US Army websites defaced with pro-Kurdish sentiments, insults to Trump

US Army Websites Defaced with Pro-Kurdish Sentiments and Insults to Trump

Multiple US Army internet subdomains have been defaced in a sophisticated cyber attack, displaying pro-Kurdish sentiments and insulting messages towards President Donald Trump and United States Ambassador to Türkiye Tom Barrack. The incident highlights the vulnerability of military websites to cyber threats and raises concerns about the potential for broader compromises.

The affected websites, oil.army.mil and ai2c.army.mil, are part of the Army’s Open Innovation Lab and Artificial Intelligence Integration Center respectively. These centers were established to develop and integrate cutting-edge technologies into the military, but it appears that their online presence has been compromised by hackers. The error pages on these websites displayed defacement messages, including a call for “FREE KURDISTAN” and insults towards Trump and Barrack.

This type of attack is known as a 404 hijacking, which exploits a website’s error-handling system to control the content displayed when a page isn’t found. Hackers can insert malicious content, such as defacement messages or redirects, that visitors see specifically on error pages, making it harder to detect the compromise. In this case, the affected sites run on WordPress and Microsoft cloud infrastructure, but it’s unclear how long they have been compromised or whether other subdomains are affected.

The incident has sparked concern about the potential for broader compromises within the Army’s network. While the defacement appears to be limited to error pages, it raises questions about how hackers gained access to these websites and what internal measures were in place to prevent such an attack. The US Army has taken swift action to mitigate the issue, but the investigation into this incident is ongoing.

The motivations behind this cyber attack are unclear, but it’s believed that Kurdish hacktivists may be responsible for the defacement. The region of Kurdistan has been a source of conflict and tension in the Middle East for decades, with many Kurds fighting for independence. It’s possible that hackers sympathetic to the Kurdish cause sought to draw attention to their demands by compromising government websites.

This incident is not an isolated event; US Army websites have been compromised before. In 2015, hackers from the Syrian Electronic Army defaced several major Army websites, including the Army main home page and the Department of Defense’s U.S. Strategic Command. The current incident serves as a reminder that military websites are vulnerable to cyber threats and require robust security measures to prevent such compromises.

In light of this incident, it’s essential for individuals and organizations handling sensitive information to prioritize cybersecurity and take proactive steps to protect themselves against similar attacks. This includes staying up-to-date with software patches, using strong passwords and two-factor authentication, and regularly monitoring network activity for suspicious behavior. By being vigilant and taking the necessary precautions, we can reduce the risk of cyber attacks and prevent the spread of malicious content online.


Source: CyberScoop — 2026-07-06