Drooid Logo
Back to story perspectives

Full Breakdown

Iranian Hackers Compromise Space Force Chief Master Sergeant’s Instagram Account

6/2/2026, 12:23:53 AM

Event Overview

On the evening of May 31 – June 1, 2026, the official Instagram account of Chief Master Sergeant John Bentivegna, the senior enlisted guardian of the U.S. Space Force, was hijacked for several hours. The intruders posted a series of pro-Iranian graphics, including a video that reused audio from Vietnam-War propagandist “Hanoi Hannah” and footage of the late Iranian security official Ali Larijani. The content was removed by early June 2 after Bentivegna and Space Force officials began remediation.

Background: Cyber Threats Amid the U.S.–Iran Conflict

The breach occurred during the ongoing U.S.–Iran war that began with U.S. strikes on February 28, 2026. U.S. Central Command (CENTCOM) has repeatedly warned that adversaries are exploiting commercial location data to surveil service members. In April, CENTCOM reported multiple threat alerts about such exploitation, and the Pentagon acknowledged that the Department of Defense has known of this risk for at least a decade. Earlier in the year, Iranian hackers accessed the personal email of FBI Director Kash Patel, underscoring a broader campaign of digital intimidation.

Key Figures

  • John Bentivegna – Chief Master Sergeant of the Space Force, top enlisted guardian.
  • Gen. Dan Caine – Chairman of the Joint Chiefs of Staff, credited Space Force with “non-kinetic effects” against Iran.
  • Ali Larijani – Late secretary of Iran’s Supreme National Security Council, featured in the hacked posts.
  • Trinh Thi Ngo (“Hanoi Hannah”) – Vietnam-War radio broadcaster whose audio was repurposed.
  • Sen. Ron Wyden – Oregon senator who highlighted DoD’s failure to adopt recommended cyber defenses.

Timeline of the Incident

  • May 31, 2026 (evening) – Instagram account compromised; pro-Iran videos and images posted.
  • June 1, 2026 (early hours) – Bentivegna issues a Facebook warning to colleagues.
  • June 1, 2026 (1 a.m. ET) – Space Force confirms the breach and begins recovery.
  • June 2, 2026 – All unauthorized content removed; investigation ongoing.

Official Statements & Responses

Space Force spokespersons confirmed the compromise and said the service was “working with the appropriate teams to regain access and resolve the issue as quickly as possible.” Bentivegna posted on Facebook urging personnel not to engage with any messages from the account and emphasized personal vigilance in cybersecurity. CENTCOM reiterated its earlier alerts about location-data exploitation, and the White House released edited strike footage to counter the propaganda.

Criticism & Calls for Policy Reform

Sen. Ron Wyden’s letter to the Pentagon warned that despite a decade of awareness, the DoD has not implemented “commonsense cyber defenses” such as disabling unique tracking numbers on smartphones. Former Navy Secretary John Phelan similarly cautioned that “adversary cyber actors” are targeting service members and families on social media. Cybersecurity analyst Michael Smith described Iran’s high-volume, low-impact attacks as a method to demonstrate reach across continents, urging stronger defensive measures.

Conflicting Reports & Information Gaps

Sources differ on the exact method used to gain account access; no official attribution has been confirmed, and it remains unclear whether additional senior enlisted accounts were targeted. While the Space Force acknowledges the breach, the Department of the Air Force has not commented on broader implications.

Verbatim Quotes

  • “If you receive any direct messages, requests, links, or unusual posts from that account, please do not engage with them,” — John Bentivegna, Chief Master Sergeant, Space Force
  • “Experiences like this are a good reminder that cybersecurity isn’t just an issue for organizations, it’s something we all deal with in our daily lives.” — John Bentivegna
  • “DoD has known about this serious threat for over a decade, but has failed to adopt commonsense cyber defenses that are recommended by federal agencies,” — Ron Wyden, U.S. Senator
  • “In April, then-Navy Secretary John Phelan warned sailors that “adversary cyber actors” were targeting Navy personnel and their families on social media .” — John Phelan, former Navy Secretary
  • “a way of telling people in other countries that you can still reach out and touch them even though they’re on a different continent.” — Michael Smith, DigiCert CTO

What’s Next

U.S. military leaders are reviewing cyber-hygiene protocols and considering mandatory opt-in privacy settings for service-member devices. Congressional oversight hearings on the use of commercial location data are slated for later this summer. The Pentagon has indicated that additional threat-intelligence sharing with allied cyber units will be accelerated to mitigate further propaganda-focused intrusions.