US Army Websites Defaced with Pro-Kurdish Sentiments and Insults to Trump
The US Army’s online presence has been compromised in a brazen display of cyber vandalism, as multiple subdomains were defaced with pro-Kurdish sentiments and insults directed at President Donald Trump. The incident, which was first reported by independent cybersecurity researcher Ronald Lovelace, highlights the vulnerability of even the most secure websites to 404 hijacking attacks.
Lovelace discovered that error pages on two US Army websites – oil.army.mil and ai2c.army.mil – displayed defacement messages visible to users. These messages called for “FREE KURDISTAN” and included a personal attack on President Trump, as well as a reference to Tom Barrack, the US Ambassador to Türkiye. The use of these specific targets suggests that the hackers may be motivated by a desire to draw attention to Kurdish separatist issues.
The defacement is attributed to a 404 hijacking exploit, which allows attackers to control what content is displayed on error pages rather than breaching the site’s core pages directly. This type of attack can be particularly insidious as it often goes undetected, with only the error page displaying signs of compromise. In this case, the affected sites run on WordPress and Microsoft cloud infrastructure, raising questions about the security measures in place.
The incident has sparked concerns about the potential for broad reach, given that multiple subdomains were compromised. However, the Army spokesperson emphasized that many other websites remain unaffected, with normal 404 error pages still displayed. The exact duration of the compromise and whether other subdomains are affected remains unclear at this time.
As investigations into the breach continue, one thing is certain: the US Army’s online presence has been compromised by a group or individual seeking to make a statement about Kurdish issues. This incident serves as a stark reminder that even the most secure websites can be vulnerable to cyber attacks, and highlights the need for robust security measures to prevent similar incidents in the future.
The US Army’s incident response team is working tirelessly to mitigate the issue and ensure that the affected pages are secured. While it remains unclear whether the third-party platform hosting these sites will be patched or discontinued, one thing is certain: this incident serves as a wake-up call for organizations to review their security protocols and ensure they are equipped to handle similar attacks.
Ultimately, this incident underscores the importance of staying vigilant in the face of cyber threats. As we rely increasingly on digital platforms to conduct our daily lives, it’s essential that we prioritize robust cybersecurity measures to protect against attacks like these. By doing so, we can prevent not only data breaches but also the reputational damage that comes with them.
Source: CyberScoop — 2026-07-06