An escalating cyber threat is placing renewed attention on the operational technology that controls essential systems across the United States, raising questions about how deeply foreign adversaries have reached into the nation’s critical infrastructure and whether those vulnerabilities have been fully addressed.
WASHINGTON — As military tensions between the United States and Iran continue to dominate public attention, another confrontation is unfolding largely outside public view—one involving the computer systems and industrial technology that help operate America’s critical infrastructure.
The threat is real, documented, and serious, making it important to separate what federal authorities have actually confirmed from claims circulating online about widespread Iranian attacks against America’s military, banking system, electrical grid, and other infrastructure.
There is currently no public confirmation from the U.S. government that Iran has successfully launched a coordinated nationwide cyberattack disabling the American electrical grid, banking system, or classified military networks. That does not mean Iranian-affiliated cyber actors have failed to penetrate or disrupt individual systems within America’s critical-infrastructure environment. Federal authorities have confirmed exploitation of operational technology and, in some cases, disruption involving U.S. critical infrastructure.
In April 2026, the Environmental Protection Agency (EPA), Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) issued a joint cybersecurity warning describing an urgent and ongoing threat involving Iranian-affiliated cyber actors targeting operational technology across U.S. critical infrastructure.
The agencies reported that American organizations were experiencing exploitation and, in some cases, disruption involving commonly used operational technology. Drinking-water and wastewater systems were specifically identified among the affected environments, making the distinction between traditional cyberattacks and attacks involving operational technology particularly important.
Operational technology, commonly known as OT, is different from the traditional information technology systems used for email, documents, websites, and business applications because OT interacts directly with physical equipment and industrial processes.
Programmable logic controllers, or PLCs, are specialized industrial computers capable of controlling or monitoring equipment such as pumps, valves, motors, treatment processes, manufacturing machinery, and other physical systems. A compromise involving traditional corporate information technology can result in stolen data or disrupted business operations, while a compromise involving operational technology can potentially reach the physical processes upon which communities and industries depend.
The federal government’s warning therefore concerns something considerably more consequential than ordinary computer hacking because the systems being targeted can extend beyond digital information and into the technology responsible for operating essential physical infrastructure.
IRANIAN-AFFILIATED ACTORS TARGETING INDUSTRIAL CONTROLS
The April advisory focused on Iranian-affiliated advanced persistent threat actors exploiting internet-connected programmable logic controllers across U.S. critical infrastructure.
EPA subsequently held a May cybersecurity briefing specifically addressing the active threat, describing Iranian-affiliated actors as targeting internet-exposed PLCs and affecting operational technology systems. The agency said the activity had produced real-world impacts across critical-infrastructure sectors.
That means the issue was not simply theoretical preparation for something that might happen in the future. Federal agencies had already documented successful exploitation of operational technology within critical infrastructure environments, observed real-world impacts resulting from those intrusions, and, in some cases, confirmed that the activity caused operational disruptions.
The full public scope of those incidents remains less clear because federal authorities have not released a comprehensive list identifying every affected organization, every facility involved, or every physical process associated with the compromised technology. That leaves an important gap between what federal agencies know through their investigations and what has been publicly disclosed.
AMERICA’S WATER INFRASTRUCTURE IS PART OF THE CYBER THREAT
Among the most concerning confirmed elements of the federal warning is the inclusion of drinking-water and wastewater systems, which represent some of the nation’s most fundamental lifeline infrastructure.
Homes, hospitals, fire departments, businesses, schools, manufacturing facilities, power generation operations, and countless other parts of society depend upon reliable access to water. A serious disruption involving water infrastructure therefore has the potential to extend far beyond the affected utility and create consequences across multiple interconnected sectors.
The EPA explicitly warned that cybersecurity threats against water infrastructure can affect not only utilities themselves but also the communities, businesses, hospitals, and other critical-infrastructure sectors that rely upon those services.
The vulnerability of water infrastructure has become a growing national cybersecurity concern because the United States does not operate one centralized water network protected by a single cybersecurity architecture. Thousands of individual public water systems operate across the country, ranging from major metropolitan utilities with substantial resources to small community systems with limited staffing and cybersecurity budgets.
Industrial equipment within these environments may remain operational for years or even decades, and systems originally designed primarily for reliability and physical process control operate within environments connected to modern digital networks. This combination of older industrial technology and newer forms of connectivity can create security challenges that were never envisioned when some of the equipment was originally designed or installed.
When operational technology becomes reachable through the public internet without adequate security controls, attackers gain another potential pathway into infrastructure that was never intended to function like an ordinary internet-connected computer network. The April warning demonstrated that adversaries are actively searching for and attempting to exploit those pathways, reinforcing the need to secure the technology responsible for delivering one of the most essential resources upon which American communities depend.
THE PROBLEM OF INTERNET-EXPOSED INFRASTRUCTURE
One of the hardest questions raised by the Iranian-affiliated activity is also one of the simplest: Why are industrial control systems responsible for physical infrastructure accessible from the public internet?
Remote connectivity can provide legitimate operational benefits because engineers and operators may need to monitor equipment, diagnose failures, collect telemetry, or manage geographically dispersed infrastructure. That convenience also creates significant security risks because every internet-facing industrial device can potentially become visible to attackers searching for exposed systems.
Weak passwords, default credentials, outdated firmware, inadequate network segmentation, and poorly configured remote-access systems can transform equipment intended to improve operational efficiency into a potential entry point for malicious actors. The problem also extends far beyond America’s water infrastructure.
On June 3, 2026, the NSA joined CISA and other government partners in issuing separate guidance concerning malicious cyber activity targeting internet-exposed automatic tank gauge systems. These systems are widely used across the energy, chemical, food and agriculture, and transportation sectors to remotely monitor fuel and liquid levels, temperatures, and possible leaks.
Federal authorities reported that unidentified cyber actors had compromised exposed automatic tank gauge systems and subsequently modified them through command execution. The government did not attribute that June campaign to Iran, and there is no evidence supporting such an attribution at this time.
The significance of the incident lies in what it reveals about the broader vulnerability of internet-connected operational technology across American critical infrastructure. Industrial systems responsible for monitoring or interacting with physical resources remain potential targets when they are exposed to the public internet without adequate security protections.
Iranian-affiliated cyber actors represent one documented threat operating within this environment, but they are not the only threat. The underlying vulnerability can potentially be exploited by nation-state adversaries, cybercriminal organizations, hacktivists, or other malicious actors capable of discovering and accessing inadequately secured industrial systems.
THE QUESTION OF PERSISTENT ACCESS
The immediate disruption caused by a cyberattack is only one part of the problem. Another significant concern is the possibility that attackers can establish persistent access to compromised networks and remain inside those environments beyond the initial intrusion.
In an October 2024 joint cybersecurity advisory, the NSA, FBI, CISA, and international partners warned that Iranian cyber actors had used brute-force and credential-access techniques against critical-infrastructure organizations. Successful credential theft can provide attackers with access through legitimate accounts, potentially making malicious activity more difficult to distinguish from authorized network activity.
This changes the nature of an intrusion because an attacker does not necessarily need to deploy destructive malware or immediately disrupt operations. Access can potentially be maintained, expanded, or used to gather information before defenders recognize that an unauthorized actor has entered the environment. Federal authorities warned that this type of activity could enable persistent access to sensitive systems.
Finding evidence of an intrusion therefore does not automatically reveal the full extent of the compromise. Investigators must determine how the attackers initially gained access, which accounts and credentials were compromised, what systems were reached, whether additional credentials were obtained, whether persistence mechanisms were established, whether information was removed, and whether the attackers moved laterally into other portions of the network.
Answering those questions is critical to understanding whether an organization has successfully contained an intrusion and eliminated every known point of unauthorized access. Until that process is completed, one of the most important questions facing investigators and infrastructure operators remains whether the attackers have actually been completely removed from the compromised environment.
THE ELECTRICAL GRID
The possibility of Iranian cyber operations against the American electrical system has understandably generated significant concern because the energy sector represents one of the most consequential components of the nation’s critical-infrastructure landscape and has long been considered an attractive target for nation-state cyber actors.
At this time, there is no publicly confirmed evidence that Iran has successfully launched a nationwide cyberattack that disabled the U.S. electrical grid during June or July 2026. That does not diminish the broader cybersecurity challenges facing the energy sector or the potential consequences associated with attacks against the systems responsible for generating, transmitting, and distributing electricity.
America’s electrical system is extraordinarily complex, consisting of power generation facilities, transmission networks, distribution utilities, substations, industrial control systems, communications infrastructure, and numerous private and public operators spread across enormous geographic areas. Because of this complexity, a cyber incident affecting an individual utility, facility, or technology provider is not equivalent to compromising the entire national electrical grid.
That distinction is critical when evaluating claims involving cyberattacks against American energy infrastructure. Any assertion that Iran successfully hacked the U.S. power grid would require evidence establishing what infrastructure was compromised, where the intrusion occurred, which systems were affected, whether attackers obtained access to operational technology, and whether the incident resulted in an actual disruption of electrical service.
Without evidence establishing those facts, such a claim should not be made. The documented reality remains that Iranian-affiliated cyber actors have targeted American critical infrastructure and operational technology, while the energy sector continues to face cybersecurity threats from multiple nation-state and criminal actors capable of exploiting vulnerabilities within the interconnected systems upon which the nation’s electrical infrastructure depends.
THE BANKING AND FINANCIAL SYSTEM
Similar caution is necessary when discussing America’s financial infrastructure. Iranian cyber actors have a documented history of targeting financial organizations, and financial institutions remain high-value targets for nation-state and criminal cyber operations because of their importance to the economy and the enormous volume of financial transactions and sensitive information they process.
There is currently no public confirmation that Iran successfully disrupted the U.S. banking system on a nationwide scale during June or July 2026. The financial dimension of the confrontation, though, extends beyond attempts to directly compromise American banks and includes broader efforts by the United States to disrupt Iranian financial networks, digital-asset infrastructure, sanctions-evasion mechanisms, exchange houses, front companies, and international procurement operations.
On June 2, the U.S. Treasury Department sanctioned Iran’s largest digital-asset exchange, Nobitex, along with three other Iranian digital-asset exchanges. Treasury stated that Nobitex had facilitated transactions linked to the Islamic Revolutionary Guard Corps, including wallets associated with IRGC-affiliated ransomware actors. The action highlighted the important role that cryptocurrency and digital-asset infrastructure can play within the broader financial networks connected to state-linked and malicious cyber activity.
Treasury took additional action on June 5 against a network accused of using front companies, foreign bank accounts, and shipping operations to conceal hundreds of millions of dollars in Iranian-origin petroleum trade. On June 10, Treasury sanctioned additional individuals and entities accused of supporting weapons procurement for the IRGC and Iran’s Ministry of Defense and Armed Forces Logistics.
Taken together, these actions illustrate a financial confrontation that extends across traditional banking channels, cryptocurrency platforms, international trade, sanctions-evasion networks, and procurement operations. While none of these actions establishes that Iran has successfully compromised the U.S. banking system, they demonstrate how financial infrastructure and cyber activity can intersect within a much broader network of national-security concerns involving the movement of money, digital assets, technology, and resources across international borders.
THE MILITARY AND NATIONAL SECURITY QUESTION
Claims involving successful Iranian penetration of classified U.S. military networks require an even higher evidentiary standard because of the sensitivity of the systems involved and the significant national-security implications that would accompany such a compromise.
The United States publicly identifies Iran as a significant cyber and counterintelligence threat, and Iranian government-linked actors have conducted cyberespionage and other malicious operations against American interests. There is currently no public confirmation establishing that Iran successfully compromised classified U.S. military command-and-control networks during June or July 2026.
The absence of public confirmation does not establish whether attempts have occurred or whether classified incidents exist. It means there is currently no publicly available evidence sufficient to responsibly state that Iranian cyber actors successfully penetrated these classified military systems.
For the public, understanding the difference between a cyber threat, an attempted intrusion, a successful network compromise, and a successful disruptive attack is critical because these terms represent fundamentally different levels of cyber activity and should not be treated as interchangeable.
A threat actor can target an organization without successfully gaining access, while an attacker who gains initial access may never reach sensitive systems. An attacker who compromises sensitive systems may obtain information or establish persistence without disrupting physical operations, and a disruptive cyberattack affecting an individual facility does not necessarily indicate that an entire critical-infrastructure sector has been compromised.
Each scenario represents a different level of severity and requires its own supporting evidence. Maintaining those distinctions is particularly important when discussing military and national-security systems, where unsupported claims of a successful compromise can create an inaccurate picture of both the capabilities of an adversary and the actual security condition of U.S. defense networks.
WHAT JUNE AND JULY 2026 ACTUALLY SHOW
As of July 2026, the publicly documented picture is serious but more precise than many of the claims circulating online. The United States entered June and July with an urgent Iranian-affiliated cyber threat against critical infrastructure already publicly documented by federal agencies.
American organizations had experienced exploitation involving operational technology, with some organizations also experiencing disruption. Drinking-water and wastewater systems were specifically included in federal warnings, while Iranian-affiliated actors had demonstrated interest in internet-exposed programmable logic controllers capable of interacting with physical equipment and industrial processes.
Federal authorities had also previously documented Iranian cyber actors using brute-force and credential-access techniques capable of providing persistent access to critical-infrastructure networks, creating concerns that extend beyond the immediate consequences of a single intrusion.
At the same time, separate malicious actors continued targeting exposed industrial technology across sectors including energy, chemical production, food and agriculture, and transportation. Although those separate incidents should not be attributed to Iran without supporting evidence, they reinforce a broader national cybersecurity problem involving the continued exposure of internet-connected operational technology across multiple critical-infrastructure sectors.
What has not been publicly established is equally important. There is no confirmed nationwide Iranian shutdown of America’s electrical grid, no confirmed Iranian disruption of the national banking system, and no publicly confirmed Iranian compromise of classified U.S. military command-and-control networks during June or July 2026.
Those distinctions must remain clear because documented Iranian-affiliated cyber activity against American critical infrastructure is serious enough to warrant public attention without attributing unconfirmed attacks to Iran or overstating what the available evidence establishes.
THE QUESTIONS THE PUBLIC STILL DESERVES ANSWERED
The most difficult part of this story is not necessarily what federal authorities have disclosed, but what remains unknown about the full scope of the Iranian-affiliated activity and the condition of the critical-infrastructure environments that were affected.
Significant questions remain about how many American critical-infrastructure organizations were affected by the operational-technology campaign, which sectors experienced confirmed exploitation, how many facilities suffered actual disruption, and what physical processes were connected to the compromised programmable logic controllers.
Questions also remain about how long unauthorized access may have existed before being discovered, whether attackers were able to move beyond the initially compromised devices, whether credentials or additional access mechanisms were established elsewhere within affected networks, and whether all identified attackers have been completely removed from those environments. The number of internet-exposed industrial controllers that remain accessible and potentially vulnerable today also remains an important cybersecurity concern.
The public record does not currently provide comprehensive answers to all of these questions. Some information may be withheld for legitimate cybersecurity, investigative, operational, or national-security reasons, particularly when disclosing technical details or identifying vulnerable facilities could create additional risks or provide useful information to malicious actors.
Still, the absence of a complete public accounting means Americans do not yet know the full extent of the infrastructure exposure federal agencies have already acknowledged. Protecting sensitive technical and operational information is necessary, but the public also has a legitimate interest in understanding the overall scale of the threat, the progress being made to secure affected systems, and whether the vulnerabilities that allowed these intrusions to occur are being systematically addressed across the nation’s critical infrastructure.
THE LARGER NATIONAL SECURITY PROBLEM
The documented Iranian-affiliated activity also exposes a larger national-security problem involving the security of America’s interconnected critical infrastructure.
Removing unnecessary internet exposure from industrial control systems can eliminate one potential attack path, but it does not make operational technology immune from compromise. Sophisticated cyber actors can pursue multiple avenues into protected environments, including stolen credentials, compromised remote-access systems, vulnerable virtual private networks, third-party vendors, supply-chain relationships, infected engineering workstations, misconfigured network infrastructure, and lateral movement from previously compromised information-technology networks.
Strong multifactor authentication, network segmentation, credential rotation, continuous monitoring, timely vulnerability remediation, and properly secured remote access can significantly reduce risk, but no individual cybersecurity control can guarantee that a determined adversary will never gain access. Effective critical-infrastructure defense therefore depends upon multiple overlapping layers of security designed to prevent intrusions, detect unauthorized activity, restrict an attacker’s ability to move through a network, and contain a compromise before it reaches systems capable of affecting physical operations.
This is particularly important when operational technology is involved. An attacker who compromises an organization’s business network may attempt to move laterally toward more sensitive environments, while compromised vendor credentials or legitimate remote-management tools can potentially provide another route around defenses intended to isolate industrial systems.
Cybersecurity is therefore not solely a matter of identifying the adversary or disconnecting individual devices from the public internet. It requires understanding the complete attack surface surrounding critical infrastructure and recognizing that sophisticated adversaries will search for alternative pathways when the most obvious route is unavailable.
Iran represents one documented cyber threat within that environment. Russia, China, North Korea, ransomware organizations, financially motivated cybercriminals, hacktivists, and other malicious actors present additional threats with different capabilities, resources, and objectives.
The identity of an attacker remains critical for intelligence, attribution, diplomacy, national defense, sanctions, and law enforcement. At the same time, every successful intrusion can expose weaknesses that another adversary may attempt to exploit through entirely different methods.
The larger national-security challenge is therefore not simply preventing one country or one group from reaching American critical infrastructure. It is building resilient systems capable of defending against multiple adversaries, multiple attack paths, and an evolving threat environment in which the next intrusion may not resemble the one that came before it.
TRJ VERDICT
The evidence so far does not support claims that Iran is currently shutting down America’s national electrical grid, crippling the U.S. banking system, or controlling classified military networks. The documented reality is serious enough without exaggeration.
U.S. federal agencies have publicly confirmed an urgent and ongoing Iranian-affiliated cyber threat involving the exploitation of programmable logic controllers across American critical infrastructure. Organizations have experienced exploitation, with some also experiencing operational disruption, and drinking-water and wastewater infrastructure has been specifically identified as part of the threat environment.
At the same time, federal authorities continue confronting a broader security problem involving internet-exposed operational technology across American infrastructure. The June warning involving compromised automatic tank gauges demonstrates that malicious actors are actively finding and manipulating exposed industrial systems in sectors extending from energy and chemicals to transportation and agriculture, although federal authorities did not attribute that particular campaign to Iran.
The question Americans should be asking is therefore not whether every alarming claim circulating online is true, because many of those claims are not established by the available evidence. The harder question is how adversaries are gaining access to industrial technology connected to critical infrastructure and whether the security measures surrounding those systems are sufficient to detect, contain, and eliminate sophisticated intrusions.
The United States has spent decades connecting physical infrastructure to complex digital networks. Those connections have delivered enormous benefits in efficiency, monitoring, automation, and remote management, but they have also expanded the potential attack surface available to hostile governments and cybercriminal organizations. Direct internet exposure represents one potential pathway, while compromised credentials, vulnerable remote-access infrastructure, third-party vendors, supply-chain relationships, compromised information-technology networks, and other intrusion methods can provide additional routes into sensitive environments.
Water, electricity, fuel, transportation, communications, financial services, healthcare, manufacturing, and government operations depend upon digital systems that most Americans never see. Protecting those systems is no longer simply an information-technology responsibility; it is a national-security responsibility that requires layered defenses capable of preventing intrusions, detecting unauthorized activity, restricting lateral movement, and containing attackers before they can reach systems capable of affecting physical operations.
The public should be informed without being frightened by unsupported claims. The government must protect sensitive technical and operational details without allowing legitimate secrecy to become a substitute for accountability. Critical-infrastructure operators must treat unnecessary internet exposure, weak authentication, outdated technology, insecure remote access, inadequate network segmentation, and insufficient monitoring as security risks that can potentially carry consequences extending beyond computer networks and into physical infrastructure.
What is publicly known already warrants serious attention. Iranian-affiliated cyber actors have targeted and exploited technology operating within America’s critical-infrastructure environment, and federal authorities have acknowledged that some of this activity resulted in disruption.
The full extent of that access, the identities of every affected organization, the duration of any unauthorized presence, and the complete status of remediation remain outside the public record. Until those questions are answered, vigilance should not be confused with speculation, and the absence of a nationwide catastrophe should never be mistaken for the absence of a serious and continuing threat.
TRJ CYBEROPS DEPARTMENT ADVISORY
The TRJ CyberOps Department reminds individuals, businesses, organizations, and critical-infrastructure operators that cyber threats can originate from anywhere and often emerge with little or no warning. Regardless of whether an attack is attributed to a nation-state, criminal organization, hacktivist group, or independent threat actor, maintaining strong cybersecurity practices and remaining prepared for potential incidents is always the best course of action.
Systems should be kept updated and properly secured, important data should be backed up through reliable and protected methods, multifactor authentication should be enabled wherever possible, and unusual network or account activity should never be ignored. Organizations responsible for operational technology and critical infrastructure should maintain appropriate network segmentation, secure remote-access systems, monitor for unauthorized activity, and have tested incident-response and recovery procedures in place.
Cybersecurity preparedness cannot begin after an attack has already occurred. Staying vigilant, maintaining layered defenses, and preparing for potential disruptions can significantly reduce the impact of an intrusion, regardless of where the threat originates.
— TRJ CyberOps Department
Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), Department of Energy (DOE), Environmental Protection Agency (EPA), Transportation Security Administration (TSA), Department of Transportation (DOT), and U.S. Department of Agriculture (USDA) — “CISA and Partners Urge Hardening Automatic Tank Gauge Systems,” June 2, 2026. The joint fact sheet confirms malicious cyber activity targeting U.S.-based automatic tank gauge systems used across the energy, chemical, food and agriculture, and transportation sectors. It states that threat actors compromised internet-exposed ATG systems and subsequently modified them through command execution; the U.S. government had not attributed the activity to a nation-state or specific threat actor group. (Free Download)
Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), and U.S. Cyber Command–Cyber National Mission Force (CNMF) — “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” April 7, 2026, Product ID AA26-097A. The joint cybersecurity advisory confirms that Iranian-affiliated APT actors targeted internet-facing operational technology and that the activity caused PLC disruptions across several U.S. critical-infrastructure sectors, resulting in operational disruption and financial loss. The advisory identifies government services and facilities, water and wastewater systems, and energy among the affected sectors. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified




Very nice.
Thank you very much. 😎