CSIDB logo
Incident

US municipal government

Incident posture

Attack window
May 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:09

Linked entities

Victim
US municipal government
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker claimed to have breached a centralized server operated by TeleMessage, an encrypted messaging archiving service owned by Smarsh, downloading a large cache of files and providing a screenshot of an internal contact list as evidence. The company confirmed it was investigating a potential security incident, suspended all TeleMessage services, and engaged an external cybersecurity firm to support its response. Multiple U.S. federal agencies, including the Department of Homeland Security, the Department of Health and Human Services, the Treasury Department, and the U.S. International Development Finance Corporation, have active contracts involving the service, and Customs and Border Protection immediately disabled its use as a precaution. A separate hacker also claimed to have accessed TeleMessage data, sharing evidence with another publication. The full scope of the breach, including whether sensitive government communications were exposed, remains under investigation.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

TeleMessage, the encrypted messaging application owned by Smarsh, suspended all of its services on May 1, 2025, after credible claims emerged that hackers had breached its infrastructure and stolen files. The incident became public when a hacker contacted NBC News on Sunday evening and claimed to have broken into a centralized TeleMessage server, downloading a large cache of files in the process. As initial evidence of the intrusion, the hacker provided a screenshot of TeleMessage's internal contact list containing employees of the cryptocurrency broker Coinbase, a company that uses TeleMessage's services. A Coinbase spokesperson subsequently confirmed the authenticity of the screengrab to NBC News, while emphasizing that Coinbase itself had not been hacked and that no customer data had been affected. The company further clarified that TeleMessage was not used by Coinbase to share passwords, seed phrases, or other information needed to access customer accounts. The hacker informed NBC News that they had not yet fully reviewed the stolen files, leaving it unclear whether sensitive U.S. government conversations were among the compromised data.

TeleMessage had originally attracted public attention the previous week when Mike Waltz, then President Donald Trump's national security adviser, appeared to be using the application during a Cabinet meeting. Waltz's use of the app drew renewed scrutiny of his communication practices following the earlier "Signalgate" controversy, in which he had inadvertently added a journalist to a Signal group chat among top administration officials discussing planned military strikes on Houthi targets in Yemen. TeleMessage uses encryption technology similar to Signal's but distinguishes itself by offering government agencies and companies a way to archive copies of their chats to satisfy records retention and compliance requirements. The company had previously promoted itself in a blog post as having been conceived to address the tension between encrypted communications and federal recordkeeping laws, though that post was taken down following the incident. Cybersecurity experts have long noted that archives of sensitive information inherently create attractive targets for malicious actors seeking valuable data.

In response to the breach, a spokesperson for Smarsh, TeleMessage's parent company, stated that the organization was investigating a potential security incident and had acted quickly upon detection to contain the situation. The company engaged an external cybersecurity firm to support the ongoing investigation and, out of an abundance of caution, temporarily suspended all TeleMessage services. The Department of Homeland Security confirmed through a spokesperson that Customs and Border Protection had immediately disabled TeleMessage as a precautionary measure following the detection of the cyber incident. DHS indicated that the investigation into the scope of the breach remained ongoing at the time of reporting.

Government records reviewed by NBC News indicated that several federal agencies held active contracts with TeleMessage or with other companies using TeleMessage's services, including the Department of Homeland Security, the Department of Health and Human Services, the Treasury Department, and the U.S. International Development Finance Corporation. Separately, a second hacker contacted the technology news publication 404 Media and also claimed to have compromised TeleMessage, providing significant evidence to support their claim. NBC News reported that it had not independently interacted with this second hacker, and it was not immediately clear whether additional unauthorized parties had accessed TeleMessage files beyond those who had come forward publicly. The full scope of the breach, including the identities of all affected users and the complete contents of the stolen data, remained under investigation as of the latest available reporting.

Sources

Sources available to members: 1 source.

CSIDB