Breach report
MessagingTeleMessage (Smarsh)
TeleMessage, a modified Signal clone used by US government officials, has been hacked
TeleMessage, which sells archiving versions of Signal and other messengers to governments and firms, was hacked in May 2025, days after a photo showed former US national security adviser Mike Waltz using it.
Reported by TechCrunch
Records exposed
Undisclosed
Undisclosed
- When
- 2025
- How they got in
- Exploitation of exposed server endpoint; messages archived without end-to-end encryption
- Sector
- Messaging
In early May 2025, 404 Media reported that a hacker had broken into TeleMessage, an Israeli-founded company that makes modified versions of Signal, WhatsApp, Telegram and WeChat. Those apps copy messages to an archive so that organizations can meet record-keeping rules. The breach landed just days after a news photograph showed then-national security adviser Mike Waltz using TeleMessage's Signal clone during a cabinet meeting, turning an obscure compliance tool into a national story.
The hacker told 404 Media the intrusion took minutes. The data obtained included archived messages and group chats, contact information for government officials, and credentials for TeleMessage's backend systems. Samples pointed to users at US Customs and Border Protection, cryptocurrency exchange Coinbase and several financial institutions. There was no indication that messages from Waltz or other cabinet members were captured in this incident.
The central security issue was architectural. TeleMessage marketed its apps as retaining Signal's encryption, but the archived chat logs were not end-to-end encrypted between the modified app and the archive, meaning the company's servers could see message contents in plain text. Later analysis by independent researchers suggested that a publicly exposed diagnostic endpoint on TeleMessage's servers could return memory snapshots containing messages and credentials. The US Cybersecurity and Infrastructure Security Agency subsequently added TeleMessage flaws to its catalog of known exploited vulnerabilities.
Smarsh, the Portland, Oregon-based communications archiving company that owns TeleMessage, suspended all TeleMessage services while it investigated with outside security experts. Coinbase said it had no evidence that sensitive customer information was accessed. Lawmakers including Senator Ron Wyden called for a federal investigation into the use of the app by government officials, and transparency group DDoSecrets later published a large trove of data derived from the exposed servers.
The TeleMessage hack illustrates the tension between secure messaging and legal requirements to preserve records. Bolting an archive onto an encrypted messenger creates a centralized store that can undo the protections users think they have. For government agencies and regulated firms, the lesson is that compliance tools need the same security scrutiny as the systems they supplement, and that a secure app is only as secure as the least-protected place its data ends up.