Menu
Browse

Cyber Incident Victim: United States Army

Date

Jul 2026

Location

United States of America

Status

Resolved

Updated

2026-08-11 00:24

Timeline
Occurred
Undetermined
Discovered
Undetermined
Disclosed
Jul 2026
Resolved
Jul 2026
Summary

U.S. Army subdomains oil.army.mil and ai2c.army.mil were defaced via a 404 hijacking that displayed pro‑Kurdish messages, insults to President Donald Trump and Ambassador Tom Barrack, and a signature reading “Kurdish sr was here.” The compromise exploited error‑handling on WordPress sites hosted on a third‑party platform, allowing attackers to control content shown on missing pages without altering core site functionality. After discovery by researcher Ronald Lovelace, officials took the pages offline, secured them, and began an investigation into how the intrusion occurred and whether it extends beyond the defacement.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 6, 2026, cybersecurity researcher Ronald Lovelace noticed that the 404 error pages for two U.S. Army subdomains, oil.army.mil and ai2c.army.mil, displayed unauthorized messages that denounced President Donald Trump, criticized Ambassador Tom Barrack, and proclaimed “FREE KURDISTAN” along with a signature reading “Kurdish sr was here.” The defacement was the result of a 404 hijacking technique that altered the error‑handling behavior of the sites, allowing attackers to control what users saw when a page was not found rather than compromising the main content. Lovelace reported the findings to Army officials and to CyberScoop, which confirmed the presence of the messages on the error pages. Both affected sites were running on WordPress platforms hosted on Microsoft cloud infrastructure, though the exact method used to gain edit access to the error pages remained unknown at the time of discovery. The researcher noted that the defacement appeared across multiple subdomains, suggesting a broader reach than a single‑path compromise, but many other Army websites continued to show normal 404 pages.

Cyber Incident Image

Following the disclosure, the U.S. Army took the compromised subdomains offline after CyberScoop requested comment, and an Army spokesperson stated that the pages were hosted on a legacy third‑party platform that is not connected to the Army’s enterprise network. The spokesperson said technical teams had taken immediate action to mitigate the issue, secured the affected pages, and that incident response by Army cyber investigators remained ongoing. The Army emphasized that it takes all cyber incidents seriously and is actively investigating to enforce its cyber defense and network security standards. It was not yet clear whether the legacy platform would be patched or discontinued, and the spokesperson noted that the full scope of the intrusion, including whether it extended beyond the error pages, was still under investigation. The defacement messages did not appear to affect the core functionality of the sites, and the rest of the Army web presence remained accessible.

The incident evoked earlier episodes of Army website defacement, most notably in 2015 when the Syrian Electronic Army compromised the Army’s main home page and the Department of Defense’s U.S. Strategic Command, prompting temporary shutdowns of those sites. The Kurdish separatist movement has fought for decades to establish an independent nation, and defacing government websites has long been a popular tactic among Kurdish hacktivists. President Trump and Ambassador Barrack had previously drawn criticism from Kurdish supporters for perceived support of a Syrian government military campaign in Kurdish‑majority areas. Despite the references to Kurdistan in the messages, the identity of the perpetrators remained unknown, and no group claimed responsibility. The Army continued to investigate how the attackers gained the ability to edit the error pages, whether the breach originated internally or through a third party, and whether other subdomains might be affected. As of the latest statements, the investigation was ongoing and no further details about the attackers’ motives or methods had been released.

Sources
Sources available to members
1 source