A fake U.S. Cyber Command memo circulated widely in military chats and social media, falsely claiming that apps including Uber, Snapchat, and Talabat were “compromised” and exposing servicemembers’ locations; the Department of Defense confirmed the memo was not authentic, and Uber and Snapchat said they had no indications of compromise. The incident was described as part of a broader surge of misinformation/disinformation spreading rapidly after the start of U.S. and Israeli strikes on Iran, underscoring how quickly deceptive messaging can reach operational communities during active conflict.
Separately, the UK’s National Cyber Security Centre (NCSC) warned British organizations of a heightened risk of Iranian cyberattacks amid the same regional tensions, emphasizing that Iran and Iran-linked actors likely retain capability to conduct cyber activity even with reported domestic internet disruption, and advising preparedness for DDoS, phishing, and ICS-targeting scenarios—particularly for organizations with Middle East presence or supply-chain exposure. A reported DDoS attack that disrupted Russia’s internet regulator (Roskomnadzor) and Defense Ministry websites is a distinct event (unattributed, described as multi-vector and sourced from globally distributed botnets) and does not directly substantiate the Iran-focused warning or the fake-memo campaign beyond illustrating concurrent geopolitical cyber activity.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Reporting cited security firms observing Iran-linked hackers beginning DDoS and reconnaissance activity as the regional crisis unfolded. These observations suggested the potential for further cyber escalation tied to the conflict.
Alongside its warning, the NCSC told organizations to strengthen monitoring, review internet-facing exposure and access controls, and follow guidance on DDoS, phishing, industrial control systems, and severe cyber scenarios. Critical infrastructure operators were also advised to review preparedness and consider enrolling in the NCSC Early Warning service.
The UK National Cyber Security Centre issued an advisory warning that the escalating Middle East conflict could increase cyber risks from Iranian state or Iran-linked actors. It said there was no major immediate change in direct threat to the UK, but warned the situation could shift quickly and that organizations with Middle East ties faced elevated indirect risk.
A Department of Defense official confirmed the circulating memo was not authentic, and U.S. Cyber Command said it had issued no such warning. Uber and Snapchat also said they had no indication their apps had been compromised.
A fraudulent memo falsely claiming to be from U.S. Cyber Command circulated online, in servicemember chats, social media groups, and some non-public Defense Department channels. The message alleged Uber, Snapchat, and Talabat were compromised and exposing servicemembers' locations, creating confusion despite skepticism from some recipients.
Following the start of U.S. and Israeli attacks on Iran, social media saw a broader increase in misinformation and deceptive messaging related to the conflict. This became the backdrop for later false cyber-related warnings circulating in military communities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcenextgov.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.