AAFES probes suspicious messages sent to Exchange customers
The messages reached customers through the My Exchange app, a channel scammers don't normally have access to, and one that suggests the attacker may have had more than just a list of email addresses.
TL;DR
The Army and Air Force Exchange Service is investigating suspicious messages sent to customers through its My Exchange app and via email. AAFES hasn't determined whether the email messages came from a spoofed address or its own system, and the investigation into the origin remains open. Ally Armeson, executive director of FightCybercrime.org, told DefenseScoop the combination of transmission through an official channel and targeting of AAFES customers specifically "points to there's a breach somewhere or someone got in." AAFES says notification to impacted customers is standard procedure if PII was compromised.
The Army and Air Force Exchange Service (the military's largest retailer, operating more than 5,500 facilities and serving roughly 30 million eligible shoppers) confirmed Thursday that it is investigating a string of suspicious messages that reached customers this week.
The messages arrived through at least two channels: email and push notifications from the My Exchange app. One email, posted to social media by recipients, contained a link to a "wish list" attributed to the "AAFES Security Team." AAFES acknowledged that link publicly and warned that other messages "may also be circulating."
Julie Mitchell, AAFES vice president for marketing customer engagement, urged customers not to click links, open attachments, or provide personal or payment information in response to unexpected messages. "The message should be deleted," she said.
Mitchell told DefenseScoop the organization hasn't yet determined whether the emails used AAFES's official system or a spoofed address. Social media screenshots showed what appeared to be a standard no-reply Exchange address, but that alone doesn't confirm origin. The app push notifications are a different matter, those went through AAFES's own infrastructure.
That's what separates this from run-of-the-mill military phishing. Ally Armeson, a former Army officer who now leads FightCybercrime.org, told DefenseScoop the incident is "quite different" from other scams targeting service members and veterans: the messages used an official channel, targeted Exchange customers specifically, and required the sender to know at minimum a customer email address or app-linked account. "All of this sort of points to there's a breach somewhere or someone got in," Armeson said, adding that the compromise could have occurred at AAFES or through a third-party partner.
What AAFES isn't saying yet
Mitchell declined to say where the messages originated, citing the ongoing investigation. She also said AAFES was still determining the impact and that its customer contact center had seen only a "small uptick" in calls. On the question of a security breach, Mitchell didn't answer directly, stating only that if personally identifiable information "is compromised, direct and timely notification to impacted customers is standard operating procedure."
The Defense Department and Army deferred all questions to the Exchange. Air Force spokespeople hadn't responded by DefenseScoop's publication time.
The military community is a recurring target for scams (fake job offers, identity theft, benefits poaching) but those campaigns typically rely on broad distribution and spoofed addresses to cast a wide net. A message pushed through the My Exchange app narrows the blast radius to people who are verifiably Exchange customers. That precision, combined with the app as a delivery mechanism, raises the stakes beyond a routine phish.
Published ·Deep Fathom