Syrian Electronic Army Took Aim at U.S. Army Website

Published: Jun 10, 2015
Updated: Feb 2, 2021
2 minute read
U.S. Army website
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The Syrian Electronic Army (SEA), a digital hacking group loosely aligned with the government of Syrian President Bashar al-Assad, is claiming responsibility for an attack against the Army.mil Website operated by the U.S. Army.

The attack occurred on June 8 and was a defacement of the site that triggered multiple pop-up messages, including one that stated, “Your commanders admit they are training the people they have sent you to die fighting.” The Army site was offline and unavailable briefly on June 8 and has since been fully restored.

As of June 10, the Army site is fully operational, and there is no mention whatsoever on the public site that the incident ever took place. Although it’s unclear at this time precisely how the attack occurred, there are a number of common attack vectors that the SEA and other attacker groups use to get control of a given domain. One common tactic is via some form of Domain Name System (DNS) redirection that enables attackers to gain access to a domain registrar and then change the DNS settings so the site will point to a different IP address. That’s what happened in the Lenovo site defacement earlier this year by the hacker group Lizard Squad.

DNS redirection apparently, however, is not the root cause for the attack on the Army site as far as publicly available records show. A Netcraft search for the Army.mil shows that the domain has been at the same IP address since at least August 2014. The SEA itself claimed in a tweet that it somehow got control of the Army site via the Limelight Content Delivery Network (CDN). That claim has not been confirmed by any third-party source, including Limelight, at this time.

SEA has been active in recent years going after multiple organizations, including Microsoft’s Skype service in 2014, and attacks against media outlets, such as The Washington Post and The New York Times in 2013. In The New York Times incident, DNS records were the attack vector the SEA used while the Skype attack allegedly was executed via phished credentials.

The simple truth is that there are a lot of different ways the SEA, or any attacker for that matter, could potentially get access to any Website.

The U.S. government in now mandating the use of HTTPS-Only across all federal Websites, which is helpful, but there are other elements of Websites that need to be secured. Administrative passwords for content management systems and servers needed to be monitored and guarded closely. Third-party resources, including DNS records, need to be protected as well. The watchword for Website security is, and will always be, “continuous vigilance.”

Advertisement

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。