Opinion
Dutch information security professionals can be tracked on Strava too, it turns out
Until early August 2026, viceadmiral Peter Reesink, director of the Dutch military intelligence service MIVD since February 2024, had a public Strava account. For years, his cycling and running routes were visible to anyone who cared to look. From that data, journalists at de Volkskrant, as reported by NOS, could work out his home address, where he parked his camper, his holiday patterns, and his regular commute to the Frederikkazerne in The Hague, home to MIVD headquarters. This is against Defence’s own guidelines, which exist specifically to stop this sort of information reaching the public. The account has since been set to private, and Reesink has asked for it to be deleted entirely.
There is a particular irony here. At the presentation of the MIVD’s 2025 annual report, Reesink himself warned that Russia is becoming increasingly brazen in its intelligence activities. He was, at the time, still logging his own commute to a secure facility on an app anyone could open.
If this feels familiar, that is because it should. Earlier this year, a French naval officer is believed to have revealed the location of the aircraft carrier Charles de Gaulle through a logged Strava run, while it was en route to the Middle East, according to the same NOS report. Last year, Omroep Gelderland traced more than a thousand Dutch military personnel through the same app. And it goes back further than that. In 2018, Strava’s own global heatmap of user activity inadvertently exposed the outlines of military bases in Iraq, Syria and Afghanistan, along with the patrol routes running through them. Danielle Cave, a senior analyst at the Australian Strategic Policy Institute, called the resulting dataset an “open source intelligence gold mine” at the time. She was not exaggerating.
And now it turns out that more than fifty Dutch information security professionals also put their rides on Strava, out in the open, for anyone to see.
Is Strava actually a security risk?
Yes, genuinely. A training app does not need to name you to expose you. It only needs to log where you start, where you finish, and how often you take the same route. Do that for long enough and the metadata does the rest: home address, workplace, the school run, the holiday cottage, the exact week you are away. This is precisely the reasoning behind Defence’s guidelines, and precisely what Reesink’s account made irrelevant.
So why does Guardian360 run a cycling club that does exactly the same thing?
Because those fifty-plus information security professionals are the Cyber Cyclists, a group Guardian360 organises regular rides for. They log every ride on Strava, in a public club anyone can find, and new members are welcome. To be clear about what this is and is not: it is not a Guardian360 product or a paid service, it is a group of people in the industry who enjoy cycling together, and who happen to work in the field that spends its working days telling other people to think twice about what they publish online.
Because the risk was never the app, it was the mismatch
Publishing a bike ride is not automatically a security failure. It depends entirely on what you are protecting, and from whom. The director of a military intelligence service, whose daily movements connect directly to a classified facility and a threat picture that includes a state actor Reesink himself called increasingly brazen, is protecting something specific and high value. A group of information security professionals meeting on a Friday afternoon to ride a familiar loop is protecting, at most, their sprint time for the village sign and their standing on the club leaderboard. Treating both cases as the same problem, “an app revealed a location”, misses the point entirely. The app did not fail in either case. It did exactly what it was built to do. What differed was whether anyone had thought about what that meant before pressing save.
That is the actual lesson from the Reesink story, and it is a less satisfying one than “delete the app”. The useful question was never whether to share your ride. It was whether you had thought about who is watching, and why it would matter if they were.
The Cyber Cyclists have thought about it, which is precisely why their Strava data staying public is not the story here. If anything, that is rather the point of the club.
If you work in information security in the Netherlands and fancy finding out what a Friday afternoon ride with fifty like-minded people is actually like, the Cyber Cyclists club on Strava is open to join, and new riders can sign up through the Guardian360 website.
Sources
- NOS, “MIVD-directeur had openbaar account op sportapp Strava, huisadres te achterhalen”, August 2026.
- Nederlands Dagblad, “MIVD-directeur had openbaar account bij Strava: activiteiten jarenlang te volgen”, August 2026.
- ABC News, “Strava has published details about secret military bases, and an Australian was the first to know”, January 2018.