A German security researcher showed that abandoned ENUM DNS infrastructure could be re-registered and used to intercept or reroute SIP-based telephone traffic for the country codes of St. Helena, Ascension Island, and the British Indian Ocean Territory. By taking control of the deleted domain enum.org.uk, which was still referenced by one of the authoritative nameservers for those ENUM zones, she gained the ability to answer ENUM lookups for affected numbers and potentially perform a man-in-the-middle attack on call routing.
After initially seeing no activity, the researcher later observed more than 100,000 ENUM queries, largely originating from the United States, including lookups for numbers associated with Diego Garcia and Ascension Island, where U.K. and U.S. military facilities are located. The findings indicate that at least one U.S. telecom provider was still relying on the stale ENUM path, creating a risk that calls involving military personnel and their families could have been exposed; after disclosure efforts stalled, the U.K. NCSC assumed control of the domain and parked it, while the case also highlighted broader decay across legacy country-specific ENUM deployments.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
In March, the UK National Cyber Security Centre took interest in the issue and had the domain transferred away from Lina. The recovered domain is now parked on a blank country page, ending her control over the affected ENUM responses.
Lina tried to report the issue through responsible channels but encountered bureaucratic obstacles. RIPE NCC said it was not the competent authority and referred her to the ITU-T, while British authorities initially did not respond.
In the later post-mortem, the researcher said roughly 400,000 ENUM queries had been accidentally collected over about six months, nearly all tied to Diego Garcia and Ascension Island. The source says many resolver IPs were predominantly American and corresponded to military bases, indicating broader exposure than initially described.
About six months later, Lina observed more than 100,000 ENUM queries for numbers on Diego Garcia and Ascension Island. Most queries came from the United States, indicating that at least one U.S. telecom provider was still attempting to route calls through ENUM for those territories.
After taking control of the domain, Lina monitored the infrastructure and saw no ENUM traffic for St. Helena within one day. This suggested the abandoned setup might be unused, at least initially.
Lina found that enum.org.uk, a deleted nameserver domain for the ENUM zones of St. Helena, Ascension Island, and the British Indian Ocean Territory, was available and re-registered it. This gave her the ability to answer ENUM queries for those territories and created the conditions for call interception or rerouting via attacker-controlled SIP infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyberveille.ch
Open sourceheise.de
Open sourcelina.sh
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.