The security risks of Dutch military work phones after yet another location data leak

Photograph of the Polarsteps app, which is now blocked on military work phones. Image taken by Aniek Wiering

Polarsteps is a travel app that lets users share their journeys, photos and locations with friends and family. At first, this may seem harmless. But in September 2026, Follow The Money discovered a major data leak involving the Dutch app. Exposing sensitive location data of millions of users worldwide, including dozens of military personnel. This was not the first time a location-tracking app raised security concerns. In 2018, Strava (a fitness tracking app) also exposed locations of military personnel. The incident raises concerns about the security of military work phones, and if it’s still realistic to keep using them this way.

Jonathan, a marine in the Dutch Corps of Marines, explains that military personnel work on a closed network called Intranet.  ‘You basically do all your work on there, and it is closed. So sensitive things can also be on it,’ says Jonathan. The level of access depends on the employee’s security classification.
 
Because of the sensitive information, military work phones are controlled and some apps are blocked. ‘If you put Snapchat or TikTok on it, the phone simply stops working.’

According to Jonathan it is not practical to completely block the apps. ‘Sometimes there is an advantage to being able to install apps. There are so many apps that could be useful, such as maps, so that we can easily create a photo route and that we have good satellite images. You need apps for that.’

Installing apps

Certified Information Security Manager (CISM) Koen Teeuwisse finds that one of the biggest risks comes from the amount of information apps can collect once users give them permission. ‘When you install an app, you’re often asked to grant access to your photos, microphone and your camera. And most people just click “yes, yes, yes” without thinking,’ says Teeuwisse.

Location data can be sensitive. Photos and videos can also contain metadata showing when and where they were taken, including GPS information. ‘It also often tracks what other apps you’re using, what you do with them and allot more, unless you explicitly state that you don’t want that.’

This means that information that seems harmless on its own can reveal sensitive details about where someone is and what they are doing.

Whitelisting as solution

According to Teeuwisse there are two ways of controlling which apps can be installed on a work phone, namely blacklisting and whitelisting.

With blacklisting, all apps are allowed until they are identified as a security risk and get banned. The problem is that a new and unknown app can still be installed before anyone has seen a risk.

Whitelisting works the other way around. Only apps that been checked and approved can be installed.  ‘Nothing is allowed, but only things on that list are permitted. You start with a very secure situation where you can do very little.’

According to research by National Institute for Research and Development in Informatics mobile phones bring major benefits to the military, such as fast communication and efficiency, but they also create significant security risks. To protect against these risks, military organisations need strong electronic and cyber security measures, as well as trainings to make personnel aware of the risks they may face.

This shows that securing military phones is not only about restricting which apps can be used, but also about making personnel aware of the risks.

According to Teeuwisse, military work phones can be made highly secure, but never completely risk-free. ‘I think it can be organised in such a way that it’s 99 percent safe.’

About The Author