Iran is studying American service members’ social media feeds to lethal impact. The actual fact is that not all intelligence should be gleaned from secret, closed sources for it to be efficient, and Tehran has made use of public and open-source knowledge to focus on U.S. forces with psychological and kinetic assaults. Till the Pentagon updates and enforces its insurance policies on social media posting and private gadget safety, American servicemembers can be sitting geese.
Admiral Brad Cooper, the commander of CENTCOM, warned in a letter final month to U.S. forces that Iran is utilizing social media posts from personnel, corresponding to footage of U.S. bases, to enhance its lethality. For instance, a video of troopers operating for shelter throughout Iranian strikes helped Iran carry out a battle harm evaluation of their strikes, together with their precision, and perceive base structure for future assaults.
Iran has lengthy exploited open-source knowledge to focus on U.S. forces and allies. Two years in the past, Iran doxxed 2,200 Israel Protection Forces personnel relying completely on open-source knowledge. In April 2026, the Division of the Navy warned service members that unnamed cyber adversaries (clearly referring to Iran) are reaching out on social media and conducting phishing assaults, urging sailors to activate privateness settings and chorus from posting on social media. The identical month, Iranian hacker group Handala despatched threatening WhatsApp messages to U.S. troops and printed the supposed private info of two,300 U.S. service members stationed within the Persian Gulf.
Open-source knowledge is broader than simply Instagram and Fb. Iran exploits knowledge breaches to gather info and determine and ship textual content messages to former Israeli protection personnel to threaten them and to try to recruit them for espionage functions.
Iran is exploiting Signaling System 7 (SS7), an older telecom protocol for roaming, to determine gadgets with U.S. SIM playing cards, in line with menace intelligence platform Cellular Surveillance Monitor. Utilizing SS7, Iran was reportedly capable of pinpoint motels that housed U.S. personnel and contractors.
Iran can even merely purchase knowledge for its malicious campaigns. CENTCOM said in a letter to Sen. Ron Wyden (D-OR) that it has been warned that Iran could have used commercially out there location knowledge utilized by digital advertisers to “goal and surveil” U.S. personnel. Whereas the cellphone numbers behind promoting IDs are anonymized, Iran may use them to trace gadgets in particular areas corresponding to army bases. The Pentagon conceded that these IDs should not but disabled by default on government-issued telephones.
None of those vulnerabilities ought to be a shock to protection officers. A U.S. Authorities Accountability Workplace report from October 2025 discovered that social media posts from service members and their households or mates present adversaries with names, ranks, and places that may be pieced collectively to disclose details about U.S. power formations and operations. Wyden and his Democratic and Republican colleagues within the Home and Senate despatched a letter to the Pentagon’s chief info officer in Could 2026 urging safer private knowledge practices and blaming present vulnerabilities on the division’s “failure to prioritize this menace and implement frequent sense cyber defenses really useful by federal cybersecurity specialists.” The Home model of the annual protection invoice, in the meantime, calls for the division to higher perceive and practice personnel about how adversaries can exploit business applied sciences to determine and monitor U.S. personnel.
To curb adversarial intelligence assortment alternatives, the Division of Protection (DoD) ought to increase operational safety necessities throughout the power.
First, the DoD ought to harden authorities and private gadgets by requiring removing of all Cellular Promoting IDs (MAIDs) on private and DoD-distributed gadgets for personnel in delicate areas. With out IDs, the places and metadata can’t be tracked or related to particular person customers and offered to adversaries posing as business patrons.
Subsequent, the DoD ought to create and implement stringent insurance policies for social media posting. Personnel ought to be prohibited from importing unofficial pictures and movies of army amenities or that in any other case relate to their roles and may restrict the quantity of knowledge they publish about their roles on platforms like LinkedIn. Authorities gadgets ought to have their cameras disabled or eliminated except required for particular functions, and GPS ought to be disabled by default. DoD must also think about offering troops with various gadgets for private use with GPS disabled and the cameras eliminated.
Moreover, the DoD ought to monitor breached knowledge to grasp what’s publicly out there about all its personnel. Figuring out when knowledge is uncovered will enable the DoD to determine potential threats earlier than Iran acts and start fixing the difficulty as quickly because it happens. The division can even use this info to allow necessary password and credential rotation when info is uncovered. The Pentagon must also think about encouraging or requiring further strategies of authentication, corresponding to passkeys and biometrics, for all gadgets and accounts
Lastly, Congress ought to cross regulatory reforms to transition from SS7 to new signaling know-how. SS7 is an outdated system and can’t assure safe communications, even when new updates had been to be accomplished. Altering the system will enable service members overseas to speak with family members with out main adversaries to their location.
These measures will restrict the open-source knowledge that, at current, is available to Iran and different adversaries. If the DoD continues to allow unrestricted use of non-public gadgets overseas, Iran and different adversaries will proceed exploiting their vulnerabilities to find, examine, and threaten American forces.
The Cipher Temporary is dedicated to publishing a spread of views onnationwide safety points submitted by deeply skillednationwide safety professionals. Opinions expressed are these of the creator and don’t symbolize the views or opinions of The Cipher Temporary.
Have a perspective to share based mostly in your expertise within the nationwide safety subject? Ship it toEditor@thecipherbrief.com for publication consideration.
Learn extra expert-driven nationwide safety insights, perspective and evaluation inThe Cipher Temporary
