I. Introduction
In March 2026, a French Navy officer went for a run while on the deck of the aircraft carrier Charles de Gaulle and recorded the activity on the fitness app Strava. The resulting location data shared via the application revealed the position of the vessel in the middle of the Mediterranean Sea, despite the operational sensitivity of its movements (Balluffier et al., 2026). This incident, not the first of its kind, is a clear example of a wider security problem. Military personnel operate within the same commercial digital environment as civilians, where smartphones, applications and connected devices continuously generate information about their movement.
While the Strava exposure is a result of information actively shared on a user-facing app, location data can also be passively generated, collected and aggregated for commercial sale to third parties (Twetman & Bergmanis-Korāts, 2021). For military personnel, repeated location observations can reveal links to sensitive installations, establish movement patterns and potentially provide indications of broader military activity.
This report examines how commercially available location data creates operational security vulnerabilities. It argues that these vulnerabilities stem from the aggregation of ordinary location observations, which reveal information about military affiliation and habits. Significant parts of the collection, aggregation and resale of this location data, however, remain outside direct military control.
The report first examines how commercial location data can become militarily relevant. It then assesses documented cases of commercial availability, military exposure and reported hostile exploitation. Finally, it considers why this vulnerability creates a broader challenge for operational security.
II. From Commercial Location Data to Military Intelligence
Commercial data collection is not new, but the volume, variety, accessibility and direct intelligence application of commercial data have expanded substantially.
Traditionally, due to the substantial physical and financial resources required, the primary means for national intelligence agencies to acquire large volumes of behavioural and location information was state surveillance. However, the rise of commercial ecosystems, mobile applications and free online services monetised through behavioural data harvesting has fundamentally transformed this dynamic (Berrefjord & Bjørstad, 2025).
Today, large volumes of potentially sensitive data are compiled, aggregated and sold commercially, turning information that could require dedicated intelligence collection into a readily purchasable commercial commodity. In this context, national security and intelligence agencies are increasingly using Commercially Sourced Intelligence (CSINT) and Commercially Available Information (CAI), as they provide valuable information while often facing fewer constraints than traditional intelligence collection (Berrefjord & Bjørstad, 2025).
For location data specifically, the relevant shift is therefore not simply the growth of digital location traces, but the development of a commercial ecosystem that makes individual movements persistent, searchable, saleable and usable for intelligence purposes.
The main security value of commercial data lies in its aggregation, rather than in single isolated observations. While browsing the web, using apps and posting online, individuals leave continuous digital footprints of their activities (Preti et al., 2026). On its own, a single location ping may reveal little; however, repeated location observations can establish where a device regularly appears, how it moves, and which locations it connects to.
When location histories are combined with other commercial or publicly available information, an otherwise anonymous device may be linked to a person, organisation or sensitive location. Operational information can thus emerge through inference, and so commercial data does not need to contain labels such as soldier or military operation to reveal military information.
In a military context, aggregated location histories can generate several levels of inference.
Data brokers package and sell datasets that identify active-duty members of the military, veterans, their families and acquaintances, as well as sensitive information about them, including health, political affiliation and religious practices (Sherman et al., 2023). Location data can add another layer to these profiles, since if a device frequently appears inside a military installation and later travels to the same residence location, then observers could infer the user’s identity, daily routine and precise workplace and address (Brennan et al., 2023).
Changes in these established patterns may also provide further indication of military activity. For example, a cluster of military-affiliated devices moving to a new area or a significant deviation from normal routines could indicate mobilisation, exercises or deployments. In general, military significance can emerge from the relationship between otherwise ordinary pieces of information, rather than from any single sensitive disclosure.
About the author
Isabel Marino is a Defence & Security Trainee at Finabel.