In a detailed technical blog post published earlier this week, researcher Lina Sh describes how a configuration error in her personal server allowed her to intercept a vast number of telephone calls meant for other organizations. The incident, which has drawn significant attention on tech forums like Hacker News and Lobsters, centers on the E.164 number mapping (ENUM) system, which translates phone numbers into internet addresses and routes calls over IP networks.
Sh explains that she was experimenting with the .e164.arpa zone—a special domain used to map telephone numbers to internet services—when she mistakenly claimed responsibility for a large block of numbers. Due to a lack of proper validation by upstream providers, her server began receiving call routing queries for thousands of numbers, many of which were associated with U.S. military installations.
"I basically set up a DNS server for a range I shouldn't have, and the phone system just started sending me all these requests," Sh wrote. "I didn't intend to spy, but I ended up with logs of calls to military bases, recruiting offices, and other sensitive numbers." The logs contained metadata such as timestamps and caller IDs, but not the content of the calls themselves.
The researcher has since taken the server offline and notified relevant authorities, but the incident has sparked a broader discussion about the security of the global telecommunications infrastructure. Experts note that while this was an accidental breach, a malicious actor could exploit similar misconfigurations to eavesdrop on communications or launch targeted attacks.
The U.S. Department of Defense has not publicly commented, but security analysts suggest that the incident highlights a pressing need for stricter controls on ENUM delegation and better monitoring of phone number routing. The researcher did not disclose how long the misconfiguration persisted or whether any classified information was inadvertently accessed.