logo

Privacy Meltdown: Strava tricked into Revealing Soldiers’ Names

ID: ad69d16f-94ff-5d0b-a61f-35923f3e8b58

STIX ID: report--ad69d16f-94ff-5d0b-a61f-35923f3e8b58

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2018-02-01

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

A Norwegian journalist demonstrated that Strava's public heatmap and Flyby feature can be abused to identify and reveal names and locations of military personnel by uploading hundreds of slightly altered GPX tracks to generate fake runs and then using Flyby to find co-located users; the experiment exposed dozens of service members and highlights risks from default privacy settings and location-based services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.