Drooid Logo
Back to story perspectives

Full Breakdown

U.S. Army Subdomains Defaced in Pro-Kurdistan 404 Hijacking

7/7/2026, 1:50:51 AM

Incident Overview

On Monday morning, two U.S. Army internet subdomains—oil.army.mil and ai2c.army.mil—displayed unauthorized 404 error pages that were altered to include pro-Kurdistan messages and insults directed at President Donald Trump and U.S. Ambassador to Türkiye Tom Barrack. The defaced pages showed the phrases “FREE KURDISTAN” and “Kurdish sr was here.” Both sites are hosted on a legacy, non-authoritative platform; oil.army.mil supports the Army’s Open Innovation Lab (established 2020) and ai2c.army.mil houses the Artificial Intelligence Integration Center (established 2019).

Data & Statistics

  • Affected sites: 2 (oil.army.mil, ai2c.army.mil)
  • Defacement observed: Monday morning (date not specified)
  • Exact messages displayed: “FREE KURDISTAN” and “Kurdish sr was here.”

Background: Kurdish Hacktivism and Prior Army Cyber Incidents

Kurdish separatist activists have long used website defacement to promote their demand for an independent Kurdish state covering parts of Turkey, Iraq, Iran and Syria. Their opposition to U.S. policy intensified after President Trump and Ambassador Barrack were seen as supporting a Syrian operation in Kurdish-majority areas. The Army has faced foreign-origin website compromises before, notably in 2015 when the Syrian Electronic Army forced temporary shutdowns of the Army’s main homepage and the Department of Defense’s U.S. Strategic Command.

Key Entities Involved

Maj. Sean Minton, Army spokesperson; President Donald Trump; Ambassador Tom Barrack; unidentified Kurdish hacktivists; the Army’s Open Innovation Lab (oil.army.mil); and the Artificial Intelligence Integration Center (ai2c.army.mil).

Official Army Response

Maj. Sean Minton said the Army was aware of the defacements, that technical teams acted immediately to secure the pages, and that an investigation is underway to enforce cyber-defense standards. He added that it remains unclear whether the legacy platform will be patched or retired.

Criticism & Opposition

The defacement reflects longstanding Kurdish opposition to U.S. policy perceived as supportive of Syrian government actions in Kurdish-populated regions. The messages “FREE KURDISTAN” and the targeting of Trump and Barrack illustrate the hacktivists’ attempt to draw attention to their political objectives and to protest perceived U.S. backing of military campaigns that threaten Kurdish autonomy.

Verbatim Quotes

  • “We are aware of unauthorized defacements on the error pages of oil.army.mil and ai2c.army.mil, which are hosted on a legacy, non-authoritative platform,” — Maj. Sean Minton, Army spokesperson
  • “Technical teams took immediate action to mitigate the issue, and the affected pages have been secured. The Army takes all cyber incidents seriously and is actively investigating this matter to enforce our strict cyber defense and network security standards.” — Maj. Sean Minton, Army spokesperson
  • “FREE KURDISTAN,” — Defacement message (unknown hacker)
  • “Kurdish sr was here.” — Defacement message (unknown hacker)

What’s Next

The Army’s cyber investigators continue to assess the legacy platform’s vulnerability and decide whether to patch it or migrate the sites to a more secure environment. No further defacements have been reported.