
An expired domain let the author take control of the phone routing for three British territories and accidentally log hundreds of thousands of calls to military bases.
The author discovered that a forgotten phone-network protocol, e164.arpa, could still be hijacked. The protocol was meant to route phone calls over the internet but has long been abandoned.
1. Buying three territories for 5 euros
Scanning the protocol, the author found that the e164.arpa zones for three British territories — Saint Helena, Diego Garcia and Ascension Island — were delegated to two nameservers, one of which had expired. For 5 euros, the author bought the domain and gained control of the DNS for those zones, meaning every call to those territories could be intercepted.
2. Accidentally logging hundreds of thousands of calls
At first no one cared, so the author hosted a personal site on the domain. Six months later, checking the logs, the author found hundreds of thousands of queries — almost all for Diego Garcia and Ascension Island, mostly from US military bases. The logs contained full phone numbers, timestamps and resolver IPs. The author shut down the server and deleted the logs immediately.
3. When the military suddenly cares
The author reported it again to the UK's National Cyber Security Centre, and this time they took it seriously. After Iran's missile strike on Diego Garcia in 2026, the author transferred the domain to the NCSC. In the end, the author was only down 10 euros in domain fees, but it made for a great story.
In summary: an expired domain exposed the fragility of the phone network and the risks of forgotten infrastructure.