In a rather strange turn of events, millions of emails intended for Pentagon employees mistakenly ended up being sent to Mali in West Africa. The mixup occurred due to typos in email addresses, as the US military’s email domain bears a striking resemblance to that of Mali’s.
As a result of the typos, which mixed up “.mil” with “.ml,” sensitive information meant for Pentagon employees, including hotel reservations for senior US military officials, was exposed.
Naturally, the incident, while caused by a seemingly simple mistake, does raise concerns about security risks and potential cyberattacks that can result from such mishaps.
The issue was brought to light by Dutch technologist Johannes “Joost” Zuurbier, who discovered the problem and promptly reported it to US officials, including the US Embassy in Mali.
Taking immediate action, the US Department of Defense has blocked its email accounts from sending messages to “.ml” addresses, mitigating further incidents.
It is worth noting that only personal email accounts, such as Gmail or Yahoo, were affected by this error. Interestingly, some of the typos were made by US government employees themselves, inadvertently directing the emails to the Mali domain.
In a statement to CNN, Lieutenant Commander Tim Gorman said the Department of Defense was aware of the issue and “takes all unauthorized disclosures” of national security information “seriously.”
To prevent similar incidents in the future, the Defense Department has implemented protective measures, including policies, training programs, and technical controls.
These safeguards aim to ensure that such typos and subsequent misdeliveries do not occur again, safeguarding the confidentiality and security of sensitive information.