
Researcher accidentally logged hundreds of thousands of calls to military bases
A security researcher bought an expired domain for 5 euros, briefly controlled the DNS of three telephone zones and accidentally logged hundreds of thousands of calls placed to military bases.
A security researcher who publishes under the domain lina.sh has described how he briefly took control of the DNS infrastructure for three national telephone numbering zones and, without intending to, ended up logging hundreds of thousands of calls placed to military bases.
What ENUM was supposed to be
The system in question is ENUM, a registry published under the e164.arpa domain. The idea, dating from the early 2000s, was to reverse the digits of a telephone number, separate them with dots and append e164.arpa — so that every German number, for example, falls under the zone 9.4.e164.arpa administered by DENIC, the same organisation that runs .de. Carriers could then look up a number and receive a record saying it can be reached over SIP or another VoIP service, routing the call over the internet instead of the traditional telephone network. The scheme never took off and is now effectively dead. The researcher notes that Germany is one of the last countries that still allows registrations under e164.arpa, and that he was the first person to register one since 2019.
A nameserver bought for 5 euros
Scanning the zone for neglected delegations, he found three country-code zones — 0.9.2.e164.arpa, 6.4.2.e164.arpa and 7.4.2.e164.arpa — all delegated to the same two nameservers: ns6.icb.co.uk and ns.enum.org.uk. The first no longer resolved, so queries fell through to the second, which had expired. He bought that domain for 5 euros and thereby controlled DNS for the telephone codes +290 for Saint Helena, +246 for the British Indian Ocean Territory and +247 for Ascension Island. In theory this would have allowed him to accept calls to those numbers on his own server and relay them onward with a spoofed caller number, listening in on every conversation. He reported the issue through several channels to the British government and received no reply.
The logs that filled up
A researcher at the Max Planck Institute for Informatics raised the matter with RIPE, which manages e164.arpa, but RIPE declined to act because delegations are governed by an ITU-T committee at UN level. Curious about traffic, the author switched on logging for Saint Helena alone and saw no queries in a full day. Six months later he checked all three zones: hundreds of thousands of ENUM lookups, almost all of them for Diego Garcia and Ascension Island, from mostly American source addresses. Because the queried name is simply a reversed phone number, the logs contained full phone numbers, timestamps and the IP addresses of the resolvers. His server returned NXDOMAIN for every request, so calls were carried over the normal network; he then shut the server down and deleted the logs. A second report to the UK's National Cyber Security Centre drew a much stronger response once military bases were mentioned, and after Iran fired ballistic missiles at Diego Garcia on 20 March 2026, the NCSC took ownership of the domain. The researcher was left 10 euros out of pocket, with no bug bounty.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.