How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

Security Flaws in Signal Clone TeleMessage Expose Sensitive Government and Corporate Data
Photo: WIRED

Security Flaws in Signal Clone TeleMessage Expose Sensitive Government and Corporate Data

In May 2025, the Signal clone app TeleMessage, used by at least one Trump administration official, was hacked in under 20 minutes due to a critical server misconfiguration. The app, marketed as a secure communication tool, actually archived all messages, nullifying any claims of end-to-end encryption. The breach was discovered after national security adviser Mike Waltz was photographed using the app. The hacker accessed TeleMessage’s admin panel, which hashed passwords using outdated MD5 on the client side. They used a tool called feroxbuster to locate a vulnerable endpoint on the archive server, leading to the download of a Java heap dump containing plaintext usernames, passwords, and chat logs. Among the compromised data were credentials associated with US Customs and Border Protection and internal chats from Coinbase. The server was likely using an outdated or poorly configured version of Spring Boot Actuator, exposing sensitive diagnostic endpoints publicly. This misstep allowed access to live memory snapshots containing user data. Despite its security flaws, the app had been deployed in sensitive governmental contexts. TeleMessage has since suspended services. The incident highlights the risks of poor server configuration and the false security narratives some apps present to users.

Leave a Reply

Your email address will not be published. Required fields are marked *