Exclusive: Hacker who breached communications app used by #Trump aide stole data across US govt

A #hacker who breached the comms service used by fmr Trump #NationalSecurity adviser [& current UN ambassador] #MikeWaltz earlier this month intercepted messages from a broader swath of ofcls than previously reported, potentially raising the stakes of a breach that has already drawn questions about #DataSecurity in the Trump admin.

#TeleMessage #Signalgate #InfoSec #idiocracy
https://www.reuters.com/world/us/hacker-who-breached-communications-app-used-by-trump-aide-stole-data-across-us-2025-05-21/

Reuters identified >60 unique govt users of the messaging platform #TeleMessage in a cache of #leaked #data provided by Distributed Denial of Secrets, a US nonprofit whose mission is to archive #hacked & leaked documents in the public interest. The trove included material from disaster responders, #customs ofcls, several US diplomatic staffers, at least 1 #WhiteHouse staffer & members of the #SecretService.

#Trump #NationalSecurity #Signalgate #InfoSec #idiocracy

Once little known outside government and finance circles, #TeleMessage drew media attention after an April 30 Reuters photograph showed #MikeWaltz checking TeleMessage's version of the privacy-focused app #Signal during a cabinet meeting.

While Reuters could not verify the entire contents of the TeleMessage trove, in more than half a dozen cases the news agency was able to establish that the phone numbers in the #leaked #data were correctly attributed to their owners.

#Trump #NationalSecurity

One of the intercepted texts' recipients - an applicant for aid from #FEMA confirmed to Reuters that the #leaked message was authentic; a financial services firm whose messages were similarly intercepted also confirmed their authenticity.

Based on its limited review, Reuters uncovered nothing that seemed clearly sensitive & did not uncover chats by #MikeWaltz or other cabinet ofcls.

#Trump #NationalSecurity #Signalgate #Signal #Telemessage #InfoSec #idiocracy

Some chats did seem to bear on the travel plans of snr govt ofcls. One #Signal group, "POTUS | ROME-VATICAN | PRESS GC," appeared to pertain to the #logistics of an event involving #Trump at the #Vatican. Another appeared to discuss US ofcls' trip to #Jordan.

Reuters reached out to all the individuals it could identify seeking comment; some confirmed their identities but most didn't respond or referred questions to their respective agencies.

#NationalSecurity #Signalgate #InfoSec #idiocracy

Reuters could not ascertain how #TeleMessage had been used by each agency. The service - which takes versions of popular apps & allows their messages to be archived in line w/government rules - has been suspended since May 5, when it went offline "out of an abundance of caution." TeleMessage's owner, the Portland, Oregon-based digital communications firm #Smarsh, did not respond to requests for comments about the #leaked #data.

#Trump #NationalSecurity #Signalgate #Signal #InfoSec #idiocracy

The White House said in a stmnt that it was "aware of the cyber security incident at #Smarsh" but didn't offer comment on its use of the platform. #State didn't respond. The #SecretService said #TeleMessage products had been used "by a small subset of Secret Service employees" & that it was reviewing the situation. #FEMA said in an email that it had "no evidence" that its info had been compromised. It didn't respond when sent copies of internal FEMA msgs.

#Trump #NationalSecurity #InfoSec

A #CBP spox repeated a past stmnt noting that it had disabled #TeleMessage & was investigating.

Federal contracting data shows that #State & #DHS have had contracts w/TeleMessage in recent years, as has the #CDC. A CDC spox told Reuters in an email that the agency piloted the software in 2024 to assess its potential for records management requirements "but found it did not fit our needs." The status of the other contracts wasn't clear.

#Trump #NationalSecurity #Signalgate #InfoSec #idiocracy

A week after that #hack, the #CISA recommended that users "discontinue use of the product" barring any mitigating instructions about how to use the app from #Smarsh.

Jake Williams, a fmr #NationalSecurity Agency #cyber specialist, said that, even if the intercepted text messages were innocuous, the wealth of #metadata - the who & when of the #leaked conversations & chat groups - posed a #counterintelligence risk.

#Trump #Signalgate #Signal #Telemessage #InfoSec #idiocracy