
Reporters say a travel diary app let strangers follow soldiers to their homes, bases, and missions.
Story Snapshot
- Journalists tracked service members across multiple NATO countries using Polarsteps trip data.
- Data reportedly included exact locations, photos, and home addresses at meter-level detail.
- The Dutch defense ministry blacklisted the app after questions from investigators.
- Polarsteps denies a breach and says only public trip data was collected.
What reporters found and why it matters
Investigators from Follow the Money said they were able to identify and track dozens of military service members through Polarsteps, a popular travel app. Their report describes trails that led to homes, barracks, and overseas missions, and spanned the Netherlands, the United States, the United Kingdom, France, and Belgium. Cybernews said the exposure covered photos, videos, and precise locations, and claimed access to about one billion location points from nearly two million trips. That scale turns a vacation diary into a live map of sensitive routines.
The danger is simple to picture. A soldier’s trip album shows where the unit assembles, where they sleep, and when they return home. A patient adversary does not need passwords if it can watch movement over weeks. The report says investigators matched faces, uniforms, and dates to nail down identities and routes. Belgian and Dutch outlets echoed that data from millions of users sat open for months, and that home addresses were easy to infer from end points. That is not a privacy oops; that is operational risk.
How the data was reachable at scale
The reporting points to Polarsteps’ own interface for developers, often called an application programming interface. Journalists said they could connect and pull names, photos, and precise coordinates from public trips. They also claimed some links kept working even after users flipped a trip to “followers only”. That behavior matters more than labels. If a once-public link still exposes old posts, a user’s attempt to hide a trail may not work as expected. Design choices become attack surfaces.
Polarsteps disputes the “data breach” label and says nothing private leaked. The company states that Follow the Money only accessed public trip data that users chose to share, that no passwords were cracked, and that private trips stayed private. That rebuttal lands on a legal line, not a safety line. A hunter does not care whether the gate was locked if the field was open. The company also says it tightened security and curbed large-scale scraping after the report. That is an implicit admission that scale changed the risk.
Defense ministries respond, and the stakes for NATO families
The Dutch Ministry of Defence blacklisted Polarsteps and moved to remove it from official devices after receiving questions from the reporters. Belgian coverage said sensitive data on Belgian military personnel was exposed for months and highlighted similar concerns. Those reactions show how ministries read the risk. You do not ban an app on a hunch. You ban it because the cost of a miss is too high. For service families, the worst case is not spam; it is a stranger on the doorstep.
American conservative values demand common sense over wishful thinking. If a tool lets anyone stitch together a soldier’s life, leaders must lock it down. The claims here are journalistic, not a court filing, and Polarsteps contests the breach framing. That caveat belongs in the record. But the facts that move policy are stronger: ministries acted, reporters traced real trails to real places, and the company adjusted its systems after the spotlight. That alignment tilts the scale toward caution.
How users and institutions can close the gap now
Service members should set profiles to private, scrub or archive old public trips, and turn off location tagging by default. Families should avoid posting travel in real time; share after returning home. Units should issue clear rules on location-sharing apps, not just on base but also off duty. Ministries should audit apps for sticky links, developer interfaces that allow bulk pulls, and privacy toggles that do not fully revoke access. Test with red teams. Assume adversaries can code.
Reporters opened a door that others might have used first in the dark. The fix cannot rely on trust. It must rely on design that shrinks the blast radius: rate limits on data pulls, short-lived links, strict access logs, and default-private settings for new users. Clear, plain warnings help too. Tell users, in one sentence, what a public trip reveals. People will choose safety when the risk is not hidden in fine print. Until then, phones will keep out-talking our best intentions.
Sources:
military.com, telegraaf.nl, nltimes.nl, nieuwsblad.be, brusselstimes.com, nos.nl, polarsteps.com, ground.news










