How a Journalist Ended Up in a War Plans Signal Group
On March 13th, Mike Waltz, then Trump’s national security adviser, added Jeffrey Goldberg, editor-in-chief of The Atlantic, to a Signal group with 18 other members. The group included Pete Hegseth, Secretary of Defense; John Ratcliffe, CIA director; Tulsi Gabbard, Director of National Intelligence; and Steven Miller. On March 15th, Hegseth posted a drone strike schedule for Yemen. Hours later, US forces bombed the target. Yemen’s Ministry of Health reported 53 dead, including five children, and 98 injured.
The War Plans and a False OPSEC Claim
Hegseth’s post laid out the March 15th attack timeline: F-18 aircraft launched at 12:15 Eastern, the strike window opened at 13:45, more F-18s launched at 14:10, and first bombs dropped by 14:15. He also wrote “We are currently clean on OPSAC.” He had not verified who was in the group before posting. Gabbard and Ratcliffe later testified under oath to Congress that nothing classified was discussed. The Atlantic published the screenshots. Both had lied.
How Siri Added a Journalist to the Wrong Signal Group
An internal White House investigation traced the mistake. In October, before the election, Goldberg had emailed the Trump campaign about a story. Someone forwarded it to Brian Hughes, the campaign spokesperson. Hughes sent it to Waltz, including Goldberg’s phone number from the email signature. Siri automatically merged that number into Waltz’s existing contact for Hughes. Months later, Waltz, now National Security Adviser, created the Signal group and tried to add Hughes. He added Goldberg instead. Using dedicated classified devices, as required, would have prevented it.
The Signal Fork That Archived Everything to an Insecure Server
A Reuters photographer caught Waltz checking his phone under the table at a May 1st cabinet meeting. Zoomed screenshots showed “verify your TM SGNL PIN,” not Signal. TeleMessage was founded in Tel Aviv in 1999 by Israeli military veterans, including Guy Levit, who previously ran an IDF intelligence technical unit. Its Signal fork copies every message to an archive server while maintaining Signal compatibility. TeleMessage marketed this as end-to-end encrypted from mobile phone to corporate archive. Lee’s analysis of the Android source code proved that claim false.
A 15-Minute Hack via an Exposed Heap Dump Endpoint
After Lee published the TM SGNL Android source code to GitHub, an anonymous hacker contacted him. The hacker found TeleMessage’s archive server ran Spring Boot with the heap dump actuator endpoint publicly accessible and without authentication. That endpoint has been disabled by default since Spring Boot 1.5, released in 2017. A single GET request returned a 150MB snapshot of server memory containing usernames, passwords, and plain text chat logs. The hacker also logged into TeleMessage’s admin panel as a CBP account and pulled 747 member contact records.
What the Stolen Data Contained
DDoSecrets released hundreds of gigabytes of heap dumps from a second hacker. Lee ran strings on 384GB of files, producing 83GB of text, then extracted JSON objects into a SQLite database. Reuters found 60-plus government users including Secret Service members and diplomatic staff. The data contained Sam Altman messaging a VC CEO about lobbying, Jared Kushner receiving messages from Trump’s AI adviser, and a Signal group discussing Trump’s Vatican visit. A Rust JSON carver later found 100,000 messages in the set, not 60,000, many in Chinese and Hebrew.
Q&A
Were other intelligence agencies also collecting from TeleMessage? Lee said he found no direct code evidence, but given the trivial hack, called it implausible that Chinese, Russian, and Israeli intelligence weren’t already collecting. ▶ 40:55
Notable Quotes
Looking forward to it. Pete Hegseth · ▶ 3:51
they’re just really really bad at OPSAC. Micah Lee · ▶ 11:59
This is a lie. Micah Lee · ▶ 26:04
This is really bad. Micah Lee · ▶ 39:35
Key Takeaways
- Signal is secure when used correctly; a fork with server-side archiving removes that protection entirely.
- A Spring Boot heap dump endpoint disabled by default since 2017 was left exposed without authentication.
- The TeleMessage breach exposed 747 CBP contacts, White House staff messages, and executives across finance and tech.
About the Speaker(s)
Micah Lee is a security researcher, independent journalist, and open source developer, and a member of the Lockdown Systems collective. He is the former director of infosec for The Intercept. His work spans privacy tools, whistleblowing, and data journalism. He wrote Hacks, Leaks, and Revelations, a book teaching people how to analyze hacked and leaked datasets.