US Secretary of Defense Pete Hegseth violated Pentagon operational security protocols by sharing sensitive details about planned airstrikes on Houthi rebels in Yemen through a Signal chat group that included unauthorized participants, such as a journalist. The Pentagon Office of Inspector General (OIG) determined that the information, which included mission timelines and specifics about aircraft and munitions, was derived from a communication marked as SECRET//NOFORN and should have been handled at the secret level. Despite Hegseth's claim of declassifying the material, the OIG found that using a non-secure, consumer messaging app for such communications broke Department of Defense rules and posed a risk to US military operations.
The Inspector General's report, released to Congress and the public, recommended that US Central Command review and improve its classification procedures and provide additional training to senior officials on the proper use of electronic messaging systems. The incident, dubbed "Signalgate," highlighted broader issues within the Department of Defense regarding the use of non-DOD-controlled messaging platforms for sensitive communications and underscored the need for stricter adherence to secure communication protocols among top officials.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
The Inspector General recommended that USCENTCOM review classification and portion-marking procedures and that the Defense Department improve cybersecurity and messaging training for senior leaders. The report also urged broader reforms, including a DoD-controlled messaging service and a waiver process for public messaging apps.
By December 2025, a publicly released Pentagon Inspector General report concluded that Hegseth's transmission of sensitive operational information over Signal from a personal device did not comply with DOD policy governing nonpublic information and approved messaging systems. The report said the practice could have put troops and military operations at risk.
After being included in the group, Jeffrey Goldberg revealed that the Signal chat existed and that he had been added to it, bringing the incident into public view under the name 'Signalgate.'
During the March 2025 incident, then–national security adviser Michael Waltz mistakenly included The Atlantic editor-in-chief Jeffrey Goldberg in the Signal group chat where the strike details were shared. His presence exposed the existence of the chat to an outside journalist.
In March 2025, Defense Secretary Pete Hegseth used Signal on a personal phone to send sensitive, nonpublic operational details about planned US airstrikes on Houthi rebels in Yemen, including mission timing and information about aircraft and munitions. The information reportedly repeated content from a USCENTCOM email marked SECRET//NOFORN.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcego.theregister.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.