The break is in the error-handling layer, not the homepage. An attacker who can control 404 responses can make a site look defaced even when the main pages still seem intact, so a normal front-page check misses the compromise.
CyberScoop confirmed defaced 404 pages on two U.S. Army subdomains, oil.army.mil and ai2c.army.mil, and the Army took both sites offline after being contacted. The pages carried pro-Kurdish messages and insults, and the pattern across multiple subdomains points to shared hosting or configuration exposure rather than a single-page prank.
That matters because error pages and other non-core web paths can be separately hijacked on WordPress and cloud-hosted subdomains. The visible damage can spread across sibling sites even when most of the site still responds normally.