US municipal government
Incident posture
Linked entities
- Victim
- US municipal government
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A hacker claimed to have breached a centralized server operated by TeleMessage, an encrypted messaging archiving service owned by Smarsh, downloading a large cache of files and providing a screenshot of an internal contact list as evidence. The company confirmed it was investigating a potential security incident, suspended all TeleMessage services, and engaged an external cybersecurity firm to support its response. Multiple U.S. federal agencies, including the Department of Homeland Security, the Department of Health and Human Services, the Treasury Department, and the U.S. International Development Finance Corporation, have active contracts involving the service, and Customs and Border Protection immediately disabled its use as a precaution. A separate hacker also claimed to have accessed TeleMessage data, sharing evidence with another publication. The full scope of the breach, including whether sensitive government communications were exposed, remains under investigation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
TeleMessage, the encrypted messaging application owned by Smarsh, suspended all of its services on May 1, 2025, after credible claims emerged that hackers had breached its infrastructure and stolen files. The incident became public when a hacker contacted NBC News on Sunday evening and claimed to have broken into a centralized TeleMessage server, downloading a large cache of files in the process. As initial evidence of the intrusion, the hacker provided a screenshot of TeleMessage's internal contact list containing employees of the cryptocurrency broker Coinbase, a company that uses TeleMessage's services. A Coinbase spokesperson subsequently confirmed the authenticity of the screengrab to NBC News, while emphasizing that Coinbase itself had not been hacked and that no customer data had been affected. The company further clarified that TeleMessage was not used by Coinbase to share passwords, seed phrases, or other information needed to access customer accounts. The hacker informed NBC News that they had not yet fully reviewed the stolen files, leaving it unclear whether sensitive U.S. government conversations were among the compromised data.
TeleMessage had originally attracted public attention the previous week when Mike Waltz, then President Donald Trump's national security adviser, appeared to be using the application during a Cabinet meeting. Waltz's use of the app drew renewed scrutiny of his communication practices following the earlier "Signalgate" controversy, in which he had inadvertently added a journalist to a Signal group chat among top administration officials discussing planned military strikes on Houthi targets in Yemen. TeleMessage uses encryption technology similar to Signal's but distinguishes itself by offering government agencies and companies a way to archive copies of their chats to satisfy records retention and compliance requirements. The company had previously promoted itself in a blog post as having been conceived to address the tension between encrypted communications and federal recordkeeping laws, though that post was taken down following the incident. Cybersecurity experts have long noted that archives of sensitive information inherently create attractive targets for malicious actors seeking valuable data.
In response to the breach, a spokesperson for Smarsh, TeleMessage's parent company, stated that the organization was investigating a potential security incident and had acted quickly upon detection to contain the situation. The company engaged an external cybersecurity firm to support the ongoing investigation and, out of an abundance of caution, temporarily suspended all TeleMessage services. The Department of Homeland Security confirmed through a spokesperson that Customs and Border Protection had immediately disabled TeleMessage as a precautionary measure following the detection of the cyber incident. DHS indicated that the investigation into the scope of the breach remained ongoing at the time of reporting.
Government records reviewed by NBC News indicated that several federal agencies held active contracts with TeleMessage or with other companies using TeleMessage's services, including the Department of Homeland Security, the Department of Health and Human Services, the Treasury Department, and the U.S. International Development Finance Corporation. Separately, a second hacker contacted the technology news publication 404 Media and also claimed to have compromised TeleMessage, providing significant evidence to support their claim. NBC News reported that it had not independently interacted with this second hacker, and it was not immediately clear whether additional unauthorized parties had accessed TeleMessage files beyond those who had come forward publicly. The full scope of the breach, including the identities of all affected users and the complete contents of the stolen data, remained under investigation as of the latest available reporting.
Sources
Sources available to members: 1 source.