Ahead of the Signal leak, the Pentagon warned of the app’s weaknesses

Days before top national security officials accidentally included a reporter in a Signal chat about bombing the Houthi sites in Yemen, a Pentagon-wide advisory warned against using the messaging app, even for unclassified information.
“A vulnerability has been identified in the Signal messenger application,” begins the department-wide email, dated March 18, obtained by NPR.
The memo continues, “Russian professional hacking groups are employing the ‘linked devices’ features to spy on encrypted conversations.” It notes that Google has identified Russian hacking groups who are “targeting Signal Messenger to spy on persons of interest.”
In a statement to NPR, Signal spokesperson Jun Harada said, “We aren’t aware of any vulnerabilities or supposed ones that we haven’t addressed publicly.”
The Pentagon memo adds, “Please note: third-party messaging apps (e.g. Signal) are permitted by policy for unclassified accountability/recall exercises but are not approved to process or store non-public unclassified information.”
The encrypted Signal app is what Defense Secretary Pete Hegseth and other leading national security officials within the administration used to discuss bombing Houthi earlier this month. The Atlantic editor Jeffrey Goldberg was inadvertently added to the group and privy to the highly sensitive discussions.
In the military, sending classified data over insecure channels is called “slippage” when it’s considered minor, but even that can be a career ender for a military officer.
At least as far back as 2023, a DoD memo, also seen by NPR, prohibited use of mobile applications for even “controlled unclassified information,” which is many degrees less important than information about on-going military operations.
There’s almost no precedent for the heads of Defense, State, Intelligence and National Security to be sharing such sensitive military intelligence in a forum that was known to be unsecured.
NPR’s Bobby Allyn contributed to this story.
NPR disclosure: Katherine Maher, the CEO of NPR, chairs the board of the Signal Foundation.
India and China to resume direct flights after a 5-year suspension
The suspension, which began with the 2020 Covid outbreak, was prolonged by tensions along the Himalayan border.
On ‘The Life of a Showgirl,’ Taylor Swift feels love’s glow and the spotlight’s glare
On her 12th album, the most dominant pop star of our era makes a spectacle of herself in full flower, in love and holding the music industry in the palm of her hand.
FDA approves another generic abortion pill, prompting outrage from conservatives
Drugmaker Evita Solutions announced on its website that the Food and Drug Administration signed off on its low-cost form of the pill, which is approved to end pregnancies through 10 weeks.
As the shutdown drags on, the threat of permanent cuts is mired in politics
President Trump is meeting with his budget director, Russ Vought, about what additional cuts to make during the shutdown, and the president says his targets are partisan.
Pope Leo’s religious community is drawing renewed interest. Here’s what makes it unique
"Before, we might get two or three discerners. But after Pope Leo, I now have 15. It's unbelievable."
The CDC still hasn’t issued COVID vaccine guidelines, leaving access in limbo
Access to the COVID-19 vaccines remains difficult because of an unusual and unexplained delay by the Centers for Disease Control and Prevention in accepting recommendations from its advisers.