Al Mayadeen English

  • Ar
  • Es
  • x
Al Mayadeen English

Slogan

  • News
    • Politics
    • Economy
    • Sports
    • Arts&Culture
    • Health
    • Miscellaneous
    • Technology
    • Environment
  • Articles
    • Opinion
    • Analysis
    • Blog
    • Features
  • Videos
    • NewsFeed
    • Video Features
    • Explainers
    • TV
    • Digital Series
  • Infographs
  • In Pictures
  • • LIVE
News
  • Politics
  • Economy
  • Sports
  • Arts&Culture
  • Health
  • Miscellaneous
  • Technology
  • Environment
Articles
  • Opinion
  • Analysis
  • Blog
  • Features
Videos
  • NewsFeed
  • Video Features
  • Explainers
  • TV
  • Digital Series
Infographs
In Pictures
  • Africa
  • Asia
  • Asia-Pacific
  • Europe
  • Latin America
  • MENA
  • Palestine
  • US & Canada
BREAKING
An Iranian missile hit an Israeli governmental compound in Haifa.
Talks begin in Geneva between Iranian Foreign Minister Abbas Araghchi and the E3.
Al Mayadeen correspondent: The E3 will present Araghchi with a four-point European plan that includes a complete end to uranium enrichment in Iran.
Iranian Foreign Minister Abbas Araghchi arrives at the venue of the negotiations that will soon begin with the E3.
Araghchi: The Israeli attacks on nuclear facilities in Iran are serious war crimes.
Araghchi: We are determined to defend our territorial integrity and sovereignty with full force.
Araghchi: We were supposed to meet with the Americans on June 15 to draft a highly promising agreement regarding our nuclear program.
Araghchi: The unjustified Israeli attack on Iran is a violation of International Humanitarian Law Article 33.
Araghchi: Iran is facing aggression that cannot be justified in any way, and justifying this aggression is an act of complicity.
Araghchi: "Israel" bombed nuclear facilities that are under the supervision of the International Atomic Energy Agency (IAEA).

Typo leaks millions of US military emails to Mali web operator

  • By Al Mayadeen English
  • Source: Financial Times
  • 17 Jul 2023 14:53
  • 2 Shares
7 Min Read

A Dutch internet entrepreneur has in his possession around 117,000 misdirected messages from the US Army, navy, and more.

  • x
  • US soldiers monitor battlefield conditions at a joint US-Afghan military command center in Ghazni province, west of Kabul, Afghanistan on Thursday, June 21, 2007. (AP)
    US soldiers monitor battlefield conditions at a joint US-Afghan military command center in Ghazni province, west of Kabul, Afghanistan on Thursday, June 21, 2007. (AP)

Millions of US military emails were misdirected to Mali due to a "typo leak" that revealed extremely sensitive information such as diplomatic documents, tax returns, passwords, and top officials' travel data.
 
Despite repeated warnings over a decade, a steady flow of email traffic continues to the .ML domain, the country identifier for Mali, as a result of people mistyping .MIL, the suffix to all US military email addresses.
 
Johannes Zuurbier, a Dutch internet entrepreneur with a contract to maintain Mali's country name, spotted the problem about a decade ago, and has been collecting misdirected emails since January to persuade the US to take the matter seriously. Around 117,000 misdirected messages are in his possession and almost 1,000 were sent on Wednesday alone. 

Zuurbier keeping emails away from Mali, US does not respond

In a letter to the US in early July, he wrote, "This risk is real and could be exploited by adversaries of the US." Moreover, control of the .ML domain will revert to Mali's government, which is close to Russia, on Monday. Malian authorities will be able to collect the misdirected emails after Zuurbier's 10-year management contract expires. 
 
Zuurbier, the managing director of Mali Dili, an organzation in Amsterdam, has frequently approached US officials, including a defense attaché in Mali, a top advisor to the US national cyber security service, and even White House officials.

Read next: Pentagon refuses to say if leaked data were seized by rivals: Report

The email flow is spam and none are marked as classified, but the messages have highly sensitive data concerning the service of US military personnel, contractors, and their families. 
 
X-rays and medical data, identity document information, crew lists for ships, staff lists at bases, maps of installations, photos of bases, naval inspection reports, contracts, criminal complaints against personnel, internal investigations into bullying, official travel itineraries, bookings, and tax and financial records are all part of their contents.

Related News

Iranians rally in support of homeland in 'Friday of Rage and Victory

US, E3 hold high-level coordination ahead of Geneva talks with Iran

'How sensitive is the information is what's important': US Army's Cyber Command

A retired American admiral who previously led the National Security Agency and the US Army's Cyber Command, Mike Rogers, stated that "If you have this kind of sustained access, you can generate intelligence even just from unclassified information," adding that "This is not uncommon... It’s not out of the norm that people make mistakes but the question is the scale, the duration, and the sensitivity of the information.”

For example, one misdirected email included the travel plans for General James McConville, the chief of staff of the United States Army, and his delegation for a May visit to Indonesia. The email included a complete list of room numbers, McConville's schedule, and information about picking up McConville's hotel key at the Grand Hyatt Jakarta, where he obtained a VIP upgrade to a grand suite.

Read next: Leaked classified docs undermine US relations, credibility with allies
 
Rogers cautioned that Mali's control over the messages was a problem, explaining that "It's one thing when you're dealing with a domain administrator who is attempting, albeit unsuccessfully, to articulate the issue...It's another thing when it's a foreign government that... sees it as an advantage that they can use."
 
According to Lt. Cmdr Tim Gorman, a Pentagon spokesperson, the Pentagon "is aware of this issue and takes all unauthorized disclosures of controlled national security information or controlled unclassified information seriously." He explained that the emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients."

How did Zuurbier detect the misdirected emails?

When Zuurbier took over the Mali country code in 2013, he quickly saw requests for domains such as army.ml and navy.ml, which did not exist. He had previously overseen similar operations for Tokelau, the Central African Republic, Gabon, and Equatorial Guinea. Suspecting it was email, he set up a system to catch any such correspondence, which quickly became overburdened and ceased collecting messages.
 
Zuurbier claims that after learning what was going on and seeking legal assistance, he made many attempts to notify US authorities. According to the Financial Times, he handed a copy of the legal advice to his wife "just in case the black helicopters landed in my backyard."
 
In order to enlist the assistance of Dutch diplomats, he joined a trade mission from the Netherlands in 2014. He made another attempt to warn US officials in 2015, but it was futile. Zuurbier resumed collecting misaddressed emails this year in a final attempt to inform the Pentagon.

FBI files leaked

The data flow reveals certain consistent sources of leakage. Emails are frequently misspelled by military travel agencies. Employees sending emails between their own accounts are another issue.
 
One FBI agent with a naval background attempted to transmit six texts to their military email and inadvertently sent them to Mali. One of them was an urgent diplomatic communication from Turkey to the US State Department concerning possible operations by the Kurdistan Workers' Party (PKK) against Turkish interests in the US.
 
When passing notes, one FBI agent frequently mistyped their own email, including a notice from the Turkish embassy in Washington on probable activity by a recognized terrorist group.

The same person also forwarded a series of briefings on domestic US terrorism marked “For Official Use Only” and a global counter-terrorism assessment headlined “Not Releasable to the Public or Foreign Governments.” 
 
Gorman told the FT: “While it is not possible to implement technical controls preventing the use of personal email accounts for government business, the department continues to provide direction and training to DoD personnel.”

What kind of emails were leaked?

A dozen persons requested recovery credentials for an intelligence community system that was accidentally delivered to Mali. Others provided passwords for documents stored on the Department of Defense's secure access file exchange system. The credentials were never used by the FT.

Many of the emails are from commercial firms that work with the US military. General Dynamics gave the army twenty routine reports on the production of grenade training cartridges.

Some emails include passport numbers sent by the state department's special issuances bureau, which grants documents to diplomats and others traveling on official business for the United States.

The Dutch army operates under the domain army.nl, which is one keystroke away from army.ml. More than a dozen emails from serving Dutch forces include discussions with Italian counterparts regarding an ammo pickup in Italy and detailed exchanges about Dutch Apache helicopter operators in the United States. Others included conversations about future military procurement possibilities and a protest about the probable vulnerability of a Dutch Apache unit to cyber attack.

Eight emails from the Australian Department of Defense were misdirected to US recipients. An artillery manual "carried by command post officers for each battery" was among those.

  • United States
  • US military
  • Finland
  • Mali
  • Mali Dili

Most Read

Iranian missiles impact Israeli sites in Tel Aviv in 2nd wave

Iran's missiles impact 'strategic' Israeli site in Tel Aviv

  • Politics
  • 14 Jun 2025
Bin Salman: Islamic world backs Iran in call to Pezeshkian

MBS says Islamic world backs Iran in call with Pezeshkian

  • MENA
  • 15 Jun 2025
Iran launches 9th wave of Op. True Promise 3, destroys IOF air defense

Iran launches 9th wave of Op. True Promise 3, destroys IOF air defense

  • MENA
  • 17 Jun 2025
Smoke rises after an Iranian ballistic missile directly struck Tel Aviv, Occupied Palestine, June 13, 2025 (AP)

Op. True Promise 3: Iran's ballistic missiles strike Tel Aviv

  • MENA
  • 13 Jun 2025

Coverage

All
The Ummah's Martyrs

Read Next

All
Netanyahu stuns by postponing son’s wedding over Iran war
Politics

Netanyahu sparks outrage citing son’s wedding delay as Iran war cost

French court postpones verdict to July 17 on Georges Abdallah
Europe

French court postpones verdict on Georges Abdallah to July 17

Perseverance to shorten war: Iran's Larijani
Politics

Larijani says Iran to hold IAEA chief accountable after war ends

Damage to the Weizmann Institute of Science from an Iranian missile strike in Rehovot, Thursday, June 19, 2025. (AP Photo/Maya Alleruzzo)
Politics

'Catastrophic loss': Iranian blow to Weizmann’s war-linked facilities

Al Mayadeen English

Al Mayadeen is an Arab Independent Media Satellite Channel.

All Rights Reserved

  • x
  • Privacy Policy
  • About Us
  • Contact Us
  • Authors
Android
iOS