Potential Federal Law Violations from Sharing Classified War Plans on Signal
Yesterday, I shared my thoughts on the stunning recklessness of National Security Adviser Mike Waltz, Vice President J.D. Vance, Defense Secretary Pete Hegseth, Secretary of State Marco Rubio, and others, who reportedly used a Signal group chat to discuss highly classified U.S. military strike plans targeting Yemen. If you missed that post, you can read it [here].
For today’s follow-up, I asked my paralegals to dig into the legal implications. Specifically, I wanted a concise legal memo analyzing potential violations of federal law—including the Espionage Act and other applicable statutes—based on the unauthorized disclosure of classified national defense information through an unsecured, nongovernmental messaging app.
Here’s what they found, along with links to relevant legal resources:
Overview
Signal is an encrypted messaging app popular for private chats. However, it is not approved for U.S. government classified communications. In March 2025, senior officials – including National Security Adviser Mike Waltz, Vice President J.D. Vance, Defense Secretary Pete Hegseth, and Secretary of State Marco Rubio – allegedly used a Signal group chat to discuss highly classified plans for U.S. strikes in Yemen. One message thread was sent to Atlantic editor Jeffrey Goldberg, an unauthorized recipient, exposing sensitive military details. These actions appear to violate several federal laws and regulations governing classified information.
Espionage Act – 18 U.S.C. § 793
Relevant Law: The Espionage Act (18 U.S.C. § 793) makes it a crime to mishandle national defense information. In particular, §793(d) and (f) prohibit officials with lawful access to defense secrets from willfully transmitting them to unauthorized persons, or through gross negligence allowing their removal or disclosure (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute) (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute). The information must relate to U.S. national defense and be such that its unauthorized release could harm the United States or aid a foreign adversary (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute).
Required Elements: To prove a violation, prosecutors must show: (1) the material was closely held information related to the national defense; (2) the accused had reason to believe its disclosure could injure the U.S. or benefit a foreign nation; and (3) the
accused either willfully communicated, delivered, or transmitted it to someone not authorized to receive it, or (through gross negligence) allowed it to be removed from proper custody or disclosed in an unauthorized way (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute) (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute). Willfulness implies a deliberate action, whereas gross negligence means a careless disregard of security such that the leak occurred.
Application to Facts: The operational strike plans for Yemen meet the definition of national defense information – they were high-level military plans and intelligence details regarding an ongoing operation (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). The officials involved knew this information was highly classified and sensitive. By using an unsecured Signal chat, they effectively transmitted war plan details to an unauthorized person (journalist Goldberg) who had no security clearance. Even if the officials did not intend for Goldberg to see it, their failure to use secure systems reflects at least gross negligence in safeguarding the information. This unauthorized disclosure of war plans to someone not entitled to receive them appears to satisfy the Espionage Act’s criteria (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms) (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). In short, the group chat incident constitutes a prima facie Espionage Act violation under §793(d) (if deemed willful) or §793(f) (if deemed grossly negligent).
Potential Penalties: A violation of 18 U.S.C. § 793 is a felony. Each offense is punishable by a fine and up to 10 years imprisonment (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute). Notably, if multiple officials conspired together to mishandle the information, the Act’s conspiracy provision (§793(g)) could also apply, carrying the same penalties per conspirator (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute). Conviction can also result in forfeiture of any proceeds derived from the offense and other collateral consequences (18 U.S. Code § 793 - Gathering, transmitting or losing defense information | U.S. Code | US Law | LII / Legal Information Institute). In a case like this, each instance of transmitting classified details to an unauthorized person (e.g. each document or plan shared) could be charged as a separate count, potentially multiplying the prison time exposure.
Go deeper with AI. This special Perplexity AI page lets you explore any question from this article—no filters, no limits. Just clarity. Context. Answers.
Unauthorized Removal of Classified Material – 18 U.S.C. § 1924
Relevant Law: 18 U.S.C. § 1924 makes it unlawful for U.S. officers, employees, contractors, or consultants to knowingly remove classified documents or materials without authority and retain them at an unauthorized location (Unauthorized Removal of Classified Documents | 18 U.S.C. 1924). This statute was designed to punish the improper handling of classified records outside approved secure facilities or systems.
Required Elements: The prosecution must establish: (1) the offender is a federal officer/employee (or contractor) who obtained classified information by virtue of their position; (2) the person knowingly removed or conveyed those classified materials from their proper, authorized place of custody without authority; and (3) the person did so with intent to retain the materials at an unauthorized location (i.e. outside approved secure channels) (Unauthorized Removal of Classified Documents | 18 U.S.C. 1924). In essence, there must be a deliberate decision to take classified info out of its secure environment and keep it somewhere it shouldn’t be.
Application to Facts: In the Yemen strikes scenario, the officials by virtue of their positions had access to Top Secret operational plans. By copying or typing those details from secure networks (like SIPRNet/JWICS) into the Signal app on a personal or unclassified device, they removed classified information from its proper secure system. This was a knowing action – as a former defense official noted, one cannot simply forward classified emails to Signal; someone had to manually transcribe or copy the content while looking at a secure system (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). Moreover, Signal is not an authorized location for any classified material (Pentagon rules state such apps “are NOT authorized to access, transmit, [or] process non-public DoD information” (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms)). By placing the classified plans on an unauthorized platform and leaving them there (in the message thread), the officials intended to retain that information outside official channels for convenience of discussion. This conduct aligns with each element of §1924: they were government officials, they knowingly removed classified data from its secure repository, and they kept it on an unapproved medium (their phones/Signal). Thus, 18 U.S.C. § 1924 appears violated by the very act of moving the strike plans to the private Signal chat.
Potential Penalties: Violating §1924 is a federal offense punishable by up to five years imprisonment, a fine (up to $250,000 per count for individuals), or both (Unauthorized Removal of Classified Documents | 18 U.S.C. 1924) (Unauthorized Removal of Classified Documents | 18 U.S.C. 1924). Although §1924 carries lower maximum penalties than the Espionage Act, it squarely applies to the mishandling of classified documents even without any intent to injure the United States. A conviction would likely also lead to loss of the individual’s security clearance and termination of government employment as collateral consequences. Each instance of removing distinct classified materials could be charged separately. (Notably, in past cases lower-level officials have pleaded guilty to §1924 for taking classified papers home or transmitting them improperly, resulting in fines and probation or short jail terms, but the statute does allow imprisonment for serious violations.)
xxx
Unauthorized Disclosure of Classified Information – 18 U.S.C. § 798
Relevant Law: 18 U.S.C. § 798 specifically criminalizes the knowing, willful disclosure of certain types of classified information to any unauthorized person (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute). Unlike §793 (which broadly covers national defense info), §798 is narrowly focused on communications intelligence and related classified information. It covers, for example, classified information concerning U.S. or foreign codes and ciphers, cryptographic systems, and information about the communications intelligence activities of the U.S. or any foreign government (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute) (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute). In short, if the leaked information falls into these special categories (often signals intelligence or code-breaking information), §798 applies.
Required Elements: The government must prove: (1) the information was classified (i.e. designated by the U.S. as requiring protection for national security) (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute), and specifically related to communications intelligence, cryptography, or similar sensitive matters enumerated in §798; (2) the defendant knowingly and willfully furnished, transmitted, or made that information available to an unauthorized person (or published it) (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute) (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute). Willfulness here means the person understood the classified nature of the material and intentionally disclosed it to someone not entitled to receive it.
Application to Facts: It is not yet confirmed whether the Yemen strike chat included information that falls under §798’s specialized scope. The messages certainly contained classified operational plans (targets, weapons, timing) and even references to ongoing intelligence operations (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). If any of that discussion involved communications intelligence – for example, details about intercepted Houthi communications, surveillance methods, or code-word protected programs – then those particular disclosures would violate 18 U.S.C. § 798. CIA Director John Ratcliffe’s contributions reportedly included information “that might be interpreted as related to actual and current intelligence operations” (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). Should that info involve signals intelligence (SIGINT) or code-related secrets, Waltz and others who forwarded it on Signal would have knowingly transmitted classified communications intelligence to an unauthorized person, directly meeting §798’s criteria. On the other hand, if the shared intel was general or from human sources (HUMINT) rather than signals/codes, it would be charged under the Espionage Act (§793) rather than §798. In summary, §798 is a potential violation here to the extent the leaked material included communications intercepts or code-related intelligence.
Potential Penalties: A violation of 18 U.S.C. § 798 is a felony carrying up to 10 years in prison, a fine, or both for each offense (18 U.S. Code § 798 - Disclosure of classified information | U.S. Code | US Law | LII / Legal Information Institute). This is similar in severity to the Espionage Act. Each individual transmission of protected communications-intelligence information to an unauthorized person would constitute a separate count. Convictions under §798 have historically been treated very seriously given the highly sensitive nature of communications intelligence (often attracting maximum sentences). Even the unauthorized confirmation of the existence of certain signals intelligence programs can trigger this statute. In addition to criminal penalties, offenders would lose their clearances and positions. It’s worth noting that while §793 and §798 may overlap, prosecutors often prefer §798 for leaks of signals intelligence because it is very clear-cut (any knowing disclosure of e.g. code-word SIGINT to an uncleared person is unlawful, regardless of motive).
Federal Records and Presidential Records Acts – 44 U.S.C. §§ 3101 et seq. & 2201 et seq. (Recordkeeping Violations)
Relevant Law: Federal law requires government officials to preserve official communications and records, and prohibits the unauthorized removal or destruction of those records. The Federal Records Act (FRA) (44 U.S.C. chapters 31 and 33) and related regulations impose a duty on federal agencies and employees to retain records that document government activities. Similarly, the Presidential Records Act (PRA) (44 U.S.C. §§ 2201–2209) requires the President and senior White House staff (including the National Security Advisor and others in the Executive Office) to preserve official communications. In this context, messages about military operations by the Vice President, NSC staff, Defense and State officials are very likely “records” under these laws.
Additionally, 18 U.S.C. § 2071 is a criminal statute that enforces recordkeeping obligations by forbidding anyone from willfully and unlawfully concealing, removing, or destroying federal records. Under §2071(a), it is a crime to willfully remove or destroy any record filed in a public office or created by a U.S. officer, and §2071(b) specifically penalizes federal custodians of records who willfully and unlawfully remove or falsify official documents ( 18 U.S.C. 2071 Concealment, removal, or mutilation generally. - Patent Laws ) ( 18 U.S.C. 2071 Concealment, removal, or mutilation generally. - Patent Laws ).
Required Elements: For a civil or administrative breach of the FRA/PRA, it must be shown that an official communication qualifies as a “federal record” (meaning it was made or received in the course of official business and is preserved or appropriate for preservation) and that the official failed to preserve it or improperly removed it from government custody. A “record” can be any informational material (including emails, texts, chats) made in official capacity. A criminal violation under 18 U.S.C. § 2071 requires evidence that a person willfully and unlawfully concealed, removed, mutilated, or destroyed such a record. Willfulness in this context means the person knew the document was an official record and intentionally took it or disposed of it contrary to law.
Application to Facts: The Signal chat in question was an official discussion of a military operation at the highest levels of government – exactly the kind of communication that constitutes an official record. By conducting this discussion on a private app outside official channels, the officials risked violating federal recordkeeping laws. None of these Signal messages would automatically be archived on government systems as required. Indeed, Department of Defense policy mandates that any DoD information created on unofficial apps must be transferred to an official records system within 20 days (Use of Unclassified Mobile Applications in Department of Defense), underscoring that these texts are considered records. There’s no indication that these officials preserved or forwarded the Signal conversation to an official record system; on the contrary, it appears the conversation was intended to remain private. Thus, they likely failed to preserve federal records as required by the FRA/PRA.
If the officials willfully used Signal specifically to avoid creating a record (for instance, to keep the discussions off the books), that could be viewed as the unlawful removal or concealment of records. Each participant had a duty to ensure their official communications were recorded through proper channels. By instead confining deliberations to an encrypted app and excluding the normal archival systems, they effectively concealed official records from the government. Should evidence show an intent to evade recordkeeping, 18 U.S.C. § 2071 could be invoked. For example, Waltz as National Security Advisor arguably had “custody” of these records and if he willfully kept them off the official system, that is akin to unlawfully removing a record. In short, the use of Signal circumvented federal recordkeeping laws, constituting an unauthorized removal of official records from government custody. This is a civil violation of the FRA/PRA (likely prompting administrative action by the National Archives or agency inspectors general) and potentially a criminal violation if done willfully.
Potential Penalties: The Federal Records Act and Presidential Records Act themselves are enforced primarily through administrative remedies (the National Archives can require agencies to recover removed records, and officials can face disciplinary action for non-compliance). However, 18 U.S.C. § 2071 provides criminal penalties for willful record removal or destruction: up to three years of imprisonment, fines, or both, and disqualification from holding any federal office upon conviction ( 18 U.S.C. 2071 Concealment, removal, or mutilation generally. - Patent Laws ). While prosecutions under §2071 are rare, the statute is serious – for example, someone convicted under §2071(b) not only faces prison but would forfeit their current office and be barred from future office. In this scenario, if it were proven that the officials intentionally skirted recordkeeping laws (for instance, to hide their deliberations), they could each face those penalties. Even absent criminal prosecution, a violation of the FRA/PRA could lead to civil lawsuits to recover the records or injunctions to enforce compliance, and certainly internal investigation and sanctions. In a classroom discussion context, it’s worth noting that Congress takes recordkeeping failures seriously; using personal apps for official business has prompted hearings and legislation to strengthen the FRA (Senate Bill Aims to Better Capture Feds' Messaging Records).
Violation of Security Protocols and Regulations (Executive Order 13526 & DoD Rules)
Relevant Rules: Beyond statutes, the handling of classified information is governed by executive orders and agency regulations. Executive Order 13526 (Classified National Security Information), for example, requires that classified information be handled only by persons with proper clearance and in approved secure environments. Agencies like the Department of Defense and State Department have implementing regulations that prohibit using personal devices or unauthorized apps for classified discussion. In this case, Pentagon information security regulations explicitly ban the use of messaging applications like Signal for any non-public DoD information (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). All classified discussion was supposed to occur via secure systems (like the secure phone lines, SIPRNet for Secret-level, or JWICS for Top Secret). These officials plainly did not follow those protocols.
Required Policy Elements: The applicable security rules mandate: (1) all classified material must be discussed, transmitted, or stored only on secured, accredited systems (with proper encryption and monitoring); (2) no unauthorized devices or applications may be used to handle classified or sensitive information (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms); and (3) any spillage or improper disclosure must be reported. While violating these rules is not a criminal offense by itself, it violates the conditions of the officials’ security clearances and executive branch regulations, which every cleared official agrees to follow.
Application to Facts: The conduct of Waltz, Vance, Hegseth, Rubio, and others was a flagrant breach of established security protocols. Instead of using approved secure channels, they formed a casual group chat on Signal to discuss “imminent military strikes” – an egregious lapse in operational security, as one senator observed (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). By doing so, they violated DoD and White House security rules on multiple levels: they used an unsecure medium (Signal on personal phones) for classified discussion, they failed to employ any authorized encryption device or secured network for those messages, and once the mistake of including an outsider occurred, they seemingly failed to immediately report the spillage (at least there’s no public indication they self-reported to security officers). According to the Pentagon’s own rules, no one is authorized to process or transmit classified info via Signal (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms), so each official in the chat was in clear violation of those regulations the moment they began sharing sensitive details. The inadvertent inclusion of a journalist only compounded the violation. In practice, even a much lower-level DoD employee would face serious consequences (investigation, loss of clearance, potential prosecution) for similar conduct (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms). The fact that this was done by top officials does not make it any less a breach – if anything, it’s more alarming given they should know better.
Potential Penalties: Violating security regulations carries administrative and career penalties. While breaking an Executive Order or agency rule isn’t a criminal offense per se, the consequences include revocation of security clearances, suspension or loss of one’s job, and removal from sensitive duties. For example, an employee who shared classified info over an unauthorized app would almost certainly have their clearance suspended pending an investigation, and could be fired or have their clearance permanently revoked (ending their ability to work in national security). In this case, former officials like Leon Panetta openly said “somebody needs to get fired” for this breach (Trump Officials Shared Yemen Strike Plans via Signal, Mistakenly Included Journalist, White House Confirms) – emphasizing that termination is an expected outcome for such a lapse. Additionally, the violation of these protocols serves as strong evidence of gross negligence or willfulness if any legal action (under the statutes discussed above) is pursued. In other words, the fact that they deliberately sidestepped required secure systems could be used by prosecutors to prove the requisite intent for charges under the Espionage Act or §1924. In summary, the officials’ use of Signal blatantly violated federal security rules, exposing them to severe administrative sanctions immediately, and bolstering any civil or criminal case against them for the underlying information leak.
Conclusion
In a scenario where senior U.S. officials share classified operational plans over an unapproved app, multiple federal laws are implicated. The Espionage Act (§793) addresses the core offense of leaking defense information to unauthorized persons (here, the accidental inclusion of a journalist). Section 1924 targets the act of moving classified information onto personal devices (the act of copying war plans into Signal). If the content included certain types of intelligence, §798 could also come into play.
Furthermore, by not using official systems, the officials likely ran afoul of the Federal Records Act/Presidential Records Act, since they failed to properly preserve these communications as official records, possibly even concealing them willfully (raising §2071 issues).
Finally, their behavior blatantly violated security regulations designed to prevent exactly this kind of leak, which would trigger administrative punishments. Each of these violations carries its own set of penalties – ranging from fines and imprisonment to loss of office and clearances.
The facts as alleged suggest that the elements of these offenses are well satisfied, making this incident a textbook case study in the legal dangers of unauthorized handling of classified information in the digital age.
Mitch Jackson, Esq. | links
This post is free.
But free doesn’t build the future.
Independent journalism only works when people like you choose to lean in—not just with attention, but with support.
If this work matters to you, today’s a great day to take the leap.
$5 a month. $50 a year.
A small investment in something bigger than all of us.




Hegseth, for sure, should be fired immediately and then brought to trial. His accomplices should all be brought in front of a Congressional Hearing to atone for complicit actions. It's up to the Democrats to jump on this opportunity now and do something about it. There are enough Republicans who feel troubled by Hegseth thinking that he's in a drinking game versus protecting the country. This clown show has gone too far, and Trump suggesting he knew nothing about it is also nonsense.
Related on Politico- ‘It’s so unbelievable': Cyber world stunned over war planners using Signal https://www.politico.com/news/2025/03/25/signal-cybersecurity-trump-war-planning-00246881