The messaging app TeleMessage, used by Donald Trump’s former National Security Advisor Mike Waltz, has been hacked, raising concerns about a possible leak of sensitive government data. An anonymous hacker gained access to TeleMessage, a messaging platform designed to mimic the interface and features of Signal while adding archiving features, according to a report by 404 Media. The tool is reportedly widely used by U.S. government officials and agencies to comply with record retention requirements.
See also: Donald Trump: Meeting at the White House about TikTok

However, the breach revealed serious weaknesses in the security of archived messages. While no messages from Waltz or other government officials were accessed, the breach did expose archived communications from other TeleMessage users, including data seemingly tied to government agencies like Customs and Border Protection, as well as private companies like Coinbase. Screenshots reviewed by 404 Media show usernames, passwords, backend dashboards, and chat snippets, all obtained through a security flaw that the hacker said was easy to exploit.
The hackers said they breached the system out of curiosity and did not inform TeleMessage of the problem, claiming that the companywould likely “try to cover it up as best they could.”
According to the report, the hacker was able to access the company's backend control panel using login details found in a hacked file. He was also able to view portions of conversations sent via modified versions of popular messaging apps, including WhatsApp, Telegram, and WeChat.
Smarsh, the Portland-based company that owns TeleMessage and is in the process of rebranding the app under the new name Capture Mobile, has not yet responded to requests for comment. Neither Mike Waltz nor the White House have commented publicly.
See also: Donald Trump: TikTok deal before deadline?

Signal, known for its strong edge-to-edge encryption, distanced itself from the copycat app, with a spokesperson telling Reuters that it “cannot guarantee the privacy or security of unofficial versions of Signal.”
Waltz came under public scrutiny last week after Reuters published a photo of him using the TeleMessage app during a cabinet meeting with former President Trump. His ouster on Thursday followed weeks of backlash over a Signal group he allegedly created to share real-time updates on U.S. military activity in Yemen. The group came under intense scrutiny when a prominent journalist was accidentally added to the conversation, either by Waltz himself or another member.
The incident has reignited concerns about the use of modified versions of secure applications that have archiving capabilities in high-level government environments. While these additional features are intended to preserve official records, they may inadvertently create new security vulnerabilities – especially when these systems are not adequately protected.
See also: Michael Waltz: Did he exchange military information via personal Gmail?
An important conclusion from the above incidents is that the attempt to combine transparency (through archiving) with security (through encrypted applications) can fail if the technological solutions are not implemented properly or are not accompanied by strict risk management procedures. The use of “hacked” versions of secure applications, such as Signal, for archiving purposes – without official support or certification – may nullify the advantages of the original technology and expose critical information to risk.
Source: indiatoday
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
