Log in

Blog

The Strava heatmap exposed military bases. Your launch spot is next.

A student traced secret military bases from Strava's public heatmap. The same maths can find your home launch, and it matters for anyone who logs a paddle.

PaddleScout · 30 June 2026 · 6 min read

A near-black map of a coastline at night with thin teal and white lines of GPS activity glowing where paddlers launch and return, blooming brightest around one stretch of shore.

In November 2017, Strava published a global heatmap built from over a billion activities and 3 trillion GPS points. Ten weeks later, a university student used it to trace the outline of classified military bases. He hacked nothing. He zoomed in on where soldiers went running.

The same maths that exposed those bases works on a quiet lake. If aggregated fitness data can draw a secret base, it can draw where you live and where you launch your board.

What the heatmap showed

Strava put the map up as a celebration of movement, the richest public dataset of its kind. For a few months it drew admiration and little else.

On 27 January 2018, an Australian student named Nathan Ruser zoomed in on Syria. Where he expected darkness, running routes glowed. 'It looks very pretty,' he wrote, 'but not amazing for Op-Sec. US Bases are clearly identifiable and mappable.' Syria, he said, 'sort of lit up like a Christmas tree.'

Within days, analysts had traced the perimeters and patrol routes of forward operating bases across Syria, Afghanistan and Iraq, then French and US sites in Djibouti, Niger and Somalia. One base in Helmand province did not appear on Google or Apple Maps, yet its jogging loops were laid out in light. The Pentagon opened a review of its device rules. Strava said the map was an aggregated and anonymised view that left out private activities.

Nobody hacked Strava, and no single soldier did anything reckless. The base showed up because hundreds of ordinary, private-feeling runs were public by default. Put hundreds of them on one map and the base appears.

Why a launch spot is a home address

The maths that gave away those bases works on a quiet lake in the Lake District too.

Human movement is distinctive. A 2013 study in Scientific Reports called 'Unique in the Crowd' analysed the movement of 1.5 million people and found that four points in time and space identify 95% of individuals. Two points alone single out more than half of us. Your pattern is a fingerprint.

Apply that to a paddle log. You put in from the same few launches, and some of them sit a short walk, or a driveway, from home. In 2023, researchers at North Carolina State University showed in a paper called 'Heat Marks the Spot' that they could work backwards from Strava's anonymous heatmap to the home addresses of active users in quiet areas, then confirm them against public voter records. One of the researchers started the project after a friend was stalked.

A stalker has already used it to hunt someone. In a 2023 Tennessee murder-for-hire case, a woman tracked her target on Strava and alerted the hired killer when the victim left home for a two-mile walk. Women runners had warned about this for years. A journalist called Strava's public routes 'a feminist issue' in Quartz in July 2017, months before anyone mentioned military bases.

Log the same launch again and again and it points back to your front door.

The default is the problem

After each of these stories, the easy reaction is to call it a one-off: a bug, or a setting someone forgot. Look closer and the same cause repeats. The tracking is public unless you find the switch and turn it off.

In 2022, an Israeli watchdog called FakeReporter found that fake route segments planted inside secret bases could harvest the identities of at least 100 security staff across six top-secret installations, including people who had set the strongest privacy options. In October 2024, Le Monde reconstructed the movements of Macron, Biden and Putin from their bodyguards' public activity. The reporter, Sebastien Bourdon, said the settings themselves were sound, and that most of the people he tracked had not switched them on. In July 2025, Sweden's Dagens Nyheter followed more than 1,400 workouts posted by the prime minister's bodyguards and exposed his classified residence.

Different apps, different years, one cause: location that stays public unless you find and change a setting. That model asks the person least able to judge aggregate risk to protect themselves, and it fails women, deployed soldiers and heads of state alike.

Strava has improved since 2018. It now hides the start and end of an activity and lets you opt out of the heatmap. The philosophy has not changed. Sharing is the default, and privacy is homework. We go further into why that default matters in a companion post on private-by-default tracking.

How PaddleScout handles it

PaddleScout starts from the opposite assumption. The water you love most, your home lake or your dawn launch, is the thing that should never leak by accident.

So every paddle you upload starts private, from the first session, with no toggle to remember. We enforce that on our servers, not in the app alone, so nothing goes public unless you choose it. There is no setting buried three menus deep that shares your tracks behind your back.

When you want to share, you pick the level: public, a secret link you send to one person, or private for you. Your friends see your paddles in a private feed of people you have added, not a public stream a stranger can scroll. We never build a public heatmap from your launches, so there is no glowing shoreline to reverse-engineer, and your home water stays yours.

We built it this way for the people most exposed by public-by-default tracking, who are often the ones who most need to feel safe on the water. There is more on that in a companion piece on fitness apps, safety and women paddlers.

The heatmap made headlines over military bases. The mechanism underneath is ordinary: an app that shares everything unless each person stops it. PaddleScout makes the private choice the automatic one, so your launch never becomes a dot that someone else can read.