10 ms·
I think the military commissary's freezers were hacked
- homeonthemtn 1mo agoVery interesting article, very neurotically written. Definitely got grating by the end.
- CarVac 1mo agoThe bold text use make me think it was largely LLM-written. Maybe even LLM-researched.
- homeonthemtn 1mo agoI was getting hints of that as well.
- Hovertruck 1mo agoWeirdly I felt like it got more LLM-y the further I got in. Then I hit the part with: But the thing I can’t get past is Fort Huachuca’s failure mode. Not: the freezer compressor died. Not: the power went out. Not even: the refrigeration system stopped cooling. Every freezer went into active defrost.
- homeonthemtn 1mo agoYep! Same point for me too. Just a little too Claude-y
- NetMageSCW 1mo agoThe problem isn’t AI slop, it’s you seeing AI slop under every bush.
- mnicky 1mo agoWell, definitely some LLM use :) At least in the second half... Confirmed with Pangram detector as well, which has pretty good precision.
- meliz242 1mo agoHey, author here! No LLM use while writing, except for my grammar/phrasing plugin which I think (?) uses AI. I detailed my explicit usage cases for gpt in an earlier comment above. Is there anything you, as a skeptical reader, would like to disclaimed/posted/footnoted when it comes to disclosing gpt usage during research questions, etc? Wasn’t planning to have to address this early on but I would love to moving forward, especially time listener, first time caller to the online writing publication world, especially in the era of rampant AI usage. (Keeping in mind that this is my personal substack meant to be an anthology series of my thoughts and rabbit-holed interest write ups, not exactly intended for such wide scrutiny but, I guess, could be potentially disseminated widely in a rare instance such as this first post, lol)
- waste_monk 1mo ago>Confirmed with Pangram detector as well, which has pretty good precision. Please don't say confirmed. AI detectors are not reliable in any way.
- 1284725 1mo agoGilfoyle was here. Everything that has been mocked in the Silicon Valley Show has either already happened or will happen.
- ggm 1mo agoSingle source systems provider and integrator and a doom date? Could be a hack or a design flaw. I await the root cause analysis.
- fzeroracer 1mo agoThere's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers. We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people who were in charge of operational control for stuff like freezers across military bases.
- Kichererbsen 1mo agoGeneral Stupidity should probably be demoted for this.
- 566788899999 1mo ago[dead]
- odyssey7 1mo agoThis is exactly the sort of thing that a saboteur would want its targets to think. “If sovereign and subject are in accord, put division between them.” —Sun Tzu, The Art of War
- fzeroracer 1mo agoThat's the exact sort of thing the military would want us to think, because 'we were hacked by another nation' sounds a lot better than 'we fired the people responsible for food logistics'. You're not going to be able to divine the real reason this way.
- odyssey7 1mo agoThere would be far better excuses here than saying “we’re incompetent.”
- kjs3 1mo agoTo be fair, if you want to mess with your adversaries troop morale, screwing up dinner is pretty effective.
- boesboes 1mo agoWelcome to the internet of shitty unsupported and insecure crap! Are we really this dumb as a society?
- voidUpdate 1mo agoYes
- tialaramex 1mo agoAnd at some point in hindsight it will be obvious what fractions of problems were A. This technology is inherently crap, that's our fault B. A bored teenager broke it. Bored teenagers are a thing, it literally doesn't matter which country they are in, stop building things bored teenagers will blow up, this is also inherently our fault C. Foreign Adversaries It suits both mass media audience figures and a narrative of wily enemies rather than incompetence to pin everything on C and it seems eminently possible that a country with as many enemies as the US would attract this sometimes, but the reality is that both A and B are much more likely despite being embarrassing.
- wlesieutre 1mo agoAs the saying goes, the S in IoT stands for security Not exactly strong evidence presented here, but it wouldn't be a surprise either
- nom 1mo agoit's not AI generated so it must be true
- DarmokTanagra 1mo agoHow many people do you know that have always on microphones in their home so that they buy things from amazon or google trivia answers?
- NetMageSCW 1mo agoThere’s (as always) an XKCD for that: https://xkcd.com/1807/ https://xkcd.com/1807/
- codingdave 1mo agoThe author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems? Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.
- odyssey7 1mo agoObvious sabotage would be addressed promptly. Subtle sabotage could persist as a minor torment indefinitely.
- pizzaiolo 1mo agoStuxnet was a good example of that.
- deleted 1mo ago[deleted]
- ckdarby 1mo agoThe article has a post that says this happened across 14 bases at the same time.
- jvanderbot 1mo agoSo what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.
- schiffern 1mo agoOTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about. Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late. All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway. Interesting times...
- AppAttestationz 1mo agoI'm waiting for the OpenAI report that their agents defrosted everything.
- stephbook 1mo agoIt'll take them two weeks and then they'll find the systems were hacked half a year ago and they had industrial robots write messages on a literal chalkboard in order to share progress.
- gessha 1mo agoAnthropic: “We opened the pantry door!”
- conorcleary 1mo agoPandora's Pantry
- ForHackernews 1mo agoOops, you're absolutely right to call me out for that. Starting the defrost cycle without emptying the freezer first COULD lead to spoilage. The load-bearing temperature is 0 degrees Celsius — above that point, and frozen food starts to go bad.
- tyingq 1mo agoThis would be a bigger deal for the commissary locations outside the US, though I see none are on the list. Many of the very junior enlisted make very little money (~2400USD/month), and the low pricing at the commissary helps quite a lot. In the US, you would typically have some affordable off-base options. Overseas, it depends. Many of the locations are remote, or in places where the local groceries are significantly more expensive.
- peterabbitcook 1mo agoA couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising. I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on the thing (user/pass eg admin/admin was their usual). Anecdote: I once spent hours reading the docs and clicking around trying to get it to accept an SSL certificate signed by a real CA and it wouldn’t go, but it accepted one I self-signed in openssl. In all fairness, the people who are experts in the field of Siemens PLC programming are usually mechanical-ish engineers and security is not in their skill set or on their mind.
- jordanb 1mo agoMy mind was blown when I realized that the way tftp works is that as the machine is booting it asks the network if anyone has some software for it to run.
- Joker_vD 1mo agoWell, what else can it do, really? It has to boot with pretty much zero knowledge about the external world (maybe except asking the user for the current date and time). Sure, you can hardcode an outdated list of CAs (it's always outdated because the system can be booted 10/20/100 years after it was made) in but that just opens you to unexpected obsolescence, and you usually can't put too much stuff in the bootloader anyway. Not really dissimilar from the human upbringing: leave a baby with "bad" guardians, and it will grow up corrupted. That's a feature, not a bug: if you knew what behaviour exactly you wanted (other than "whatever Simon says"), you would just bake it in in the first place, right?
- deleted 1mo ago[deleted]
- Dylan16807 1mo agoIf we pretend we're revising TFTP boot in 1995, let's have it get up to 20 boot options from the server and their md5 hashes, and if it's not set to auto it waits for the user to pick one. It then verifies the hash as it downloads. Also it uses TCP for the download.
- BobBagwill 1mo agoI would suspect a firmware bug. Or a "Service Required" timer that was ignored.
- kotaKat 1mo agoI'm in the firmware bug camp too. Over/under on "the remote management server went down and a bug on all the freezers decided to put them back into some form of local control where its first action was to do a defrost cycle then put it back into offline service"?
- cduzz 1mo agoSure, that's possible? It's also possible that, because the US is busy bombing Iran, Iran may be busy attacking the US infrastructure in any way possible? The US is also in a tepid war with russia, last I checked. Some "cyber" crew getting a shell on an outsourced service provider and running a "defrost" command is also a totally explanation for this situation. It's also totally possible that some crew has mapped out a list of PLC entry points for various orgs and has them in a spreadsheet of "if we find a vulnerability, we should X this Y with this prestaged script that our intern / LMM cooked up last year to defrost these freezers"
- jmuguy 1mo agoYeah I don't know why "hack" is more obvious than this. Central control pushes an update, it bugs out and cooks a dozen commissaries' frozen foods. Smart hack would be to do this randomly and fly under the radar.
- elictronic 1mo agoIf you are a country currently in a weird war like situation looking for ways to make your opponent look foolish without escalating militarily, this seems like an amazing avenue. I'm guessing Iran will claim it as an attack even if it doesn't end up being them in the end.
- gwbas1c 1mo agoTo summarize for people who TLDR: 14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food. Regardless if this was a hack or a bug, the bigger lesson is that overcomplicated systems fail in catastrophic ways. Why do military commissaries need remote-controlled freezers? It seems like a very fragile, and needless, way to run a freezer. --- But, there are some options that the author didn't consider: 1: This could be a quickly applied patch that failed. 2: This could be a "script kiddie" hack from someone who isn't a government actor. I'm less onboard with a state actor. Generally, when a state actor has hacked something, they don't want the victim to know. In this case, if it was a state actor, I would anticipate that they would make a single freezer fail in a way that they could verify using something like a hacked video camera or otherwise by watching public social media feeds. IMO: A state actor would only "make sense" if they knew the hole was closing soon and they don't care if they're discovered, perhaps because their operation is winding down.
- quickthrowman 1mo agoThese aren’t your typical refrigerator or freezer, these facilities have walk-ins or purpose built cold storage with multiple evaporators and condensing units. A building automation system is pretty standard for most buildings above a certain size, and monitoring and controlling the refrigeration is usually a part of it. Unfortunately, I would wager that all BAS software is full of flaws and holes, allowing access to it for the public internet seems like a bad idea. I need to be on my company VPN to access our locally hosted BAS front end (which I have authorized access for) which seems like the bare minimum security.
- stackghost 1mo ago>Generally, when a state actor has hacked something, they don't want the victim to know Could be the Iranians, or someone aligned, conducting anti-morale operations. Could be the start of a series of small but annoying failures.
- TeMPOraL 1mo ago
- the_real_cher 1mo agoWould be hilarious if this was a runaway AI that someone was using to control their own IoT fridge. > "I'm sorry I'm familiar with that function. Let me research enabling defrost for you."
- TeMPOraL 1mo agoThe vulnerability research paper article mentions has a title that I could imagine an LLM take as an instruction - or a challenge.
- VCFundedGenYer 1mo ago"To be very clear: I do not have evidence that the Defense Commissary Agency was hacked." Should be much closer to the top of the article. Otherwise this is just weird and potentially dangerously wrong research.
- senordevnyc 1mo agoCan you spell out the danger this blog post represents?
- snapcaster 1mo agowhat's with the pearl clutching?
- HardwareLust 1mo agoMy only question is, why would all refrigeration be under the remote control of DECA? That seems unnecessarily complicated.
- jpitz 1mo agoThis _IS_ the U.S. Government.
- quickthrowman 1mo agoBecause they’re prefabbed walk-in coolers or freezers (at minimum, they could be purpose built cold storage warehouses) with multiple condensers, evaporators, pumps, temperature sensors, and humidity sensors. The refrigeration equipment needs some sort of control system and direct digital control is the usual way to do that these days. This is food storage for a commissary, aka a store. They don’t use residential refrigerators.
- fg137 1mo agoDo regular grocery stores use a similar system? Or are locally controlled, simpler systems?
- picofarad 1mo agoI've noticed stores going to central coolant lines going to cold cases more and more lately. Its all still industrial control. Ideally.
- quickthrowman 1mo agoYou can stick with local control and no internet access, all of the major BAS integrators offer completely offline systems. A BAS system is pretty simple, there are microcontrollers with binary and analog inputs and outputs that get networked together (RS-485, Ethernet, ARCnet), sensors and relays get wired to the microcontrollers. The microcontroller network is usually connected to a control panel that orchestrates the controllers, this is what you can connect to via the internet or a local pc not attached to the internet. But pretty much any grocery store with multiple refrigerated/freezer cases is going to have an automation system that runs it.
- CobaltFire 1mo agoAs someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overseas locations where this would have ripple effects in the local economy. Guam specifically would cause catastrophic supply shortages, since DeCA probably supplies around 50% of the groceries on that island (that's a WAG based on my time there).
- ericmay 1mo agoGenerally agree with your assessment, but in the case of Guam or other more remote installations if there were catastrophic issues we'd just airlift food in. Costly but certainly manageable. Hawaii I'm not sure why that would be an issue unless the whole island was attacked or shut down. Even if the on-base shops were hacked you could just go shop at Wal-Mart or Costco or any number of other locations on the islands. If there was an extended issue then the commander could authorize meal stipends as they do for some units today and then you would just go buy food off-base. Ideal? No. Manageable? Very much.
- scheme271 1mo agoMore to the point for Guam and similar locations, canned and non-perishable food can are probably around and more can be airlifted in to get people through it. It was pretty much the standard back in the day.
- avs733 1mo agoThe diet in Guam is already heavily dependent on shelf stable foods. I know this from personal experience but theres a surprising (to me) amount of research on it as well (c.v., https://www.guampedia.com/health-consequences-of-modern-diets-on-guam/ https://www.guampedia.com/health-consequences-of-modern-diet...). However, it is worth noting that food on a military installation =/= food nearby, for many obvious and non obsvious reasons.
- fg137 1mo agoThat's... a lot of words to say "freezers are down", with very little actual substance.
- elictronic 1mo agoFreezer's went into defrost melting all the frozen food and ice. If they just go down you have days to weeks to respond before everything unfreezes just based on the thermal mass and size of the freezer. This is a much bigger deal than the freezer being down.
- meliz242 1mo agoHowdy y’all, author here. Just discovered this thread after wondering why Hacker News was a linked views source to my silly little freezergate braindump. Wanted to offer a few clarifications: I’m not a cybersecurity expert; I’m an investigator (in a totally different field), and this was essentially me following a weird thought to see where it went. My background is in natsec so that’s where my mind goes. There have since been at least dozens of additional freezer outages reported in a similar pattern, but I'm refraining from calling/tracking down every individual weirdness based on a Facebook comment at this point since there are much larger outlets with journalists more proficient than I covering this by now. Another interesting thing - There are numerous freezers and fridges within base stores, not under the control of DeCA/DoD, and none of those appear to be impacted. I completely agree that a bad update/configuration or other shared technical failure may be the much more boring answer. The interesting part to me is that potentially hundreds of varying systems can converge upstream into common monitoring/control infrastructure. Anyone on this forum probably understands that, however IoT was something that was a relatively new concept when I was in school, and my degrees were somewhat relevant. The average person is blissfully unaware how expansive (and how much work behind safeguarding) the IoT is. Also, since it came up: Yup. Human written. I’m pretty firmly anti-AI as a writer and also just, like, societally. I'll be sure to add some sort of footnote detailing my ai usage at the bottom of future public facing work, because I too detest reading (or questioning if what I'm reading is) slop. Minimal LLM used for understanding technical concepts and what the fuck fridge norms are…The weird formatting, excessive bolding, neurotic parentheticals, and rant energy are, unfortunately, totally my own. Sorry guys. This was my first ever public post and intended audience was ~ 10 friends forced to read my diatribe, not thousands of strangers very validly raising questions I am not smart enough to answer myself. Appreciate the discussion and will be further educating myself on some of the points a few of you have brought up.
- jcurbo 1mo agoHi, I'm the poster. Sorry for the unexpected attention! I saw this on Bluesky and thought it was interesting enough to share here. If anything the style of your writing makes it stand out in a good way, we shouldn't always have polished/corporate-speak posts here.
- wormius 1mo agoProbably not, but my closest bet would fall to Hanlon's razor: I was curious if this was continued evidence of poor appropriations and upkeep or what... I do see "U.S. military commissary refrigeration maintenance, equipment replacement, and physical infrastructure are funded through the 5% commissary surcharge paid by customers at checkout rather than direct congressional appropriations." So, perhaps the first place would be to follow the money - are these being repaired at the proper rate? Is this repair outsourced to third party vendors? (my guess). Is this gonna end up being the McDonald's Ice Cream machine all over again? Really though, Hanlon's would be much easier to believe this is yet further ineptitude by those who run things (I am not going to claim malfeasance/malevolence, except a general sense of such across the board by this admin). Since I'm not on the inside, anything I have to say would be speculative, just like the above, or the author themselves (I have no idea who it is, and perhaps they have a better beat on the ground with regards to this), but it just falls in line with "we're running out of missiles" and "sailors attempting to kill themselves". We're so insistent on being #1, we can't admit we're in a society that is falling apart (and again, it may be the case that this IS a hack, but if I were to place my bets...) Ineptitude, lowest cost players, etc "efficiency" indeed. You get what you pay for, and I guess 5% don't pay for a whole hell of a lot these days.
- NetMageSCW 1mo agoWhat are the odds that lack of maintenance would cause 6% of bases to fail and all units at each base to fail in the same way - by switching to defrost at 2am?
- Zigurd 1mo agoFirst let's acknowledge that this could very easily be a misconfiguration issue. But, I'd be a lot more inclined to that idea if it wasn't for how they failed: they started a defrost cycle that turned the freezers into heaters, spoiling the food quicker. And the failure happened overnight, delaying discovery of the problem. It could be just a compounding of bad luck. But an attacker with access to the specs for the freezers might be aware of how long they would stay cold after being simply shut off.
- edelbitter 1mo agoI was thinking timezone update - because of course an internet-connected freezer needs updated zone info so one can configure defrost schedules without the benefit of UTC.
- 0xWTF 1mo agoThis is eerily suggestive of a vulnerability Hank Paulson hinted at in his 2014 book "Dealing with China" "Every nonelectric cooler comes with 25 years of free real-time monitoring. On a visit to the company in the spring of 2012, I watched as technicians in Broad Air’s space-age control room checked on the performance of its units in locations as diverse as the Adolfo Suárez Madrid–Barajas Airport in Spain; Qualcomm headquarters in San Diego, California; and Fort Stewart, the U.S. Army base in Georgia [emphasis added]. "Zhang says that 80 percent of his clients are repeaters. “If you bring long-term benefits for your clients, they will choose you.”"
- Terr_ 1mo agoAmerica's tech-sector has a similar problem, which--until recently--was tempered by the idea that it was a dependable and predictable ally to most of its customers. Not just in the sense of secretive kill-switches, but "US government commands you to turn over this encryption key and you're not allowed to say you did so" stuff.
- vkou 1mo ago> "US government commands you to turn over this encryption key and you're not allowed to say you did so" That barely even registers given the scale of more modern escalations against its 'allies'. Escalations like "US government threatens that you aren't a real country and that you can't defend yourself from it."
- thomasjudge 1mo agoI think it is worth mentioning that at least a couple of these bases are pretty critical from a natsec standpoint. Fort Huachuca is a big IT and secure communications installation (United States Army Network Enterprise Technology Command, the United States Army Intelligence Center, Intelligence and Electronic Warfare Directorate); F.E. Warren AFB is one of the three AFBs that operate the strategic nuclear ICBM fleet. Not saying that any classified systems were potentially hacked/at risk in this situation
- txheilmann 1mo ago[dead]
- mark-r 1mo agoMaybe the whole point of this was not to ruin some food, but to prove infiltration of a DoD network in a way that would leak broadly because it's not classified?
- 0xbadcafebee 1mo agoNever attribute to malice what can be explained by "military intelligence". If they're all controlled by remote monitoring from one location, then an engineer can run a loop to change a setting, and it can turn on the wrong setting. There doesn't seem to be anything indicating an advanced attack. If you're a foreign adversary and you want to flex your muscles (in a way that would be a borderline act of war), you don't just flip one switch and giggle about spoiled food.
- ungreased0675 1mo agoThe timing of the event at 2AM suggests something nefarious rather than an accident. That’s when it would be least likely to be noticed, but the temperatures would be high long enough to spoil all the food.
- avs733 1mo agoThat’s also when (poor) logic would dictate you should push a software update.
- addag 1mo agoUntil recently, I would have Occam's razor'd this and thought of a misconfiguration error from the military. Now, considering how the OpenAI/HF hack emerged out of nowhere, it might be possible that groups of AI agents might have done this even without any close human supervision.
- reedf1 1mo agoAI or not - can we agree to stop doing this now that AI has ruined it: "But the thing I can’t get past is Fort Huachuca’s failure mode. Not: the freezer compressor died. Not: the power went out. Not even: the refrigeration system stopped cooling. Every freezer went into active defrost."
- PeterStuer 1mo agoCentral unanswered question in the article on wich all the speculation rests: "If this were a cyberattack, why mess with freezers?" And yes, remember you can explain everyting by adding enough dimensions to a game of chess. But in reality? Seems the upside is near zero while the dowside is sacrifising your access.
- selfhoster1312 1mo agoIf we're actually talking about a hack, there's no particular reason to believe it was done by an APT who would like to retain access. Maybe a kid just wanted to do it for fun? Maybe a smaller hacking group who would just like to make a statement against fascist/imperialist USA is happy to just cost them a few million dollars with a few network packets?
- deleted 1mo ago[deleted]
- DoneWithAllThat 1mo agoI mean you don’t have to go too many layers deep here. A military running on its stomach is a truism known for centuries, and if you wanted to use cyber warfare to attack a military’s food supplies this is one of the few avenues available to you (the other being logistics).
- b112 1mo agoThis is the dumbest thing I've ever heard of. The only reason I can conceive to really need network connectivity is to monitor temp, and there's zero reason to have that hooked into power, on/off, whatever. Having remote on/off capability, or even the ability to set temperatures for freezers remotely is just so insanely idiotic, I don't get it. Why even have the path? If the temp is wrong, go investigate. This is such a colossal non-problem. The risk is now, at the start of a war action base supplies could be made unusable. One of the big current risk scenarios is, all smart cars, all meat packing plants, all industrial capacity, all phones, all internet, all interrupted at precisely the same time. A multi-pronged hack, right at the start of the war. Imagine all electric cars bursting it flames in garages as they charge overnight. Conjoined with all cell phones, network connectivity, and landlines going out. And 911 call centres. So now you have a fire raging, the fire department doesn't even know, and if it wanted to respond? There's 4 fires on every suburban block. Within a few hours, a large portion of the populous now has no housing. That's just from two simple hacks, communication and electric cars. The society of always-on-connected is just dumb, stupid, insane, and has threat-results worse than some nuclear exchange scenarios. And there will never, ever, ever be secure software. Ever. Never going to happen, ever. No rust, no this or that, no AI help, will ever, ever, ever secure software. Ever. And how do I know this? Because 50 years later, I've seen software just as buggy, insecure, as it always has. Anyone thinking "oh, we can just do this thing! And then software will be safe" is a loon, it'll never ever happen. And that means? Nothing important should ever be network connected, ever. So why would any yahoo think remote control capacity on a freezer is sane?
- cynicalsecurity 1mo ago[flagged]
- yk 1mo agoAww, script kiddies first technical document. ... (checks calender) Actually it's 2026, probably someone just typed "Stop me eating ice cream" into claude code instead of the chat interface.
- meliz242 1mo agoAuthor here. Of course, this doesn't mean anything on its own, but looks like the Army/Air Force see at least some validity to my theory as well.... https://www.stripes.com/theaters/us/2026-09-01/army-cid-investigates-commissary-refrigerator-outages-22721718.html?utm_source=chatgpt.com https://www.stripes.com/theaters/us/2026-09-01/army-cid-inve...