On 9 October 2026, the Houthis warned airlines to stay out of Saudi airspace. Flights, crews, and passengers would be exposed to missile operations, the notice said, with exceptions made only for the airspace over Mecca and Medina.
The warning appeared at hocc.gov.ye, a website existing inside Yemen’s official government namespace. Its publisher, the Humanitarian Operations Coordination Center (HOCC), used the platform to disclaim responsibility for the consequences if airlines continued operating in the areas it named.
That same day, Houthi military spokesman Yahya Saree announced an exception: humanitarian flights to and from Riyadh would be permitted, but only if they obtained authorization from HOCC in Sana’a. The announcement was carried by the Saba outlet operating from the Houthi-controlled capital.
An organization belonging to an armed movement threatening commercial aviation was presenting itself as the administrative office from which airlines should seek permission to fly.
Those statements accompanied deadly attacks. On 11 October, the Associated Press reported another strike on a passenger terminal at Riyadh airport, following a strike the previous day that killed 12 people. The Houthis claimed responsibility for both.
The Facade of State Authority
The website gives this arrangement a purely administrative form. It hosts sanctions lists, legal documents, application procedures, and contact addresses. Crucially, its .gov.ye domain suffix supplies a claim to authority—and HOCC expressly tells readers to rely on it.
The first item on both the Arabic and English FAQ pages—still numbered 23—explains how to recognize email from an official Yemeni government body: recipients should check that the address ends in .gov.ye before replying or sharing information and documents. The next answer, numbered 22, identifies hocc.gov.ye as the domain used for HOCC’s own correspondence.
The organization is actively asking businesses to treat its control of a government web address as a reason to trust the sender.
The Shipping Precedent (2024–2025)
That claim to authority has already been challenged in a formal international record.
In February 2024, HOCC sent the International Maritime Organization (IMO) an email setting out categories of vessels subject to a shipping ban, offering operational coordination. The reproduced message displays [email protected] as its sender and copies [email protected]. A public Saba post dated 22 February promoted HOCC using the same two addresses.
Yemen’s internationally recognized embassy in London subsequently rejected HOCC’s claim to represent the government. Its letter, dated 12 March, was circulated two days later as IMO Circular Letter 4854. The Philippine Maritime Industry Authority preserves the circular and an advisory recording the government’s objection.
Below are all three pages of the letter and email annex. Download the three-page PDF.


Despite the IMO circular, the domain remained active and continued to appear in threatening correspondence.
The UN Panel of Experts’ 2024 Yemen report reproduces a message concerning the vessel CYCLADES, with [email protected] as the displayed sender. It demanded a response and an end to voyages to Israeli ports. A following annex reproduces a separate message threatening the vessel ALEXANDRIA with direct targeting and its associated fleet with further sanctions.
The Panel identified HOCC as an organization established under the office of Houthi political council president Mahdi al-Mashat (paragraph 60, annexes 34–36). The evidence includes a named institution, its leadership relationship, and the correspondence sent to shipping companies.
By May 2025, HOCC was publishing restrictions on US crude oil shipments and threatening the fleets of companies it considered in violation. Applications for exceptions were directed to [email protected].
The October 2026 Saudi aviation announcements simply extend this established practice to flights. Restrictions backed by threatened military action come with a bureaucratic procedure for requesting an exemption, and the same national domain hosts both.
The IANA Delegation and Infrastructure Accountability
How that domain is administered matters.
The Internet Assigned Numbers Authority (IANA) delegation record names TeleYemen in Sana’a as the manager of .ye. TeleYemen’s published 2026 registration rules reserve .gov.ye strictly for government entities and expressly require registry approval. They also subject existing registrations to continuing obligations and give the operator powers to suspend or delete domains.
Registration creates an ongoing relationship with the operator: the applicant must qualify, receive approval, comply with the rules, and retain permission to operate. HOCC directly benefits from a government-labeled address within that controlled system.
The public documents reviewed here do not identify the official who approved HOCC’s original registration. The 2026 rules also cannot establish which procedure was followed when the domain first appeared in the 2024 correspondence. They do, however, identify the institution responsible for government-domain eligibility and continued registration.
Houthi control of Yemen’s internet institutions predates HOCC. Cybersecurity firm Recorded Future has previously documented Houthi supervision of YemenNet after the capture of Sana’a, along with changes to government websites in the .ye namespace to reflect Houthi authority.
The hocc.gov.ye record shows a specific, deadly consequence of that control. Yemen’s national internet identity now supports an office that publishes military threats, claims authority over civilian transport, and invites global businesses to submit requests through its official channels.
For reporters investigating the attacks, the domain supplies a documentary trail extending back to 2024. But for the international community and the bodies governing global internet infrastructure, it represents a profound systemic vulnerability. HOCC’s operation is no longer just a localized anomaly; it is a blueprint.
By allowing an armed group to run an extortion racket through a strictly regulated, state-sanctioned internet registry, the global governance of the web is failing a critical test. If infrastructure bodies like ICANN, IANA, and international regulators treat this as a purely domestic issue, they establish a dangerous precedent: that the global trust architecture of the internet can be openly weaponized to legitimize violence without consequence.
HOCC’s own advice to its audience is to inspect its web address before deciding whom to trust. The world should take that advice, recognize the severe precedent this domain sets, and hold the authorities keeping it online accountable—before this model of digital extortion is adopted by others.
Our work and the evidence archive
FreeTheDotYE investigates the use of Yemen’s national internet infrastructure and publishes the records behind its findings. Read our investigations and published correspondence to follow the work.
Our public .YE Domain Ledger brings together registration, DNS, certificate, screenshot and web-archive observations. Start with the hocc.gov.ye record to inspect the infrastructure behind this article.
The underlying evidence is available on GitHub:
- Domain corpus and DNS monitoring, including the web archive and its checksums and a downloadable WARC archive.
- Registration records, with normalized RDAP and WHOIS data.
- Website screenshot archive, with dated captures and integrity checks.
For the wider context, read When a Militia Owns a Country’s Domain.