Distributed Denial of Secrets: the TeleMessage hacker stole messages from 60+ US government users covering about one day ending on May 4, including travel plans
A hacker who breached the communications service used by former Trump national security adviser Mike Waltz earlier … Bluesky: @metacurity.com , @stokel , @zachsdorfman , and @micahflee.com Mastodon: @ddosecrets@kolektiva.social , @malwarejake@infosec.exchange , @ddosecrets@kolektiva.social , and @Bmwalt@infosec.exchange X: @rhinozzcode , @lesleyabravanel , and @verambergen Forums: r/technology and r/technology Bluesky: Cynthia Brumfield / @metacurity.com : OMG the trainwrecks never end — www.reuters.com/world/us/hac... Chris Stokel-Walker / @stokel : This is really, really bad www.reuters.com/world/us/hac... Zach Dorfman / @zachsdorfman : If this contains more substantive conversations between senior U.S. national security officials, this could be the biggest data breach/hack-and-leak in years. — micahflee.com/ddosecrets-p... Micah Lee / @micahflee.com : DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server micahflee.com/ddosecrets-p... [embedded post] Mastodon: @ddosecrets@kolektiva.social : “The trove included material from disaster responders, customs officials, several U.S. diplomatic staffers, at least one White House staffer and members of the Secret Service.” — https://www.reuters.com/... Jake Williams / @malwarejake@infosec.exchange : Great reporting highlighting that TeleMessage was much more widely used in government than previously reported. — I'll say it again: every foreign intelligence service worth its salt had access to this data. This is a *monumental* security failure by the Trump admin. — https://www.reuters.com/... @ddosecrets@kolektiva.social : Telemssage (410 GB) — https://ddosecrets.com/... Thousands of heap dumps taken May 4, 2025 from TeleMessage, which produces software used to archive encrypted messaging apps such as Signal and WhatsApp. … Brian Walter / @Bmwalt@infosec.exchange : TeleMessage: for when you need “secure” government comms and don't mind a casual 410GB heap dump showing up on DDoSecrets. It's not a breach, it's an archival service! — #signal #Cybersecurity #Infosec — https://micahflee.com/... X: Ryan Fae / @rhinozzcode : today, DDoSecrets released a data behemoth: ~800k files from ISID, “a Spanish company specializing in audio/visual processing,” resulting from a breach by the now-infamous puppygirl hacker polycule. it has clients in the EU, multiple governments, Santander, and so on. [image] Lesley Abravanel / @lesleyabravanel : BUT HUNTER BIDEN'S LAPTOP!: Hacker who breached communications app used by Trump aide stole data from across US government https://www.reuters.com/... Vera Bergengruen / @verambergen : “A hacker who breached the communications service used by former Trump national security adviser Mike Waltz earlier this month intercepted messages from a broader swathe of American officials than has previously been reported” https://www.reuters.com/... Forums: r/technology : Hacker who breached communications app used by Trump aide stole data from across US government r/technology : DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server
Context & Ripple Effects
This disclosure expands the known scope of the initial TeleMessage breach: reporting had already established that the service modified and archived encrypted-message apps used by U.S. officials, while the new material indicates use across more government roles than previously visible.
The incident also follows reporting that a basic TeleMessage misconfiguration enabled a rapid intrusion. That makes the exposure consequential not merely as a single official’s communications problem, but as a failure in an archive layer handling operational government data.
First-order effects
- More than 60 government users now face exposure of a day’s messages, including travel plans, with affected groups spanning diplomatic, customs, disaster-response, White House and Secret Service personnel.
- TeleMessage and the agencies using it face immediate scrutiny over the security of software that archives Signal and WhatsApp communications; the leaked heap dumps make the archive infrastructure itself the central failure point.
Second-order effects
- Agencies may need to reassess whether compliance-oriented message archiving can be safely layered onto encrypted apps, potentially disrupting workflows built around TeleMessage-like tools.
- The breach risks further conflating Signal with the third-party archival products built around it, despite the earlier dispute over an NSA Signal warning; vendors and agencies will need to distinguish app security from deployment and retention controls.
Third-order effects
- If government demand for retained encrypted communications continues, the sector will face a durable trade-off: centralized archives improve retrieval but create high-value repositories whose compromise can expose many users at once.
- The episode points toward greater scrutiny of security assurance and access controls for government communications intermediaries, especially where a single service spans multiple agencies and sensitive operational functions.
The trend: Government adoption of encrypted messaging is increasingly shifting security risk from the messaging app itself to the archival, integration and administration layers around it.