Open-Source Intel Makes U.S. Troops an Easier Target for Iran

1 hour ago 1
Chattythat Icon

Iran is reading American service members’ social media feeds to deadly effect. The fact is that not all intelligence must be gleaned from secret, closed sources for it to be effective, and Tehran has made use of public and open-source data to target U.S. forces with psychological and kinetic attacks. Until the Pentagon updates and enforces its policies on social media posting and personal device security, American servicemembers will be sitting ducks.

Admiral Brad Cooper, the commander of CENTCOM, warned in a letter last month to U.S. forces that Iran is using social media posts from personnel, such as footage of U.S. bases, to improve its lethality. For example, a video of soldiers running for shelter during Iranian strikes helped Iran perform a battle damage assessment of their strikes, including their precision, and understand base layout for future attacks.


Iran has long exploited open-source data to target U.S. forces and allies. Two years ago, Iran doxxed 2,200 Israel Defense Forces personnel relying exclusively on open-source data. In April 2026, the Department of the Navy warned service members that unnamed cyber adversaries (obviously referring to Iran) are reaching out on social media and conducting phishing attacks, urging sailors to turn on privacy settings and refrain from posting on social media. The same month, Iranian hacker group Handala sent threatening WhatsApp messages to U.S. troops and published the supposed personal information of 2,300 U.S. service members stationed in the Persian Gulf.

Open-source data is broader than just Instagram and Facebook. Iran exploits data breaches to collect information and identify and send text messages to former Israeli defense personnel to threaten them and to attempt to recruit them for espionage purposes.

Iran is exploiting Signaling System 7 (SS7), an older telecom protocol for roaming, to identify devices with U.S. SIM cards, according to threat intelligence platform Mobile Surveillance Monitor. Using SS7, Iran was reportedly able to pinpoint hotels that housed U.S. personnel and contractors.

Iran can also simply buy data for its malicious campaigns. CENTCOM stated in a letter to Sen. Ron Wyden (D-OR) that it has been warned that Iran may have used commercially available location data used by digital advertisers to “target and surveil” U.S. personnel. While the phone numbers behind advertising IDs are anonymized, Iran could use them to track devices in specific areas such as military bases. The Pentagon conceded that these IDs are not yet disabled by default on government-issued phones.

None of these vulnerabilities should be a surprise to defense officials. A U.S. Government Accountability Office report from October 2025 found that social media posts from service members and their families or friends provide adversaries with names, ranks, and locations that can be pieced together to reveal information about U.S. force formations and operations. Wyden and his Democratic and Republican colleagues in the House and Senate sent a letter to the Pentagon’s chief information officer in May 2026 urging more secure personal data practices and blaming current vulnerabilities on the department’s “failure to prioritize this threat and implement common sense cyber defenses recommended by federal cybersecurity experts.” The House version of the annual defense bill, meanwhile, calls for the department to better understand and train personnel about how adversaries can exploit commercial technologies to identify and monitor U.S. personnel.

To curb adversarial intelligence collection opportunities, the Department of Defense (DoD) should expand operational security requirements across the force.

First, the DoD should harden government and personal devices by requiring removal of all Mobile Advertising IDs (MAIDs) on personal and DoD-distributed devices for personnel in sensitive areas. Without IDs, the locations and metadata cannot be tracked or associated with individual users and sold to adversaries posing as commercial buyers.

Next, the DoD should create and enforce stringent policies for social media posting. Personnel should be prohibited from uploading unofficial photos and videos of military facilities or that otherwise relate to their roles and should limit the amount of information they post about their roles on platforms like LinkedIn. Government devices should have their cameras disabled or removed unless required for specific purposes, and GPS should be disabled by default. DoD should also consider providing troops with alternative devices for personal use with GPS disabled and the cameras removed.

Additionally, the DoD should monitor breached data to understand what is publicly available about all its personnel. Knowing when data is exposed will allow the DoD to identify potential threats before Iran acts and begin fixing the issue as soon as it occurs. The department can also use this information to enable mandatory password and credential rotation when information is exposed. The Pentagon should also consider encouraging or requiring additional methods of authentication, such as passkeys and biometrics, for all devices and accounts

Finally, Congress should pass regulatory reforms to transition from SS7 to new signaling technology. SS7 is an outdated system and cannot guarantee secure communications, even if new updates were to be completed. Changing the system will allow service members abroad to communicate with loved ones without leading adversaries to their location.

These measures will limit the open-source data that, at present, is readily available to Iran and other adversaries. If the DoD continues to permit unrestricted use of personal devices abroad, Iran and other adversaries will continue exploiting their vulnerabilities to locate, study, and threaten American forces.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Read Entire Article