HomeInvestigationsSignalgate and government: why officials shouldn't use Signal

Signalgate and government: why officials shouldn't use Signal

The Dokos affair with the deepfake on Maximou has demonstrated something that the cybersecurity community has long known: Greek officials are now front-line targets for modern, hybrid attacks. The question that legitimately arises is which tool they communicate with when handling sensitive issues — and whether the choice of Signal, which spread rapidly among the political elite after the Signalgate , is really the right one for state operations.

The answer, based on research by the SecNews editorial team and international data from 2025, is clear: Signal is a top tool for individuals, journalists, and activists — but it’s the wrong choice for government classified communications. The fact that ministers, advisors, and senior officials use it daily for sensitive matters is not proof of security — it’s proof of a lack of institutional infrastructure and operational maturity.

Why Signal and the government don't mix

Signal was designed from day one as a tool to protect citizens from mass surveillance. Its philosophy, as the Signal Foundation, is to keep as little data as possible so that it has nothing to hand over to government authorities requesting information. This is good for democracy and press freedom — but it is completely incompatible with the institutional framework of a government that must keep records, have audit trails, and safeguard classified information.

Signal Foundation president Meredith Whittakerhas never advertised Signal as a solution for classified government communications. In an interview with WIRED in September 2025, she said her reaction to Signalgate was “No fucking way” — a clear admission that her tool was not designed for such use. Signal, then, is not the problem: the problem is its misuse by government agencies that have not invested in the proper infrastructure.

See also: Dokos and Deepfake: How the attack on Maximou took place and what are the countermeasures

Signalgate and TeleMessage: the lessons of 2025

The most prominent episode that fully exposed the problem was Signalgate in March 2025 — the largest leak of classified communications via a consumer app in U.S. history. Then-U.S. national security adviser Mike Waltz created a Signal group called the “Houthi PC small group” to coordinate impending strikes in Yemen. He accidentally added Jeffrey Goldberg, editor-in-chief of The Atlantic, while trying to save his number under a colleague’s contact. On March 15, Defense Secretary Pete Hegseth posted the exact aircraft types, missiles, and launch times in the same chat — two to four hours before the attack.

Signal government Signalgate group chat

The Pentagon Inspector General’s finding, released on December 4, 2025, was a cataclysmic blow: Hegseth “endangered the security of American personnel” by transmitting sensitive, unclassified operational information over an unauthorized, insecure network ([Lawfare](https://www.lawfaremedia.org/article/pentagon-inspector-general-releases-report-on-hegseth-s-signal-use)). He violated DoD Directive 8170.01, which specifically prohibits the use of personal devices and unauthorized applications for official business. A few weeks later, the New York Times revealed that the same secretary maintained a second Signal group on his personal cell phone, which included his wife, brother, and lawyer — and where he also shared military details.

The situation worsened in May 2025 with the TeleMessage TM SGNL. It is an Israeli fork of Signal (owned by Smarsh) that archives messages for regulatory compliance. Users like Waltz also kept a copy of their conversations there — and on May 4, a hacker breached the servers in less than 20 minutes. Journalist Micah Lee showed Wired that the app transmits logs in an unencrypted format, completely negating the promise of end-to-end encryption. On May 19, the organization Distributed Denial of Secrets published 410GB of data from the attack.

The lesson of Signalgate is fundamental: any attempt to archive Signal messages for compliance destroys the encryption itself. You can’t have both the security of Signal and the archiving trails required by government agencies — the two are inherently incompatible. After Signalgate, CISA added the TM SGNL vulnerabilities (CVE-2025-47729, CVE-2025-48925) to its list of known exploited vulnerabilities ([Security Affairs](https://securityaffairs.com/177743/hacking/us-cisa-adds-telemessage-tm-sgnl-to-its-known-exploited-vulnerabilities-catalog.html)).

Signal's weaknesses in government use

Beyond Signalgate itself, Signal has structural weaknesses when used by officials — weaknesses that led to Signalgate and that essentially made the crisis inevitable. The most critical one concerns the security of the device itself: encryption protects the message between the two phones, but not within the phone. Any spyware like Pegasus, Predator, or Graphite from Israeli company Paragon reads the messages in their clear form, before they are encrypted. The Greek Predatorgate, where 92 mobile phones of politicians, journalists, and businessmen were monitored via infected SMS, is the definitive proof that the choice of messenger is irrelevant if the device is exposed.

Second weakness: identity is tied to the phone number. This exposes officials to SIM swap attacks, where social engineering at the telecom provider allows an attacker to take over the number. In addition, the provider can be legally forced to cooperate with foreign agencies, creating a jurisdictional risk that no military communication should accept. Government IDs require PKI cards with hardware chips (CAC/PIV in the US, equivalent under ADAE in Greece) — not a mobile number.

See also: Pegasus creator sells antidote to governments through Dream

Third, and perhaps most worryingly, Signal's group management itself is designed for ease of use, not security. Any member can add another user via number, without out-of-band verification. This is exactly what caused Signalgate. Government solutions based on the Matrix protocol (as we'll see below) have built-in identity management via LDAP/Active Directory, where no one enters a sensitive chat without a confirmed government status.

Fourth: Google Threat Intelligence has documented active exploitation of the “linked devices” feature by Russian groups. The attacker sends a fake QR code that looks like an invitation to a group — the victim scans it and grants permanent access to all their future conversations. Fifth: the app does not have any FIPS 140-2/-3, Common Criteria, or NSA CSfC certification, the lists that check whether a tool meets the specifications for classified use. Signal, like any other app downloaded from the App Store, cannot officially support classified information in any Western country.

Sixth: there is no form of compartmentalization. The same application on the same phone is used for family conversations and for operational military information. The revelation of “Defense | Team Huddle,” Hegseth’s personal group with his wife and lawyer, where he shared military plans, is a vivid illustration of this structural flaw. In every other serious government, the “two-phone doctrine”: separate device for personal and separate for official.

Legal obligations after Signalgate

In the US, the Federal Records Act (44 USC § 3301) requires that all official communications of a public official be preserved and made available for inspection. The National Archives and Records Administration (NARA) issued AC 23.2025 in May 2025, specifically to clarify: Waltz's disappearing messages feature (with 7- and 28-day expirations) may constitute unlawful destruction of federal records, punishable by fines or imprisonment.

Signal government secure QKD device

In the EU, the previous Pfizergate is equally instructive. Commission President Ursula von der Leyen negotiated a €35 billion contract with Pfizer’s CEO via messages, which were never archived. The European Ombudsman Emily O’Reilly characterized the case as “maladministration,” and in May 2025 the EU General Court annulled the Commission’s refusal to disclose the messages. The legal conclusion is clear: “we didn’t keep a copy” is not a legitimate defense. Using Signal with disappearing messages for official work directly violates this logic.

After Signalgate, legal analysts have examined the European framework very carefully. In Greece, Law 5160/2024 , which transposed the NIS2 Directive into national law, as explained in the National Cybersecurity Authority’s guide, imposes cyber risk management obligations on public bodies and infrastructures. The use of unmanaged consumer applications (Signal, WhatsApp) by officials for official communication is implicitly exempted from this compliance framework, creating a legal vacuum. Furthermore, the NATO/EU framework for classified information (CONFIDENTIEL UE, NATO CONFIDENTIAL) explicitly prohibits the use of consumer applications, regardless of the strength of their encryption.

The right solutions after Signalgate

After Signalgate, the market already offers mature solutions. The French government banned WhatsApp and Telegram in December 2023 and preferred Tchap, which is essentially a state-owned installation of the Matrix through the company Element. Tchap serves 300,000 active users per day and is certified by ANSSI (French national cybersecurity authority). Germany, on the other hand, developed BwMessenger for the Bundeswehr, with over 100,000 active military users.

Other business options include Threema OnPrem (a Swiss solution without a phone number, with full data sovereignty), Salt Communications (a British one with FIPS 140-2 certification), AWS Wickr (used by the US Army), and Element Server Suite for a full self-hosted Matrix installation. The key difference between all of these and Signal is built-in identity management, audit trail, archival , and compartmentalization. As an executive at French DINUM told Tchap: “Consumer solutions don’t offer transparency. We didn’t know what backdoors might exist. The data was outside our servers, probably outside the country.”

For higher-level communications, the NSA CSfC defines the layer architecture through certified combinations of COTS products. Samsung Knox for Government has been certified for classified use, while devices Bittium Tough Mobile have been given a National Confidential classification and are used by European officials. Recently (February 2026), Germany’s BSI approved iPhones/iPads with iOS 26 for NATO RESTRICTED level — but only for this low level, through Apple’s built-in mechanisms, not through a third-party app like Signal.

Signal government sovereign infrastructure network

See also: New information: What are the common goals of Predator and EYP

Along with the device, a dominant infrastructure. In Greece, SYZEFXIS II is the national public administration network that provides secure interconnection, telephony and videoconferencing to government agencies. HellasQCI, the Greek arm of the European quantum communication infrastructure EuroQCI, is building three metropolitan quantum communication networks in Athens, Thessaloniki and Heraklion, with a budget of 9.99 million euros and 13 collaborating institutions. It is the type of infrastructure that makes eavesdropping technically impossible, as quantum interactions immediately betray any surveillance attempt.

At the level of procedures, principles that are now international standards apply: Zero Trust architecture according to NIST SP 800-207, Mobile Device Management with device attestation (Microsoft Intune for Government, BlackBerry UEM, Ivanti), mandatory second device for official communication, regular red-team assessments and OSINT hygiene training. The physical classified content areas (CCP) under the supervision of ADAE are the equivalent of American SCIFs and offer the controlled physical location that no messenger application can replace.

The Greek position after Signalgate

After Signalgate, Greece already has all the building blocks to create a serious, sovereign state communication solution. The National Cybersecurity Authority, created in 2023-2024 and drafting the new national strategy 2026-2030, can play the role that ANSSI played in France for Tchap. EDYTE/GRNET has the know-how for a self-hosted Matrix installation. SYZEFXIS II provides the deep network infrastructure. HellasQCI adds the quantum layer of security. And ADAE ensures the legal framework.

What is missing is the political decision. As long as ministers and advisers continue to use Signal daily for serious discussions — from strategic decisions to negotiations with foreign ambassadors — Greece is exposed to a double Signalgate risk: on the one hand, to a Signalgate-style operational leak, and on the other, to a targeted Dokos-style deepfake, where the very familiarity with the application becomes a tool of persuasive deception. Predatorgate showed that the Greek state is already an active target, with foreign governments and commercial spyware companies operating on its territory.

Signalgate is not a reason to abolish Signal. The editorial team of SecNews does not propose its abolition — on the contrary, the tool remains excellent for any citizen, journalist or activist who wants to protect their privacy. The proposal concerns the clear dividing line: Signal for private life, a state Matrix-based messenger for official communication, hardware-anchored devices like Bittium or Samsung Knox for Government for high-level echelons, and quantum-secured channels via HellasQCI for what is really at stake. The next leak does not have to be Greek; its next prevention , however, depends on decisions that need to be made today.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS