Signal Clone Used By Trump Officials Reportedly Breached — Hacker Says It Took 20 Minutes
A hacker breached TeleMessage, a government-approved messaging app used by Trump administration officials, exposing archived communications from the platform’s modified version of Signal, 404 Media reported. TeleMessage…


A hacker breached TeleMessage, a government-approved messaging app used by Trump administration officials, exposing archived communications from the platform’s modified version of Signal, 404 Media reported.
TeleMessage modifies popular encrypted apps like Signal, WhatsApp and Telegram to comply with federal archiving rules, and was recently thrust into the spotlight after former National Security Advisor Mike Waltz was photographed using the service at a cabinet meeting. The breach allowed the attacker to extract sensitive data belonging to Customs and Border Protection (CBP) officials, cryptocurrency exchange Coinbase and crypto lobbyists involved in promoting legislation in the Senate, according to the outlet.
“I would say the whole process took about 15-20 minutes,” the hacker told 404 Media. “It wasn’t much effort at all … If I could have found this in less than 30 minutes then anybody else could too. And who knows how long it’s been vulnerable?”
The hacker reportedly did not access messages belonging to cabinet officials or Waltz himself.
The data reportedly includes group chat contents, direct messages, phone numbers, email addresses and internal credentials scraped from TeleMessage’s backend system. One exposed conversation, allegedly tied to crypto firm Galaxy Digital, revealed real-time discussions about legislative whip counts for a cryptocurrency bill — chatter that included mentions of Democratic Senators Angela Alsobrooks and Kirsten Gillibrand, the outlet reported.
The breach, reportedly hosted through a vulnerable Amazon Web Services endpoint, appears to have exposed select communications from multiple federal agencies and financial institutions. One screenshot, verified by 404 Media, listed nearly 750 names and contact details associated with CBP. Another reportedly displayed metadata from Coinbase and Scotiabank, including contact information of current and former employees.


