See more of Dutch Brief in your Google search results
Sharing a holiday trip with friends and family sounds harmless enough. For soldiers, it can be a good deal less wise. Dozens of military personnel could be followed in precise detail, to their homes, their barracks and their missions abroad, through the popular Dutch travel app Polarsteps, an investigation has found. The Dutch defence ministry has now placed the app on a blacklist.
What the investigation found
The investigative platform Follow the Money (FTM) revealed that a weakness in Polarsteps, an app on which people log and share their journeys, allowed the data of millions of users to be collected. Among them were dozens of soldiers, from the Netherlands and abroad.
Investigators could reconstruct a lot of detail from the data. Even when a service member used a name other than their own, FTM was able to identify them from the data and follow them, establishing where they lived, where they worked and when they were there. Reporters tracked personnel from every branch of the Dutch armed forces to barracks in the Netherlands, and to NATO bases and training grounds elsewhere in Europe. They were also able to identify and follow soldiers from the United States, the United Kingdom, France and Belgium, and even to expose the movements of one military transport. In one case, a soldier seen on holiday in Austria one summer could be tracked months later to a location abroad.
And the mechanism was not even sophisticated hacking. FTM said it was able to pull the data of millions of users through the app’s programming interface (its API, the channel through which apps share data), and that some users, after a trip, did not switch off their GPS location, so their whereabouts remained visible afterwards.
SPONSORED
You’re overpaying your accountant. And they still don’t call you back.
Neno gives you a dedicated bookkeeper, automated admin, real-time financial insights and a free business bank account. Everything your business needs, in one place.
No chasing. No surprises. No unnecessary costs.
Defence’s response
After FTM put its questions to the armed forces, the defence ministry decided to place Polarsteps on what it calls a “deny list”, the list of applications that may not be used on Defence devices. The app can soon no longer be installed on the armed forces’ equipment, and will be automatically removed where it is already present. On the question of private phones, the ministry declined to make concrete statements.
For Defence, this is not a new lesson. In 2018, it emerged that the movements of military personnel could be traced through the fitness app Strava, after which the then defence minister, Ank Bijleveld, said this was “not the intention” and banned the use of such apps. More recently, the director of the military intelligence service MIVD was found to have had a public account on Strava from which his home address could be worked out. That the same problem has now surfaced with a travel app shows how hard it is to keep location data from leaking out.
Polarsteps disputes the ‘leak’
Polarsteps, for its part, rejects the idea that there was a data breach in the conventional sense. The company says no private data was leaked or shared, and that the information involved was data users had themselves set to public. Even so, it has made a number of security changes, aimed in particular at preventing large-scale access to public user data through its interface, and says it has resolved the problem, with no indication that the vulnerability was misused by others.
Whether or not it meets the technical definition of a leak, a security organisation is unlikely to find that distinction reassuring: for the military, the practical result was the same, its people could be followed.




