New Zealand Defence Force personnel have exposed sensitive military locations, deployment movements, and daily operational routines across 13 countries by using the fitness-tracking application Strava, a 1News investigation revealed. Security experts warn the publicly accessible data allows foreign adversaries to map detailed “pattern of life” intelligence, despite military authorities having known about the operational security risks for years without implementing a specific policy to stop it.
565 Strava Accounts Logged at Defence Sites Across New Zealand and Overseas
The 1News investigation identified 565 Strava users logging workouts at New Zealand Defence Force camps and bases since January. These locations include Whenuapai, Devonport, Ohakea, Linton, Burnham, Waiouru, and Woodbourne. Some accounts recorded activity inside Papakura Military Camp, which houses the NZSAS, and the nearby Ardmore training facility used for special operations training.
Of the 565 profiles uncovered, 488 were set to public, making their complete activity histories visible to anyone. Investigators found profiles by utilizing Strava’s “segments” feature—running and cycling routes featuring public leaderboards. A simple search revealed 41 public segments at defence sites, including routes titled “Loop in Base,” “Base Escape!” at Whenuapai, “Runway Dash” at Ohakea, and “Linton RFL” referencing the Required Fitness Level test soldiers must pass. Some leaderboards displayed lists of names active since 2018.
Global Deployments and Foreign Military Installations Exposed
The digital footprint extended far beyond domestic training camps, tracking personnel stationed overseas near potential conflict zones. Australia accounted for the largest international footprint, with activity logged at major air force bases in Richmond and Amberley, alongside Townsville and Edinburgh, where surveillance and signals intelligence operations are based.
Other accounts recorded activity at RAF bases in the United Kingdom, camps in Egypt’s Sinai Peninsula where NZDF personnel serve with the Multinational Force and Observers, and Scott Base and McMurdo Station in Antarctica.
“When you’re seeing people posted offshore, close to potential combat zones, conflict zones, operationally deployed – that is much more concerning and a real risk to operational security,” said David Capie, Director of the Centre for Strategic Studies at Victoria University of Wellington.
Public Leaderboards Expose Military Personnel Profiles
One identified profile belonged to a high-ranking NZDF member posted to the New Zealand Embassy in Washington DC.
Cole Proebstel, a former New Zealand Army intelligence specialist and founder of ALCON Intelligence, explained that public leaderboards instantly supply a verified list of military personnel. “An actor can then go and look at other social media profiles, and then figure out your relationships, the network you’re part of, who you work for, potentially your position, your rank, and what you might have access to,” Proebstel said. In at least 30 cases, private profiles appeared by name on public leaderboards, while 13 cases allowed investigators to identify family members through linked accounts or tagged activity.
Historical Warnings and Lack of a Specific App Policy
Documents obtained by 1News show the New Zealand Defence Force has repeatedly warned personnel about fitness-tracking risks. The military’s social media handbook cites a 2018 incident where New Zealand personnel visiting the US National Security Agency’s Fort Meade headquarters were identified through a different fitness app. Guidance instructs personnel to disable tracking apps in sensitive locations and avoid using real names, though the military currently has no policy specifically covering Strava.
“This is not a new issue. This is as old as time itself,” said John Howard, a retired Major General and former NZDF Chief of Defence Intelligence, noting that similar exposures occurred during Middle East operations in 2015.
In a statement addressing the findings, the New Zealand Defence Force said it applies a range of measures to protect personnel and operations, expects sound judgment from staff, and provides regular guidance during pre-deployment training. The military added that the online availability of fitness tracking data does not inherently indicate a security breach, operational compromise, or non-compliance with requirements.
Frequently Asked Questions About Military Fitness Tracking Risks
Does the New Zealand Defence Force ban Strava for its personnel?
No. The NZDF has no specific policy covering Strava or other fitness-tracking applications, relying instead on general guidance that instructs personnel to exercise sound judgment and disable tracking features in sensitive locations.
How did investigators identify military personnel through the app?
Investigators used Strava’s public “segments” and leaderboards, which displayed user names along specific running routes located inside military camps and bases both in New Zealand and overseas.
What international military sites were linked to New Zealand profiles?
New Zealand personnel profiles logged workouts at major installations in Australia, the United States, South Korea, the United Kingdom, Egypt’s Sinai Peninsula, and Antarctica, among other international locations.
Keep reading