Hackers Compromise Signal Clone Users to Steal Passwords and Sensitive Information
Security experts and a U.S. government agency have reported that cybercriminals are taking advantage of a previously disclosed vulnerability in the TeleMessage app, a clone of Signal, to gain access to users’ personal information.
Earlier this year, TeleMessage, which was identified as being used by high-ranking officials in the Trump administration, experienced at least one data breach in May. The company provides altered versions of apps like Signal, WhatsApp, and Telegram for organizations and governments that need chat archiving for legal and compliance reasons.
On Thursday, GreyNoise, a cybersecurity firm that monitors online hacker activities through its sensor network, issued a warning about numerous attempts to exploit the vulnerability in TeleMessage, initially reported in May.
If hackers manage to exploit this vulnerability, they could potentially access “plaintext usernames, passwords, and other sensitive information,” the firm cautioned.
“I was taken aback by how straightforward this exploit is,” stated GreyNoise researcher Howdy Fisher in a post analyzing the situation. “[A]fter conducting some investigation, I found that many devices continue to be exposed and susceptible to this.”
The researcher described the method of exploiting this flaw as “trivial,” suggesting that hackers are increasingly becoming aware of it.
Contact Us
Do you have any additional information regarding these attacks or TeleMessage? We would like to hear from you. From a personal device and network, you can securely reach Lorenzo Franceschi-Bicchierai on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or through email.
In early July, the U.S. cybersecurity agency CISA added the vulnerability—officially designated CVE-2025-48927—to its catalog of Known Exploited Vulnerabilities, a list of security issues actively leveraged by hackers.
CISA has indicated that this bug is currently being actively exploited by hackers. However, no public reports have been released regarding hacks against TeleMessage customers at this time.
In May, TeleMessage, once a relatively obscure alternative to Signal, gained attention after U.S. National Security Advisor Mike Waltz inadvertently exposed its use. Waltz had previously included a journalist in a sensitive group chat with other Trump administration officials discussing plans to bomb Yemen, leading to a scandal that subsequently resulted in his departure.
After TeleMessage was identified as the communication tool used by Waltz and others, it suffered a hack. Unidentified attackers managed to access users’ private messages and group chats, including communications involving Customs and Border Protection and the cryptocurrency firm Coinbase, as reported by 404 Media, which first covered the incident.
TeleMessage has not responded to a request for comment.


