intelligence, explained that these public leaderboards instantly generate lists of verified military personnel names. From there, malicious actors can examine connected social media profiles to determine personal relationships, ranks, unit assignments, and potential security clearances.
Internal Warnings Versus Lack of Specific Policy
Internal documents obtained by 1News reveal that NZDF leadership has repeatedly warned personnel about the intelligence risks of fitness-tracking software since at least 2018, following an incident where New Zealand personnel visiting the US National Security Agency’s Fort Meade headquarters were identified through a fitness app. Despite these recurring warnings and a June advisory prompted by a French naval officer exposing an aircraft carrier’s location via Strava, the NZDF maintains no specific policy banning or regulating fitness applications. In an official statement, the Defence Force noted that it applies standard measures to protect information and expects personnel to exercise sound judgment, adding that the mere availability of online fitness data does not automatically constitute a security breach.
Related reading