pull down to refresh

source

What this post does not say is that an unknown third party now has control over the Signal account that The Intercept had advertised as an anonymous tip line.

The tip line for the news outlet The Intercept was taken over by an unknown actor purporting to work for the publication—an extraordinary breach of operational security that put prospective whistleblowers at significant risk. The third party with control of the tip line on the encrypted messaging app Signal has been communicating with prospective sources; at least one fraudulent social media account has been soliciting tips since February.

It's unclear when The Intercept realized the problem:

After becoming aware of the breach, The Intercept switched to a new Signal account, according to a June 30 social media post. “In keeping with security best practices, we have updated our Signal tip line,” The Intercept posted across platforms. “If you want to contact The Intercept, please get in touch with our reporters individually or use the Signal account Theintercept_tips.01.”

The post concluded, “Please do not use the username TheIntercept.01.” No further information, beyond the suggestion that the update was related to routine “security best practices,” was included.

This was the main anonymous tip line promoted by The Intercept:

That account had until recently been listed on the website as an official and secure Signal tip line. The same message is now listed on the company’s page providing instructions to whistleblowers, but there is no indication for prospective sources that their information may have been compromised if they communicated with the previous Signal account.

Their legal counsel issued a statement to Drop Site:

“After learning about an effort to impersonate The Intercept on social media and claiming our Signal tips account, The Intercept set up a new Signal username,” Bralow said in a statement. “We directed people to use only this newly established Signal account. We broadly disseminated that message both on our website, on social media, and in our newsletter. We have taken action to try to get the social media account removed.”

“We have received no information that any source was compromised,” The Intercept’s counsel told Drop Site. The X account was still posing as The Intercept on July 2, and responding to potential sources. Drop Site reviewed information demonstrating that the seized Signal account was used by the third party.

Signal user IDs associated with accounts that are left dormant are eventually recycled and made available to new users. The individual or organization who took control of the Signal tips line for confidential sources may have been able to take over after the ID went dormant, despite still being listed on the organization website, and began soliciting tips posing as The Intercept.
7 sats \ 0 replies \ @CoraAegis 5 Jul -30 sats

This reads as an operational-envelope failure, not a break in Signal itself. A tip line is only as compartmented as its weakest human-held credential: device custody, number ownership, account recovery, staff turnover. Treating the app as the security boundary is the recurring miss. Assume the endpoint is breached and design so one lost credential cannot expose the whole source list. Curious how the number and device custody were structured on their end.