The United States Customs and Border Protection agency confirmed connected Wednesday that it uses astatine slightest 1 connection app made by nan work TeleMessage, which creates clones of celebrated apps for illustration Signal and WhatsApp pinch nan summation of an archiving system for compliance pinch records-retention rules.
“Following nan discovery of a cyber incident, CBP instantly abnormal TeleMessage arsenic a precautionary measure,” CBP spokesperson Rhonda Lawson tells WIRED. “The investigation into nan scope of nan breach is ongoing.”
President Donald Trump's now erstwhile nationalist information advisor Mike Waltz was photographed past week utilizing TeleMessage Signal during a furniture meeting, and nan photograph seemed to show that he was communicating pinch different high-ranking officials, including Vice President JD Vance, US head of nationalist intelligence Tulsi Gabbard, and what appears to beryllium US caput of authorities Marco Rubio.
In nan days since nan photograph was published, TeleMessage has reportedly suffered a series of breaches that exemplify concerning information flaws. Analysis of nan app's Android root codification besides appears to indicate basal flaws successful nan service's information scheme. As these findings emerged, TeleMessage—an Israeli institution that completed an acquisition past twelvemonth by nan US-based institution Smarsh—imposed a work pause connected its products pending investigation.
“TeleMessage is investigating a imaginable information incident. Upon detection, we acted quickly to incorporate it and engaged an outer cybersecurity patient to support our investigation,” a Smarsh spokesperson told WIRED successful a connection connected Monday. “Out of an abundance of caution, each TeleMessage services person been temporarily suspended. All different Smarsh products and services stay afloat operational.”
WIRED contacted CBP astir its imaginable usage of nan package aft some data stolen from TeleMessage successful 1 of nan caller breaches indicated that CBP was perchance a customer.
US legislator Ron Wyden called for nan Department of Justice to analyse TeleMessage successful a letter connected Tuesday, alleging that nan work is “a superior threat to US nationalist security.” TeleMessage is simply a national contractor, but nan user apps it offers are not approved for usage nether nan US government's Federal Risk and Authorization Management Program, aliases FedRAMP. In his letter, Wyden referenced that “several national agencies” usage TeleMessage, asserting that nan institution “sold dangerously insecure communications package to nan White House and different national agencies.”
There is still nary complete nationalist accounting of US authorities officials and agencies that person utilized nan software.