A hacker breaches TeleMessage, which makes modified versions of apps like Signal used by US officials including JD Vance, leaking some chats, contacts, and more
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked. — 💡
micahflee Micah Lee
Context & Ripple Effects
TeleMessage’s appeal was to add archiving to Signal-derived communications for government users. Subsequent coverage found that its TM SGNL product sent decrypted chat logs to TeleMessage’s archive server, making the archive layer—not Signal’s core service—the key exposure point.
The incident developed from an initial breach into evidence of a basic misconfiguration and a broader data haul, including messages from more than 60 government users. That sequence makes the security and governance of compliance-oriented messaging modifications consequential.
First-order effects
- TeleMessage customers and affected officials must treat exposed chats, contacts, and related metadata as compromised, creating immediate operational and privacy risk.
- TeleMessage’s archiving product faces scrutiny because the added retention path appears to have created a plaintext repository that attackers could access.
Second-order effects
- Government agencies using archived messaging will need to reassess whether vendor-operated retention systems preserve the security properties users expect from Signal-derived apps.
- The breach raises the bar for vendors selling compliant messaging overlays: customers will focus on archive-server configuration, encryption boundaries, and access controls rather than the underlying messenger’s brand.
Third-order effects
- If organizations continue to layer retention and records-management requirements onto encrypted messengers, the archive layer may become the dominant security and procurement risk.
- The episode could accelerate a split between secure communications tools and compliance capture systems unless vendors can demonstrate that added oversight does not create centralized plaintext targets.
The trend: Encrypted messaging is increasingly being reshaped by enterprise and government compliance layers whose data-retention architecture can weaken the protections of the underlying app.
Related: Signal licensing · TeleMessage · Signal · How TeleMessage was breached · TeleMessage plaintext archive analysis · TeleMessage government-user data haul
Related Coverage
- TM SGNL, the obscure unofficial Signal app Mike Waltz uses to text with Trump officials micahflee · Micah Lee
- Here's the source code for the unofficial Signal app used by Trump officials micahflee · Micah Lee
- Photo appears to show Mike Waltz using Signal-like app that can archive messages NBC News
- Signal Clone Used by Former National Security Advisor Reportedly Hacked PCMag · Jibin Joseph
- Company behind modified Signal app used by Mike Walz allegedly hacked CSO · John E. Dunn
- Signal Clone App Used by Trump Officials Breached in Minutes CyberInsider · Alex Lekander
- TeleMessage, a modified Signal clone used by US govt. officials, has been hacked TechCrunch
- A hacker stole data from TeleMessage, the firm that sells modified versions of Signal to the U.S. gov Security Affairs · Pierluigi Paganini
- A hacker stole content from the Telemessage system used by the US government Metacurity · Cynthia B Brumfield
- The Signal Clone the Trump Admin Uses Was Hacked 404 Media · Joseph Cox
- Hacker breaches TeleMessage system used by US officials, raising security concerns TechSpot · Skye Jacobs
- Tech site 404 Media says Signal-like app used by Trump adviser was hacked Reuters
- Secret Messaging: I Have a Bridge in Brooklyn to Sell You Beyond Search · Stephen E. Arnold
- 👊🇺🇸🔥 — On one hand, I tend to think that aside from things … Eschaton · Atrios
- Modified Signal App Used by Trump Admin Officials Has Been Hacked WinBuzzer · Markus Kasanmascheff
- The Signal app clone used by Trump's administration was hacked in less than 30 mins SiliconANGLE · Mike Wheatley
- TeleMessage, Used by Various U.S. Government Officials, Has Been Breached Pixel Envy · Nick Heer
- And now after all of the experts clarifying that the problem isn't that Signal is insecure it turns out they were actually using a special third party fork of Signal that had extra bugs and attack surfaces added. — https://micahflee.com/... @ckape@teh.entar.net · Brian Danger Hicks
- so not only did US gov members use a signal clone, the company behind that also really took into open source and leaked their own sad code on their press. including a hardcoded token — https://micahflee.com/... thx @micahflee for the awesome blog @cy@chaos.social · Chris
- The third party version of Signal the White House has been using has been hacked, and Signal messages from devices stolen (as they were being sent to the supplier). — This includes group chat messages. The suppliers website has disappeared as of writing this toot. — https://www.404media.co/... @GossiTheDog@cyberplace.social · Kevin Beaumont
- TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. “I would say the whole process took about 15-20 minutes,” the hacker said https://micahflee.com/... @micahflee@infosec.exchange · Micah Lee
- So you said it couldn't get any worse? :elmo_fire: — https://micahflee.com/... “Here's the source code for the unofficial Signal app used by Trump officials” — “The source code contains hardcoded credentials and other vulnerabilities.” — #usa #trump #infosec #CyberSecurity #threatintel #programming @reynardsec@infosec.exchange · ReynardSec
- The code of the unofficial Signal app used to execute #SignalGate has been shared (leaked?). It's on github now and the analysis has started. … Christian Folini
- The Signal Clone the Trump Admin Uses Was Hacked Hacker News
- Technical analysis of TM SGNL, the unofficial Signal app Trump officials used Hacker News
Discussion
-
@dzaia40
Dave Czaja
on bluesky
Is it being hacked when you are invited? — micahflee.com/the-signal-c...
-
@trumpwatch
@trumpwatch
on bluesky
“Mike Waltz using the unofficial Signal app, TM SGNL, to text Trump officials is just the latest in a pattern of secrecy and shady dealings. This is the same guy who invited The Atlantic's editor into a secret chat about Trump's war crimes. What's next, Mike? #Resist” — mica…
-
@joemenn
Joseph Menn
on bluesky
The tool used by White House officials to archive Signal chats has been hacked by someone who acquired stored chats by other government officials. www.404media.co/the-signal-c...
-
@joshtpm
Josh Marshall
on bluesky
Very very important follow up on the Signal story . The clone version of Signal White House officials are using is so insecure it's already been hacked. www.404media.co/the-signal-c...
-
@reichlinmelnick
Aaron Reichlin-Melnick
on bluesky
Incredible. Hacked Signal chats of CBP officials are now floating out there. [embedded post]
-
@justinhendrix
Justin Hendrix
on bluesky
I guess the FBI finally got that backdoor it wanted.... wait.... [embedded post]
-
@josephcox
Joseph Cox
on bluesky
Here is a screenshot the hacker provided of their access to TeleMessage's systems. This was a list of Customs and Border Protection officials. I called a bunch of them, confirmed the numbers do belong to CBP officials www.404media.co/the-signal-c... [image]
-
@rondeibert
Ron Deibert
on bluesky
Wow #signalgate is the gift that keeps on giving — see also @micahflee.com: micahflee.com/the-signal-c... [embedded post]
-
@leahmcelrath
Leah McElrath
on bluesky
“A hacker has gained access to the Signal message archiving tool which Mike Waltz accidentally revealed to the world.” — Even if it hadn't been hacked, the tool archives messages to an IP address located in Israel. One has to wonder about the Israeli government's access. — m…
-
@pecunium
@pecunium
on bluesky
This hacker didn't get Cabinet chats. — Dollars to donuts this wasn't the only person to get into their database. micahflee.com/the-signal-c...
-
@josephcox
Joseph Cox
on bluesky
Here is an example of a message that was obtained by the hacker. There are Signal group chats too. This is the risk of archiving systems: they're no longer end-to-end encrypted. It introduces massive new risk www.404media.co/the-signal-c... [image]
-
@jasonkoebler
Jason Koebler
on bluesky
SCOOP: The Signal clone used by Trump admin that Mike Waltz was seen using in a cabinet meeting in has been hacked www.404media.co/the-signal-c...
-
@micahflee.com
Micah Lee
on bluesky
I wrote up a detailed analysis of TM SGNL, the unofficial Signal app that senior Trump fascists use to organize their war crimes micahflee.com/tm-sgnl-the-...
-
@dbnewtondoors
@dbnewtondoors
on bluesky
www.nbcnews.com/tech/securit... We are not secure as long as these fools are in power. They only think about themselves and their current performance for the orange asshole. — They have to go - our security is being destroyed from within.
-
@kevincollier
Kevin Collier
on bluesky
I've been traveling so forgive me for not posting this yesterday, but: That Signal clone app for archiving messages that Mike Waltz has been using, TeleMessage? It's unlicensed. Signal was unaware of its existence until they saw it in that Reuters photo. There's no known secur…
-
@kevincollier
Kevin Collier
on bluesky
Signalgate was a little confusing in that there were multiple things to be outraged about. Some thought Signal itself was insecure, when the evidence doesn't suggest that. Using an unauthorized Signal knockoff? That's actual cause for concern.
-
@lastofhiskind
John
on x
If what is being said about TeleMessage is true then this is arguably the greatest intelligence failure since Snowden. - Hardcoded credentials - messages archived on Github - built in back doors This is the app used by bulk of highest security officials in the nation, including …
-
@ur_ninja
@ur_ninja
on x
The app itself appears as “TM SGNL” and it's a fork of Signal — an alternate version which can still message other Signal users, but it pushes archive copies of everything sent and received to another server. screenshots from the TeleMessage vendor video [image]
-
@thinkwiselymatt
Matt
on x
Only in 3 files [link] looks like it sends logs somewhere — back of napkin quick analysis - phone owner knows this app on phone — messages are sent and achieved to known location - other people intercepting or grabbing communications - unlikely - real potential risk — people inse…
-
@joshtpm
Josh Marshall
on x
Very very important follow up on the Signal story . The clone version of Signal White House officials are using is so insecure it's already been hacked. https://www.404media.co/...
-
@ur_ninja
@ur_ninja
on x
Official developer docs show TeleMessage's “tech stack” has included a user management function that connects directly with a WordPress site. Unicorn Riot found that at least one access pattern must have been implemented through the #WordPress Gravity Forms plugin. [image]
-
@_mg_
@_mg_
on x
All the people who actually think the gov has a backdoor in Signal are real quiet right now. 😂 Multiple departments have been using this clone of Signal just to keep copies of their messages. It's so busted that it only took 20min effort to start reading people's messages.
-
@jason_koebler
Jason Koebler
on x
SCOOP: The Signal clone used by Trump admin that Mike Waltz was seen using in a cabinet meeting in has been hacked https://www.404media.co/...
-
@chalicotherex
Adam Threeze
on x
“Another screenshot obtained by 404 Media mentions Scotiabank. Financial institutions might turn to a tool like TeleMessage to comply with regulations around keeping copies of business communications.” Well that's not good
-
@mikebutcher
Mike Butcher
on x
Astounding that these people are in charge. The damage done to the US must be incalculable at this point.
-
@weareoversight
@weareoversight
on x
It's not clear if Waltz began using TeleMessage months ago, or after we sued for failure to comply with records laws. But it underscores a dangerous reliance on tools that threaten the integrity of official records. https://www.nytimes.com/...
-
@ericgeller
Eric Geller
on x
“The hack shows that an app gathering messages of the highest ranking officials in the government...contained serious vulnerabilities that allowed a hacker to trivially access the archived chats of some people who used the same tool.” https://www.404media.co/...
-
@silvermanjacob
Jacob Silverman
on x
As intended https://www.404media.co/...
-
@ur_ninja
@ur_ninja
on x
The “TM SGNL” message was oddly different on Waltz's phone, which quickly led people to a software vendor called TeleMessage that is based in Israel. TeleMessage is owned by Portland, Oregon-based Smarsh.
-
@jason_paladino
Jason Paladino
on x
From the photo, it appears they're now using an Israeli firm's archiver/wrapper app called TeleMessage, hence the “TM SGNL” in the PIN popup. Means they are attempting to archive to comply with federal records laws... but I'm skeptical of security implications. [image]
-
@_mg_
@_mg_
on x
People were concerned that gov record retention laws were being broken due to the use of Signal. This picture shows that's not the case! See the “TM SGNL” on screen? That's a Signal wrapper specifically for maintaining archives of the messages. https://www.telemessage.com/ ... I …
-
@caseyjohnellis
@caseyjohnellis
on x
“The source code contains hardcoded credentials and other vulnerabilities.” 🫠 🫠 🫠 https://micahflee.com/...
-
@jason_paladino
Jason Paladino
on x
@404mediaco ... I speculated about the potential for hackers to access the archived messages in @DropSiteNews. If these hackers could get in so easily, highly likely some intelligence agencies are already in there. Also it seems like they're just lying about the archives being en…
-
@jason_paladino
Jason Paladino
on x
Wow, just a few days after revelations that's Mike Waltz was using an Israeli Signal clone to archive messages, the app has been hacked. Via @404mediaco. It took the hacker 15-20 mins, exposed unencrypted archives, including CBP data. These are not serious people. Link below [ima…
-
@matthew_d_green
@matthew_d_green
on x
Micah Lee is spending his weekend poking through the TeleMessage Signal app source code. So far it looks like they use hard-coded credentials. I'm sure it's going to produce exciting results in the future. https://micahflee.com/...
-
r/Military
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/inthenews
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/signal
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/neoliberal
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/technology
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/NoShitSherlock
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/cybersecurity
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/law
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/technology
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/politics
r
on reddit
The Signal Clone the Trump Admin Uses Was Hacked
-
r/signal
r
on reddit
TM SGNL, the obscure unofficial Signal app Mike Waltz uses to text with Trump officials
-
r/republicans
r
on reddit
Here's the source code for the unofficial Signal app used by Trump officials, TeleMessage. The source code contains hardcoded credentials and other vulnerabilities.