CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 496

As cited

Copy frozen at (site build).

breaches incidents

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

Multiple U.S. Army websites, including oil.army.mil and ai2c.army.mil, were defaced through 404 hijacking that displayed pro-Kurdish messages and insults to President Trump and Ambassador Tom Barrack. The compromise affected error pages on legacy third-party platforms not connected to the Army's enterprise network; the affected pages were taken offline after discovery. It remains unclear how the attackers gained access to modify error pages or whether the intrusion extends beyond the visible defacement.

Why it matters: U.S. Army IT and CISO teams need to audit all legacy third-party platforms for similar 404 hijacking compromises, review error-page handling mechanisms across WordPress and Microsoft cloud infrastructure, and determine whether the breach indicates deeper network access that could pose operational risk.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

Multiple U.S. Army websites, including oil.army.mil and ai2c.army.mil, were defaced through 404 hijacking that displayed pro-Kurdish messages and insults to President Trump and Ambassador Tom Barrack. The compromise affected error pages on legacy third-party platforms not connected to the Army's enterprise network; the affected pages were taken offline after discovery. It remains unclear how the attackers gained access to modify error pages or whether the intrusion extends beyond the visible defacement.

Why it matters: U.S. Army IT and CISO teams need to audit all legacy third-party platforms for similar 404 hijacking compromises, review error-page handling mechanisms across WordPress and Microsoft cloud infrastructure, and determine whether the breach indicates deeper network access that could pose operational risk.

VendorsMicrosoftWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary