Multiple U.S. Army internet subdomains, including oil.army.mil and ai2c.army.mil, were defaced in an apparent 404 hijacking campaign that replaced error pages with pro-Kurdistan and anti-Trump messages. The altered pages also referenced U.S. Ambassador Tom Barrack, while the main site content did not appear to be changed. The affected properties were tied to the Army’s Open Innovation Lab and Artificial Intelligence Integration Center.
The Army said the impacted pages were hosted on a legacy third-party platform that was not connected to the Army enterprise network, and it removed the pages while an incident response investigation continued. Independent reporting said the affected sites appeared to use WordPress and Microsoft cloud infrastructure, but the intrusion vector and scope of any broader compromise remain unconfirmed. Researchers said the messaging was consistent with Kurdish hacktivist themes, though no perpetrator has been officially identified.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. Army said the impacted pages were hosted on a legacy third-party platform not connected to the Army enterprise network, removed the affected pages, and began an ongoing incident response investigation. Officials said it remained unclear whether additional subdomains were affected or whether any deeper compromise had occurred.
Independent researcher Ronald Lovelace identified the defaced Army subdomains and reported that the affected sites were using WordPress and Microsoft cloud infrastructure. His findings also pointed to the pages being hosted on a legacy third-party platform.
Multiple U.S. Army internet subdomains, including oil.army.mil and ai2c.army.mil, displayed anti-Trump and pro-Kurdish messages on error pages in an apparent 404 hijacking campaign. The defacement appeared to affect hosted error-page content rather than core site content, and the intrusion vector was not confirmed.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.