US Army Websites Defaced with Pro-Kurdish Sentiments
Multiple U.S. Army internet subdomains were defaced in a 404 hijacking campaign, with error pages on two U.S. Army websites – oil.army.mil and ai2c.army.mil – displaying defacement messages visible to users. The messages denigrated President Donald Trump and United States Ambassador to Türkiye Tom Barrack, called to “FREE KURDISTAN,” and included another line reading “Kurdish sr was here.”
Background on the Affected Websites
One of the websites, oil.army.mil, belongs to the Army’s Open Innovation Lab, a test bed for software and cyber capabilities established in 2020. The other belongs to the Artificial Intelligence Integration Center, established in 2019 to integrate AI technologies into the Army and train personnel on emerging technologies.
Screenshot of 404 error pages for oil.army.mil, defaced with pro-Kurdistan comments and insults to President Donald Trump and White House advisor Tom Barrack. Screenshot of 404 error pages for ai2c.army.mil, defaced with insults to President Donald Trump and White House advisor Tom Barrack and a sign off from “Kurdish sr.”
Discovery and Response
The defacements were initially discovered by independent cybersecurity researcher Ronald Lovelace, who notified U.S. Army officials and CyberScoop. The affected sites run on WordPress and Microsoft cloud infrastructure. It’s not clear how long the subdomains have been compromised or whether other subdomains are affected.
Lovelace said, “It raises the severity a decent amount because it shows it’s a bit deeper than just one single path” that’s being corrupted. However, while the defacement’s presence across multiple subdomains suggests the potential for “broad reach,” it doesn’t appear to affect all Army websites, with many still showing normal 404 error pages.
Investigation and Aftermath
The websites were taken offline after CyberScoop reached out to the Army for comment. An Army spokesperson told CyberScoop that the pages were hosted on a legacy third-party platform that is not connected to the Army’s enterprise network and have since been removed.
Army spokesperson Maj. Sean Minton said in a statement, “We are aware of unauthorized defacements on the error pages of oil.army.mil and ai2c.army.mil, which are hosted on a legacy, non-authoritative platform. Technical teams took immediate action to mitigate the issue, and the affected pages have been secured. The Army takes all cyber incidents seriously and is actively investigating this matter to enforce our strict cyber defense and network security standards.”
Possible Motivations Behind the Defacement
It’s not clear who is behind the defacement beyond the references to Kurdistan— a geographic region spanning parts of Turkey, Iraq, Iran, and Syria that is home to more than 30 million Kurdish people. The Kurdish separatist movement has fought for decades to establish an independent nation, and defacing government websites has long been a popular tactic among Kurdish hacktivists.
Trump and Barrack drew the ire of Kurdish proponents earlier this year for seeming to back a Syrian government military campaign to reestablish federal control over Kurdish-majority lands. It’s not the first time that Army websites have been seemingly compromised by foreign hackers. In 2015, Army officials had to temporarily shut down major websites, including the Army main home page and the Department of Defense’s U.S. Strategic Command, after hackers from the Syrian Electronic Army defaced them.
Source: CyberScoop