Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Hacktivists Defaced Two U.S. Army Websites Using a 404 Hijacking Technique

What Happened Two U.S. Army websites had their error pages defaced with political messages, according to reporting by CyberScoop, later confirmed by SC World and TechCrunch. The affected subdomains were oil.army.mil, which belongs to the Army's Open Innovation Lab, and ai2c.army.mil, which belongs to the Artificial Intelligence Integration Center. Both sites test and integrate AI and emerging technologies for the military. They also named Tom Barrack, the current U.S. Ambassador to Turkey, and included calls for a free Kurdistan. Cybersecurity researcher Ronald Lovelace discovered the defacements and reported them. CyberScoop contacted the Army; the pages came down shortly after. An Army spokesperson confirmed incident response is ongoing, and told CyberScoop the affected sites were hosted on a legacy third-party platform.
The Attack Method SC
World identified the technique as404 hijacking, a method that exploits a website's error-handling system rather than breaking into its core infrastructure. When a visitor tries to reach a URL that doesn't exist, the server returns an error page. That error page had been replaced with the attackers' content. Lovelace noted the sites run on WordPress and Microsoft cloud infrastructure. WordPress sites are a known target for plugin-based exploits, and TechCrunch pointed out that the Army's sites relied on several plugins that can be compromised by attackers. Whether any plugins were specifically exploited here has not been confirmed. No data theft has been reported, and the Army has not publicly stated how the defacement was accomplished.
Who Did It No group has claimed responsibility
SC World noted the pro-Kurdish messaging is consistent with tactics used by Kurdish hacktivist groups and drew a comparison to a 2015 attack by the Syrian Electronic Army that defaced U.S. Army websites. Attribution remains unconfirmed. Hacktivism of this type, politically motivated website defacement, is typically intended to generate attention for a cause rather than to steal data or disrupt operations. The messages here hit multiple targets: Trump, U.S. foreign policy toward Turkey and the Kurdish question, and the Epstein files. Whether this was a coordinated operation or a single actor borrowing multiple grievances is unknown.
Broader Context This wasn't an isolated incident
Earlier this year, hacktivists targeted the U.S. Department of Homeland Security and published records on contracts enabling ICE deportation operations, according to TechCrunch. Separately, DHS confirmed a breach of one of its intelligence-sharing platforms used to pass information between federal, state, and local authorities. The Army defacement comes on top of an already active period of hacktivist and intrusion activity against federal systems.
The Strongest Counterpoint
Some will argue that framing this as a significant security incident overstates the damage. The attackers didn't penetrate core Army systems, didn't appear to exfiltrate data, and targeted what the Army itself described as a legacy third-party platform. The quick takedown shows the Army's incident response worked as intended. The problem with stopping there: the Army's Open Innovation Lab and AI Integration Center are not random government placeholders. They handle integration of AI and emerging technologies into military systems. Even a superficial compromise of any subdomain under army.mil raises legitimate questions about what else might be accessible on that same infrastructure, and whether legacy hosting arrangements create unnecessary exposure for sensitive-adjacent platforms.
What's Still Unknown
The Army has not explained how the error pages were altered. The Department of Defense did not respond to TechCrunch's request for comment. The perpetrators remain unidentified. Whether any data was accessed, even if not published, is unconfirmed. The Army's statement that the sites were on a "legacy third-party platform" is the only public explanation so far. That phrasing raises a practical question that remains open as of July 7, 2026: how many other army.mil subdomains are still running on legacy third-party infrastructure with the same potential exposure?
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.