Sensitive US military emails reach Russian ally due to 'typo leak'

Millions of US military emails were mistakenly sent to Mali; the leak has exposed highly sensitive information, including diplomatic documents, tax returns, travel details of top officers

data protection bill
One misdirected email this year included the travel plans for General James McConville, the chief of staff of the US Army, and his delegation for a then-forthcoming visit to Indonesia in May
BS Web Team New Delhi
2 min read Last Updated : Jul 18 2023 | 3:44 PM IST
Millions of US military emails were mistakenly sent to Mali, an African nation that is a Russian ally, through a "typo leak".

The leak has exposed highly sensitive information, including diplomatic documents, tax returns, passwords, and the travel details of top officers.

Johannes Zuurbier, a Dutch internet entrepreneur, identified the problem a decade ago. The problem is that people mistype .MIL, the suffix to all US military email addresses, as .ML domain, the country identifier for Mali.

Zuurbier has been managing the Malian domain since 2013 and has collected close to 117,000 misdirected messages.

Zuurbier informed US officials this month that his contract with the Malian government will expire soon, which means that these emails could be exploited after his departure. 

The Malian military government will take control of the domain on July 24.

Much of the email flow is spam, but some emails contain highly sensitive data on serving US military personnel, contractors, and their families. The contents include X-rays and medical data, identity document information, crew lists for ships, staff lists at bases, maps of installations, photos of bases, naval inspection reports, contracts, criminal complaints against personnel, internal investigations into bullying, official travel itineraries, bookings, and tax and financial records.

One misdirected email this year included the travel plans for General James McConville, the chief of staff of the US Army, and his delegation for a then-forthcoming visit to Indonesia in May.

Lt Cmdr Tim Gorman, a spokesman for the Pentagon, said the Department of Defense "is aware of this issue and takes all unauthorised disclosures of controlled national security information or controlled unclassified information seriously".

Zuurbier says that he made repeated attempts to alert the US authorities after realising what was happening and taking legal advice.

Data shows systematic sources of leakage. Travel agents working for the military routinely misspell emails. Staff sending emails between their own accounts are also a problem. Many emails are from private contractors working with the US military. 

Some emails contain passport numbers sent by the state department's special issuances agency, while others included information on future military procurement options and a complaint about a Dutch Apache unit's potential vulnerability to cyber attack.

Eight emails from the Australian department of defence, intended for the US recipients, went astray. Those included a presentation about corrosion problems affecting Australian F-35s and an artillery manual "carried by command post officers for each battery".
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :US Militarydata leakagedata leakUS Defence SecretaryUS Defense DepartmentBS Web Reports

First Published: Jul 18 2023 | 3:44 PM IST

Next Story