Our Troops Posted Vacation Pics — STRANGERS Followed Them Home

hand holding smartphone with glowing security lock icon
Photo: Tero Vesalainen / Shutterstock

One U.S. Space Force officer logged 46 trips in Polarsteps, the travel-diary app that draws a line on a map wherever your phone goes. He believed only approved followers could see them. Investigative reporters at the Dutch outlet Follow the Money saw all 46, along with his stops at Cape Canaveral and bases in Germany, Qatar and Hawaii, his photos, and, at the end of every trip, the same house. Military.com has now carried the findings to a U.S. audience, and the Dutch Ministry of Defence has already banned the app from every service phone it owns.

Where This Stands Right Now

  • Follow the Money identified more than 30 military personnel from the United States, United Kingdom, Netherlands, France and Belgium whose homes, bases and NATO mission movements could be traced through Polarsteps.
  • The U.S. cases included Space Force and Air Force personnel, with traceable stops at Cape Canaveral, Ramstein, Spangdahlem and Al Udeid.
  • Reporters pulled the data from the app’s publicly reachable programming interface: roughly 230 million photos and videos and GPS trails from 23 million users, including trips users believed were follower-only.
  • The Dutch Ministry of Defence blacklisted the app, saying it will be “automatically removed if it is already installed” on defense devices. Belgium reminded personnel that geolocation apps are banned near its bases.

What The Reporters Could See

Polarsteps is a vacation app. You turn it on, it plots your route, you add photos, and friends follow along. Its privacy settings let users restrict a trip to approved followers. Follow the Money found that the app’s back end did not enforce that restriction the way users assumed: trips marked private could still be pulled through the interface, and old sharing links kept working after users changed their settings. With names, profile photos and follower connections in hand, the reporters could take a Space Force officer’s account, line up 46 trips, and read off his duty stations, his travel companions and the address where every route began and ended.

The same method worked on Dutch soldiers deployed on NATO missions, whose movements between home and the mission area were visible in near real time for anyone who kept an eye on the account, and on service members who had switched their tracker on for a holiday and never switched it off.

“We Should Have Found This Ourselves”

Polarsteps disputes the word “breach.” The company says no passwords were taken, no accounts were opened without permission, and the reporters accessed data users had chosen to share. Its chief executive, Clare Jones, was blunter in conversation with the reporters: “We should not have had you guys finding this, right? We should have found this ourselves.” After the investigation the company began requiring follower approval, closed the stale sharing links, and put limits on bulk access to the interface.

Why The Pentagon Has Seen This Before

In 2018 the fitness app Strava published a global heat map of user runs that lit up the perimeters of U.S. bases in Afghanistan and Syria. The Defense Department responded with a memo warning that geolocation apps and devices “pose significant risk” to service members and missions, and banned them in operational areas. Polarsteps is the same lesson from a different direction: not a heat map of thousands of anonymous joggers, but a named individual, his rank, his base and his front door, assembled from a vacation diary.

What Happens Next

The Dutch ban is in force; Belgium has restated its own. No U.S. guidance specific to Polarsteps has been published, though the 2018 policy already covers it in operational areas. Watch for whether the Pentagon names the app, whether European privacy regulators treat the exposure as a reportable breach, and whether any of the 30-plus identified personnel go public. For anyone in uniform, or married to someone who is, the practical step is the one the Dutch took: delete it from the phone that goes to work.

Sources:

military.com, cybernews.com, nos.nl, telegraaf.nl, aa.com.tr, dutchbrief.com