/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A hacker breaches TeleMessage, which makes modified versions of apps like Signal used by US officials including JD Vance, leaking some chats, contacts, and more

TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.  —  💡

micahflee Micah Lee

Context & Ripple Effects

TeleMessage’s appeal was to add archiving to Signal-derived communications for government users. Subsequent coverage found that its TM SGNL product sent decrypted chat logs to TeleMessage’s archive server, making the archive layer—not Signal’s core service—the key exposure point.

The incident developed from an initial breach into evidence of a basic misconfiguration and a broader data haul, including messages from more than 60 government users. That sequence makes the security and governance of compliance-oriented messaging modifications consequential.

First-order effects

  • TeleMessage customers and affected officials must treat exposed chats, contacts, and related metadata as compromised, creating immediate operational and privacy risk.
  • TeleMessage’s archiving product faces scrutiny because the added retention path appears to have created a plaintext repository that attackers could access.

Second-order effects

  • Government agencies using archived messaging will need to reassess whether vendor-operated retention systems preserve the security properties users expect from Signal-derived apps.
  • The breach raises the bar for vendors selling compliant messaging overlays: customers will focus on archive-server configuration, encryption boundaries, and access controls rather than the underlying messenger’s brand.

Third-order effects

  • If organizations continue to layer retention and records-management requirements onto encrypted messengers, the archive layer may become the dominant security and procurement risk.
  • The episode could accelerate a split between secure communications tools and compliance capture systems unless vendors can demonstrate that added oversight does not create centralized plaintext targets.

The trend: Encrypted messaging is increasingly being reshaped by enterprise and government compliance layers whose data-retention architecture can weaken the protections of the underlying app.

Discussion

  • @dzaia40 Dave Czaja on bluesky
    Is it being hacked when you are invited?  —  micahflee.com/the-signal-c...
  • @trumpwatch @trumpwatch on bluesky
    “Mike Waltz using the unofficial Signal app, TM SGNL, to text Trump officials is just the latest in a pattern of secrecy and shady dealings.  This is the same guy who invited The Atlantic's editor into a secret chat about Trump's war crimes.  What's next, Mike?  #Resist”  —  mica…
  • @joemenn Joseph Menn on bluesky
    The tool used by White House officials to archive Signal chats has been hacked by someone who acquired stored chats by other government officials. www.404media.co/the-signal-c...
  • @joshtpm Josh Marshall on bluesky
    Very very important follow up on the Signal story .  The clone version of Signal White House officials are using is so insecure it's already been hacked. www.404media.co/the-signal-c...
  • @reichlinmelnick Aaron Reichlin-Melnick on bluesky
    Incredible.  Hacked Signal chats of CBP officials are now floating out there.  [embedded post]
  • @justinhendrix Justin Hendrix on bluesky
    I guess the FBI finally got that backdoor it wanted.... wait....  [embedded post]
  • @josephcox Joseph Cox on bluesky
    Here is a screenshot the hacker provided of their access to TeleMessage's systems.  This was a list of Customs and Border Protection officials.  I called a bunch of them, confirmed the numbers do belong to CBP officials www.404media.co/the-signal-c...  [image]
  • @rondeibert Ron Deibert on bluesky
    Wow #signalgate is the gift that keeps on giving  —  see also @micahflee.com: micahflee.com/the-signal-c...  [embedded post]
  • @leahmcelrath Leah McElrath on bluesky
    “A hacker has gained access to the Signal message archiving tool which Mike Waltz accidentally revealed to the world.”  —  Even if it hadn't been hacked, the tool archives messages to an IP address located in Israel.  One has to wonder about the Israeli government's access.  —  m…
  • @pecunium @pecunium on bluesky
    This hacker didn't get Cabinet chats.  —  Dollars to donuts this wasn't the only person to get into their database. micahflee.com/the-signal-c...
  • @josephcox Joseph Cox on bluesky
    Here is an example of a message that was obtained by the hacker.  There are Signal group chats too.  This is the risk of archiving systems: they're no longer end-to-end encrypted.  It introduces massive new risk www.404media.co/the-signal-c...  [image]
  • @jasonkoebler Jason Koebler on bluesky
    SCOOP: The Signal clone used by Trump admin that Mike Waltz was seen using in a cabinet meeting in has been hacked www.404media.co/the-signal-c...
  • @micahflee.com Micah Lee on bluesky
    I wrote up a detailed analysis of TM SGNL, the unofficial Signal app that senior Trump fascists use to organize their war crimes micahflee.com/tm-sgnl-the-...
  • @dbnewtondoors @dbnewtondoors on bluesky
    www.nbcnews.com/tech/securit...  We are not secure as long as these fools are in power.  They only think about themselves and their current performance for the orange asshole.  —  They have to go - our security is being destroyed from within.
  • @kevincollier Kevin Collier on bluesky
    I've been traveling so forgive me for not posting this yesterday, but: That Signal clone app for archiving messages that Mike Waltz has been using, TeleMessage?  It's unlicensed.  Signal was unaware of its existence until they saw it in that Reuters photo.  There's no known secur…
  • @kevincollier Kevin Collier on bluesky
    Signalgate was a little confusing in that there were multiple things to be outraged about.  Some thought Signal itself was insecure, when the evidence doesn't suggest that.  Using an unauthorized Signal knockoff?  That's actual cause for concern.
  • @lastofhiskind John on x
    If what is being said about TeleMessage is true then this is arguably the greatest intelligence failure since Snowden.  - Hardcoded credentials - messages archived on Github - built in back doors This is the app used by bulk of highest security officials in the nation, including …
  • @ur_ninja @ur_ninja on x
    The app itself appears as “TM SGNL” and it's a fork of Signal — an alternate version which can still message other Signal users, but it pushes archive copies of everything sent and received to another server. screenshots from the TeleMessage vendor video [image]
  • @thinkwiselymatt Matt on x
    Only in 3 files [link] looks like it sends logs somewhere — back of napkin quick analysis - phone owner knows this app on phone — messages are sent and achieved to known location - other people intercepting or grabbing communications - unlikely - real potential risk — people inse…
  • @joshtpm Josh Marshall on x
    Very very important follow up on the Signal story . The clone version of Signal White House officials are using is so insecure it's already been hacked. https://www.404media.co/...
  • @ur_ninja @ur_ninja on x
    Official developer docs show TeleMessage's “tech stack” has included a user management function that connects directly with a WordPress site. Unicorn Riot found that at least one access pattern must have been implemented through the #WordPress Gravity Forms plugin. [image]
  • @_mg_ @_mg_ on x
    All the people who actually think the gov has a backdoor in Signal are real quiet right now. 😂 Multiple departments have been using this clone of Signal just to keep copies of their messages. It's so busted that it only took 20min effort to start reading people's messages.
  • @jason_koebler Jason Koebler on x
    SCOOP: The Signal clone used by Trump admin that Mike Waltz was seen using in a cabinet meeting in has been hacked https://www.404media.co/...
  • @chalicotherex Adam Threeze on x
    “Another screenshot obtained by 404 Media mentions Scotiabank. Financial institutions might turn to a tool like TeleMessage to comply with regulations around keeping copies of business communications.” Well that's not good
  • @mikebutcher Mike Butcher on x
    Astounding that these people are in charge. The damage done to the US must be incalculable at this point.
  • @weareoversight @weareoversight on x
    It's not clear if Waltz began using TeleMessage months ago, or after we sued for failure to comply with records laws. But it underscores a dangerous reliance on tools that threaten the integrity of official records. https://www.nytimes.com/...
  • @ericgeller Eric Geller on x
    “The hack shows that an app gathering messages of the highest ranking officials in the government...contained serious vulnerabilities that allowed a hacker to trivially access the archived chats of some people who used the same tool.” https://www.404media.co/...
  • @silvermanjacob Jacob Silverman on x
    As intended https://www.404media.co/...
  • @ur_ninja @ur_ninja on x
    The “TM SGNL” message was oddly different on Waltz's phone, which quickly led people to a software vendor called TeleMessage that is based in Israel. TeleMessage is owned by Portland, Oregon-based Smarsh.
  • @jason_paladino Jason Paladino on x
    From the photo, it appears they're now using an Israeli firm's archiver/wrapper app called TeleMessage, hence the “TM SGNL” in the PIN popup. Means they are attempting to archive to comply with federal records laws... but I'm skeptical of security implications. [image]
  • @_mg_ @_mg_ on x
    People were concerned that gov record retention laws were being broken due to the use of Signal. This picture shows that's not the case! See the “TM SGNL” on screen? That's a Signal wrapper specifically for maintaining archives of the messages. https://www.telemessage.com/ ... I …
  • @caseyjohnellis @caseyjohnellis on x
    “The source code contains hardcoded credentials and other vulnerabilities.” 🫠 🫠 🫠 https://micahflee.com/...
  • @jason_paladino Jason Paladino on x
    @404mediaco ... I speculated about the potential for hackers to access the archived messages in @DropSiteNews. If these hackers could get in so easily, highly likely some intelligence agencies are already in there. Also it seems like they're just lying about the archives being en…
  • @jason_paladino Jason Paladino on x
    Wow, just a few days after revelations that's Mike Waltz was using an Israeli Signal clone to archive messages, the app has been hacked. Via @404mediaco. It took the hacker 15-20 mins, exposed unencrypted archives, including CBP data. These are not serious people. Link below [ima…
  • @matthew_d_green @matthew_d_green on x
    Micah Lee is spending his weekend poking through the TeleMessage Signal app source code. So far it looks like they use hard-coded credentials. I'm sure it's going to produce exciting results in the future. https://micahflee.com/...
  • r/Military r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/inthenews r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/signal r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/neoliberal r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/technology r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/NoShitSherlock r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/cybersecurity r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/law r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/technology r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/politics r on reddit
    The Signal Clone the Trump Admin Uses Was Hacked
  • r/signal r on reddit
    TM SGNL, the obscure unofficial Signal app Mike Waltz uses to text with Trump officials
  • r/republicans r on reddit
    Here's the source code for the unofficial Signal app used by Trump officials, TeleMessage.  The source code contains hardcoded credentials and other vulnerabilities.