10 Ways The Signal App Can Be Hacked — And Why No One Should Use It for National Security Reasons
America’s top national security officials discussed details of a military operation against Yemen using a publicly available smartphone app. It sounds like a political thriller or a bad movie plot, but it actually happened in a scandal dubbed "Signalgate."
In early 2025, members of former President Trump’s circle — including Mike Waltz, Pete Hegseth, Marco Rubio, J.D. Vance, Tulsi Gabbard, John Ratcliffe, and Scott Bessent — reportedly used the messaging app Signal to coordinate sensitive strikes on Houthi rebels in Yemen. One of them even accidentally added a journalist to the group chat, exposing highly sensitive war plans.
Here’s just one screenshot of the extended conversation:
This reckless episode put a spotlight on a critical question: Should officials ever use Signal to discuss classified or top-secret government information? The answer is a resounding no, and here’s why.
What is Signal, and Why Do People Trust It?
Signal is a popular encrypted messaging app designed to keep conversations private. It uses strong end-to-end encryption, meaning when you send a message, it gets scrambled into unreadable code that only the intended recipient’s device can decode. Not even the Signal company can read your chats.
The app is also open-source (its code is public for experts to inspect), and it offers features like disappearing messages that auto-delete after a set time. Because of these privacy protections, Signal has become a go-to for journalists, activists, and anyone who wants to keep their texts away from prying eyes. In an era of constant data breaches and Big Tech surveillance, Signal feels like a safe digital vault for personal conversations.
But national security secrets are a whole different ballgame. If you’re discussing lunch plans or sharing family photos, Signal’s encryption is fantastic. However, using it to discuss classified military operations or diplomatic secrets is like using a toy lock on a bank vault – wildly inadequate and dangerous. Here are 10 big reasons why using Signal for top-secret or classified government communication is a terrible idea:
1. Hacked Phones Turn Signal Inside Out – Signal can hide messages from hackers while they travel over the internet, but it can’t protect you if your own phone is compromised. Foreign adversaries use powerful spyware (like the infamous Pegasus software) to hack smartphones at the source. Once spyware is on a device, it’s game over: the hacker can see exactly what you see, including your supposedly “secure” Signal chats. It doesn’t matter that the message was encrypted in transit; if a spy has infected an official’s phone, they can read messages, see photos, and even turn on the microphone or camera without anyone knowing.
In other words, if a hostile foreign actor hacks the phone of a government official using Signal, they get a front-row seat to all the classified discussions. It’s as if you installed a security door on your house but left a window wide open — the enemy can just climb in and take whatever they want. For national security, this is a nightmare scenario: one successful phone hack could hand an adversary our battle plans or diplomatic strategies on a silver platter.
2. Phishing and Social Engineering Tricks – Not all attacks are high-tech; sometimes the weakest link is the human using the app. Hackers often employ phishing, which means tricking someone into clicking a malicious link or revealing their login codes. With Signal, a foreign spy might impersonate a trusted colleague or create a fake emergency message to manipulate an official. For example, an attacker could send a message that looks like it’s from a fellow official: “Urgent update – download this attachment.” If the official taps that link, malware can silently install on their phone, or the link might hijack their Signal session.
Another ploy is impersonating tech support: “Your Signal account is at risk, click here to verify your identity.” One careless click or tap can give the bad guys a foothold. Social engineering exploits our trust and urgency – even savvy people can be fooled, especially when messages appear to come from friends or bosses. In the context of national security, an enemy agent might use these tactics to gain access to a confidential Signal chat or to trick officials into revealing information. It’s like a Trojan horse: the message looks legitimate, but inside it carries an enemy agent. The bottom line is that no matter how secure Signal’s encryption is, it can’t stop a user from being duped into opening the door for the intruder.
3. SIM Swaps and Identity Hijacking – Signal relies on phone numbers for identity, and that’s a glaring weak point. Hackers have techniques to hijack phone numbers, such as SIM swapping. In a SIM swap attack, someone convinces your phone carrier (through bribery or trickery) to switch your number to a new SIM card that the hacker controls. Suddenly, your Signal account (which is tied to your number) can be registered on the hacker’s device. Imagine a foreign operative stealing a general’s phone number – they could potentially intercept verification messages and take over that official’s Signal account. This would let them impersonate the official or read new incoming messages (because once they register as you, all messages now go to them). The real official gets locked out, and might not realize immediately why their Signal stopped working.
This kind of identity hijack is catastrophic in a sensitive conversation: the adversary could send false instructions (“Abort the mission” or “Send the funds now”) or quietly eavesdrop on plans. Even without an outright SIM swap, sophisticated hackers can exploit weaknesses in global phone networks (like SS7 vulnerabilities) to intercept one-time passcodes. The key point is that phone numbers aren’t fully secure identifiers. For everyday users, a hijacked social media account is a headache; for government leaders, a hijacked Signal account could be a matter of war and peace.
4. *Oops, Wrong Recipient” – Human Error and Leaks – We all know the embarrassment of texting the wrong person. In everyday life it might mean sending a meme to your mom instead of your friend. In the world of classified info, a simple mix-up can be disastrous. Signal makes it easy to create group chats and share information quickly, but that convenience can backfire.
In the Signalgate scandal, National Security Advisor Mike Waltz accidentally added journalist Jeffrey Goldberg (the editor of The Atlantic) to a Signal group that was planning military strikes. Because of one oversight – selecting the wrong contact – secret attack plans were exposed to someone outside the government. This is a jaw-dropping error, but it’s a reminder that no system is safe from plain old human mistakes.
Using informal apps like Signal for critical discussions makes it frighteningly easy to misfire a message or add an unintended participant. Once the message is out, you can’t take it back. If instead a secure government system had been used, there would likely be stricter controls and checks on who could be included in a conversation (and a mistaken invite to a reporter would be far less likely).
Whether it’s adding the wrong person, sending a message to the wrong chat, or even a typo in a phone number, human error can instantly leak sensitive information to the wrong eyes. Foreign intelligence agencies are eager to exploit any slip-up. One misplaced message could land in the hands of an undercover enemy agent or get leaked to the public, blowing an operation. When lives and national security are on the line, “oops” is not an acceptable security policy — but using Signal for secrets invites exactly that risk.
5. No Official Oversight or Monitoring – When government officials conduct business on official secure networks, those systems have monitoring and safeguards. Think of secure military communication channels: they’re like a guarded vault, with alarms and logs that alert security teams to suspicious activity. If someone tries to hack in, there’s a chance the attempt will be detected and stopped.
But if leaders take their conversation to a private Signal chat on personal phones, they’re stepping outside that protected vault. There’s no government cybersecurity team watching a Signal chat for intrusions because it’s not an official system. This lack of oversight means an enemy could be lurking in the conversation (through a hacked phone or other means) and no one in our government IT department would know. It also means that if something does go wrong — say, an account is compromised or messages are being forwarded — there's no automatic record or alert happening.
Essentially, using Signal for secret talks is like flying under the radar of our own security watchdogs. That might sound appealing for privacy, but it’s terrible for national security. If a hostile actor manages to eavesdrop or tamper with the chat, it could go on for too long without detection. In a worst-case scenario, spies could quietly monitor discussions about military or diplomatic moves, and our security teams would be blind to the breach. By keeping critical conversations on the official, secured channels, we ensure that our cybersecurity professionals can do their job: catching intrusions and protecting our secrets. On a rogue Signal chat, those protections vanish.
6. Vanishing Messages Undermine Accountability – Signal’s ability to make messages disappear after a set time might be great for privacy, but it’s terrible for government accountability and it’s against the law for official business. The Federal Records Act requires government officials to preserve communications related to official duties.
The idea is simple: in a democracy, we need a record of how decisions were made. It’s like keeping receipts or a paper trail so that later we can audit what happened, learn from it, or hold people responsible. When officials use Signal with disappearing messages to discuss policy or operations, they’re essentially writing in invisible ink and then letting it vanish. This is exactly what happened in the Signalgate case: messages were set to auto-delete, meaning there would be no trace of critical discussions about military action.
Such behavior not only potentially violates federal law, but it also poses a security risk. Why? If something goes wrong – say a mission fails or sensitive info leaks – investigators and oversight bodies have no records to examine. Lack of records makes it easier for disloyal insiders to collude with foreign actors or cover up misconduct, since there’s no evidence to catch them later. It also erodes trust: the public and other officials can’t hold leaders accountable if there’s literally no record of what they decided and why.
Imagine trying to solve a crime with no clues or run a history class with no documents – that’s what happens when Signal erases official chats. In short, using an auto-deleting, encrypted app for government business is like shredding all your notes as soon as you write them. It undermines transparency, breaks the rules, and ultimately weakens national security by allowing potential wrongdoings to go undetected.
7. Unknown Vulnerabilities (Zero-Day Exploits) – No app is perfectly secure. “Zero-day” exploits are a hacker’s trump card: these are security holes in software that no one knows about except the attacker. Signal has a strong reputation, but it’s software like any other, and it has had bugs in the past. It’s possible that right now, somewhere in the world, a team of hackers or a foreign intelligence unit has discovered a hidden flaw in Signal’s code. If so, they could use it to penetrate what users think is a secure conversation without anyone realizing.
For example, in other messaging apps, hackers have found ways to crash the app or take control by sending a specially crafted message or call — the user doesn’t even have to click anything. If a similar bug were found (or has been found) in Signal, an adversary could potentially listen in on “secure” chats or extract messages. The scary part about zero-day exploits is you typically find out about them only after the damage is done. Government officials using Signal for classified discussions are betting the security of the nation on an app that was never certified for that level of secrecy. It’s like using a personal car in a professional race: it might work, but it’s not built for that stress, and you won’t know what part will fail until it’s too late.
When the stakes are national security, relying on an app’s good reputation isn’t enough — it needs to be formally vetted and continuously monitored for new threats. Signal simply isn’t designed with the assumption that “our users are discussing nuclear codes.” And that’s okay for regular people, but not for top-secret material. One overlooked glitch is all it takes for an enemy to slip in through the digital cracks.
8. Leaks via Metadata and Side Channels – Even if the Signal app’s encryption holds strong, information can leak around the edges. Every digital interaction leaves metadata – data about the data. With Signal, metadata could include the fact that two specific officials are communicating, when, and how often (even if the content is encrypted). For a clever adversary, that’s valuable intel.
Imagine they observe (through network monitoring or other surveillance) that the Secretary of Defense and the National Security Advisor suddenly start exchanging messages back and forth at 2 AM and then go dark – that pattern itself might hint at a looming operation or crisis. This kind of analysis is called traffic analysis, and spies have used it for decades (even in WWII, knowing when and how often enemies were talking gave clues about plans).
Beyond metadata, consider other leaks: if an official has Signal on a phone that also backs up photos or notifications to the cloud, a fragment of a message or an image might inadvertently get saved outside the app’s encryption. Or someone in the chat might screenshot something and that image could get compromised.
Additionally, using Signal doesn’t occur in a vacuum: the device it’s on might be emitting signals (like those that can be picked up by listening devices) or have other apps that log usage. Advanced attackers might not crack the encryption, but they might not need to; they can learn plenty from these side channels. For instance, by analyzing the size of encrypted packets, one might guess if a photo or file was sent versus a short text. It’s a bit like noticing the envelopes a letter comes in – you might not read the letter, but a thick envelope versus a thin one tells you something. In national security, even small clues can tip off adversaries.
When officials stick to truly secure systems, those systems are designed to minimize metadata leaks and are often isolated from other devices. But Signal operates on consumer phones that are noisy data machines. In short, spies can still “read the room” even if they can’t read the exact Signal messages, and that partial information might be enough to undermine an operation or reveal secrets.
9. Advanced Infiltration via Linked Devices – Here’s a sneaky, less-known trick: exploiting Signal’s linked devices feature. Signal allows you to link your account to a computer or tablet by scanning a QR code. Recently, cybersecurity experts uncovered that Russian hackers have been abusing this feature with clever phishing attacks.
They send targets a bogus QR code, maybe disguised as a legitimate Signal notification or a group chat invite. When an unsuspecting official scans it (thinking they’re, say, logging into a secure briefing or verifying their device), they actually end up linking their Signal account to an attacker’s device. Suddenly, every message in that Signal chat is being copied in real-time to the spy’s computer, without anyone in the chat knowing. It’s the digital equivalent of a “ghost” silently sitting in on your meeting. This isn’t a hypothetical – it’s a real technique observed in the wild.
Imagine the damage: foreign agents could be literally watching U.S. officials discuss strategy or share intel, line by line, as it happens, all because of one cleverly disguised QR code. That’s a very advanced con, and most people aren’t aware it’s even possible. It shows how determined adversaries can find creative ways to bend or exploit legitimate app features against us.
While Signal has tried to add safeguards and warnings about unknown devices linking, the fact remains that a moment of inattention (scanning the wrong code) could invite an eavesdropper directly into the most sensitive conversations. For critical government communications, that risk is unacceptable. We don’t want “mystery guests” in a high-level national security chat, but using Signal in this arena creates exactly that possibility.
10. Tomorrow’s Technology Can Break Today’s Secrets – Let’s assume, for the sake of argument, that Signal’s encryption is truly unbreakable today. Classified discussions often need to stay secret not just in the moment, but for years or decades. Here’s the catch: what if someone records the encrypted messages now and sits on them, waiting for a breakthrough? With the rapid advancement of technology, that’s not far-fetched.
Quantum computing, for example, is an emerging field that could potentially crack current encryption algorithms much faster than ordinary computers. It’s like a codebreaking machine on steroids. We might be a decade (or less) away from quantum computers capable of undermining some forms of encryption.
So a patient adversary could secretly capture the scrambled Signal messages now (even if they can’t read them yet), and then decrypt them in the future once technology allows. If those messages contain top-secret plans or intelligence assessments, the damage might be done even years later – it could expose sources, methods, or strategies that are meant to be kept under wraps long term. Furthermore, there’s always the possibility of some mathematical or technical breakthrough that weakens today’s encryption.
The point is, classified information often has a long shelf life of sensitivity. We cannot assume that just because Signal is secure against current attacks, it will be secure forever. Official secure channels use encryption approved by the government and are updated as threats evolve, and they often add additional layers (and strictly control who even has access). An app like Signal doesn’t guarantee that longevity or rigor, because it wasn’t built for safeguarding state secrets into the far future. Relying on it is short-sighted. It’s a bit like writing secret messages in code that you think no one can crack, forgetting that someone might invent a decoder tomorrow. When the secrets at stake are our nation’s, we have to assume that today’s “unbreakable” code might be tomorrow’s open book.
Legal and Ethical Issues
Beyond these technical and tactical risks, let’s not forget the legal and ethical implications. The fiasco of Signalgate wasn’t just a security breach — it was a failure of responsibility. This is where the Federal Records Act (FRA) comes in. The FRA is a law that basically says: if you’re a government official, you must keep records of your work communications. Emails, memos, and yes, messages — if you’re conducting official business, it needs to be preserved. Why? Because the government works for the people, and the people have a right to know how decisions were made and to hold leaders accountable. Think of it as the rule that ensures there’s a “paper trail” (or a digital trail) of what our leaders are up to on our behalf.
Using Signal to conduct government business — especially with auto-delete turned on — is essentially thumbing your nose at the Federal Records Act. It’s saying, “We’re going to talk about this, and then pretend it never happened.” That’s not how democracy is supposed to work. Doing this may result in criminal violation which I talked about in Potential Federal Law Violations from Sharing Classified War Plans on Signal.
In the Signalgate case, for instance, a watchdog group had to sue to stop officials from destroying those Signal messages and to get them archived properly. A federal judge even ordered those messages preserved, underscoring that these were official records, not private chitchat. When officials choose secrecy over transparency in this way, they’re not just risking security — they’re breaking trust with the American people.
Imagine if historical decisions like the Cuban Missile Crisis deliberations or the raid on Osama bin Laden had simply disappeared into thin air because they were discussed on an app like Signal. Future leaders wouldn’t be able to learn from past decisions, oversight committees couldn’t do their job, and we citizens would be completely in the dark about how and why choices were made.
In plain terms: using Signal for secret government conversations is not just unsafe, it’s undemocratic. It creates a black hole in the record of governance. And from a national security perspective, that lack of accountability can itself be dangerous. When officials operate in shadows, mistakes and misconduct multiply — and adversaries can exploit chaos and cover-ups. Transparency and strong security protocols actually go hand in hand: they ensure that procedures are followed and any breaches or missteps can be quickly identified and corrected.
The Signalgate incident serves as a stark warning. We saw top-level officials opting for convenience (or concealment) over proper procedure, and it led to a serious breach. Classified information was discussed on a platform not meant for it, and it leaked. That lapse could have tipped off enemy forces, put lives at risk, or derailed diplomatic efforts. It also exposed those officials to legal peril and public outrage, for good reason. I even wrote about this in my post, Trump Called It a “Glitch.” Here’s What Could Have Happened If the Signal Chat Had Been Breached.
In the wake of all this, what should be done? First, our leaders must understand that convenience is never worth compromising national security or the law. There are secure systems in place for a reason — they might be less handy than a quick Signal text, but they exist to protect our country. If those systems are lacking or cumbersome, the answer is to invest in better secure communications technology for government use, not to sidestep into the realm of consumer apps.
Lawmakers should enforce (and if needed, strengthen) rules prohibiting the use of unauthorized apps for official business, especially for anything sensitive. Proper training and clear consequences are important too: every official and staffer should know that using something like Signal for classified or sensitive discussions is a serious violation that could end careers or invite prosecution.
For the rest of us as voters and citizens, we need to hold our elected and appointed officials accountable for following the rules that safeguard our nation. Ask your representatives how they communicate about important matters. Demand oversight and transparency when secrets are mishandled. This isn’t just “inside baseball” — these issues affect decisions of war and peace, and ultimately American lives.
Conclusion
In summary, Signal is a powerful tool for private, personal use, but it has absolutely no place in the communication of classified government information. The app was built to keep nosy corporations or hackers from reading your dinner plans; it was never built to handle state secrets and global military strategies. When officials ignore that fact, they are courting disaster. Whether it’s through hacking, human error, legal violations, or future tech breakthroughs, the risks of using Signal for national security talks are just too great. The Signalgate saga showed how badly things can go wrong: secret plans laid bare, allies alarmed, laws broken, and public trust damaged.
Let’s learn from this glaring mistake. National security discussions belong on secured, monitored, and legally compliant channels — period. Our government leaders swear an oath to protect the country and uphold its laws, and that includes taking communications security seriously. Using Signal for sensitive talks isn’t savvy or secure; it’s reckless and irresponsible. We should expect better, and demand that those in power keep our nation’s secrets safe the right way. The safety of our country and the integrity of our democracy depend on it.
Mitch Jackson, Esq. | links
This post is free.
But free doesn’t build the future.
Independent journalism only works when people like you choose to lean in—not just with attention, but with support.
If this work matters to you, today’s a great day to take the leap.
$5 a month. $50 a year.
A small investment in something bigger than all of us.





Update: TeleMessage, a modified Signal clone used by US govt. officials, has been hacked https://techcrunch.com/2025/05/05/telemessage-a-modified-signal-clone-used-by-us-govt-officials-has-been-hacked/
The plot thickens: Judge orders government to preserve Signal messages about Houthi military strike
https://apnews.com/article/signal-trump-houthis-strike-7d5a06d1c40a3c6af1c1ad1a772e87e0