For over 10 years, millions of emails associated with the US military have been getting sent to Mali, a West African country allied with Russia, due to a typo, according to a report from the Financial Times. Instead of appending the military’s .MIL domain to their recipient’s email address, people frequently type .ML, the country identifier for Mali, by mistake.

Johannes Zuurbier, a Dutch entrepreneur contracted to manage Mali’s domain, tells the Financial Times that this has been happening for over a decade despite his repeated attempts to warn the US government. When Zuurbier began noticing requests for nonexistent domains, like army.ml and navy.ml, he set up a system to catch these misdirected emails, which the Financial Times reports “was rapidly overwhelmed and stopped collecting messages.”

Since January alone, Zuurbier has reportedly intercepted 117,000 misdirected emails, several of which contain sensitive information related to the US military. According to the Financial Times, many of the emails include medical records, identity document information, lists of staff at military bases, photos of military bases, naval inspection reports, ship crew lists, tax records, and more.

Once Zuurbier’s 10-year contract with Mali ends on Monday, authorities in Mali will be able to gain access to the emails

Some of the misdirected emails were sent by military staff members, travel agents working with the US military, US intelligence, private contractors, and others, the Financial Times reports. For example, an email from earlier this year reportedly contained the travel itinerary for General James McConville, the US Army’s chief of staff, for his visit to Indonesia. The email included a “full list of room numbers,” along with “details of the collection of McConville’s room key at the Grand Hyatt Jakarta.”

Zuurbier won’t be able to intercept these emails for much longer, however. Once his 10-year contract with Mali ends on Monday, authorities in Mali will be able to gain access to the emails. Russia established a presence in Mali last year through the Wagner Group, a Russian state-backed paramilitary organization that recently staged a rebellion against President Vladimir Putin. In May, the US State Department said the Wagner Group sought to use Mali as a route to transport war supplies to Ukraine.

“The Department of Defense (DoD) is aware of this issue and takes all unauthorized disclosures of Controlled National Security Information or Controlled Unclassified Information seriously,” Tim Gorman, a spokesperson for the Office of the Secretary of Defense, says in an emailed statement to The Verge. Gorman adds that emails sent from a .mil domain to Mali are “blocked” and that the “sender is notified that they must validate the email addresses of the intended recipients.”

Gorman acknowledges that this doesn’t stop other government agencies or those working with the US government from mistakenly sending emails to Malian addresses, though. Still, he notes that “the Department continues to provide direction and training to DoD personnel.”

  • jmp242@sopuli.xyz
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    Honestly, this is just people being stupid. Validate your addresses. Maybe they should change from .mil to .mil.us or something so at least it’s going to a US address (and fits the rest of the world better).

      • krolden@lemmy.mlOP
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 year ago

        This isnt just people being stupid, its a failure by the pentagon to secure their classified comms enforce the restriction on public email account usage by their employees/contractors/whomever. At the very least they should be using some kind of pubkey encryption or better yet only emails over their intranet.

          • 133arc585@lemmy.ml
            link
            fedilink
            arrow-up
            0
            arrow-down
            2
            ·
            1 year ago

            They said it’s not just stupid people being stupid. Given the stakes of allowing stupid people to be stupid in this context, there should be guardrails in place so that even stupid people being stupid can’t lead to something like this.