
A Pentagon-wide warning said hackers abused Signal’s linked devices to spy on “encrypted” chats, underscoring that the weak point is our phones and habits—not the math inside the app.
Story Snapshot
- Pentagon memo urged staff to avoid Signal for even unclassified chatter after a March 2025 leak.
- Experts say Signal’s encryption is strong, but device hacks, phishing, and user mistakes still expose chats.
- Dutch and other agencies warned of Russia-backed campaigns targeting high-profile Signal users with scams.
- Reporters and analysts agree: secure tools fail when operations are sloppy or devices are compromised.
What Triggered New Alarm About Signal Use
Defense officials circulated a department-wide memo on March 18, 2025, telling staff to avoid using Signal, even for unclassified information. The notice cited a “vulnerability” and said Russian hacking groups abused the app’s “linked devices” feature to watch conversations that were supposed to be private. The warning came days after senior officials accidentally added a reporter to a group chat about planned strikes, a mistake that showed how user actions can undo encryption.
Public reporting since that week has repeated a clear split. Signal’s end-to-end encryption protects messages in transit, but that protection stops at the phones and computers people hold. If a device is compromised, if a phish tricks a user, or if settings allow extra linked devices, attackers can read content without “breaking” the encryption. That is why agencies and companies treat apps as tools, not shields, and set strict rules for sensitive topics.
What Experts Say About Encryption Versus Endpoints
Newsrooms and security specialists widely rate Signal as one of the safest messaging apps for daily use. They also stress that it cannot stop a bad invite, a screenshot, a spy app on a phone, or a scammer posing as a trusted contact. Cybersecurity experts note there are no confirmed cases of criminals cracking Signal’s encryption at scale, yet they warn that human error and device access remain open doors for attackers, including against senior officials.
Dutch cybersecurity agencies and others have flagged campaigns that target individual Signal users, often with social engineering. Signal itself urged users to slow down, check identities, and watch for account takeover tricks. These alerts underline the same point: strong cryptography does not fix weak operational behavior. High-value targets draw persistent attempts, so identity checks, limited linked devices, and updates are vital for safety, even on a well-designed app.
Why This Matters Beyond Tech Circles
This episode shows how modern government and business lean on consumer tech while facing nation-state level threats. Workers reach for what is simple and fast. Adversaries target those habits. Americans across the political spectrum worry that institutions cut corners, chase convenience, and then blame the tool when sloppy practices cause leaks. The Pentagon’s caution on Signal confirms a broader reality: security fails at the edge, where people and policies meet pressure and speed.
For readers, the takeaway is practical. Encryption helps, but it is not a magic cloak. Verify contacts in person or by a second channel. Lock down phones with updates and strong passcodes. Limit or review linked devices often. Treat any new “urgent” request with suspicion. Use different channels for the most sensitive work, as many experts advise for national security matters. These steps do not require elite tools; they require steady habits and leadership that values restraint over speed.
Sources:
reddit.com, mozillafoundation.org, mark37.com
© newsworthy.news 2026. All rights reserved.













