Acting Secretary of the Navy Hung Cao warned that adversaries are conducting a coordinated, multi-domain campaign against the Department of the Navy, targeting service members, civilian personnel, and military installations. The warning says the threat environment has intensified since Operation Epic Fury against Iran and now includes cyber harassment, doxing, suspicious social media activity, phishing and impersonation, drone surveillance, ground-level surveillance, and probing of installation security measures.
Navy officials said the incidents are not isolated, but part of a deliberate effort to gather intelligence, test defenses, disrupt operations, and intimidate personnel. The notice also said hostile activity appears to be escalating from online targeting and surveillance toward direct action, including attempted attacks on access control points and coordinated testing of security responses, and urged personnel and families to tighten social media privacy, limit exposed personal information, and report suspicious cyber or physical activity to NCIS, base security, force protection offices, the Marine Corps Eagle Eyes program, or local law enforcement.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Former Secretary of the Navy John Phelan issued an earlier administrative message in April recommending improved cyber hygiene amid Operation Epic Fury. Hung Cao's later warning said the threat environment had evolved beyond that earlier guidance.
Acting Secretary of the Navy Hung Cao issued an administrative message warning that adversaries are conducting a coordinated, multi-domain campaign against Department of the Navy service members, civilians, and installations. The warning said the activity includes cyber harassment, doxing, drone surveillance, ground surveillance, physical attacks, and probing of security measures, and urged personnel to strengthen privacy and report suspicious activity.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedefensescoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.