A Department of Homeland Security audit found that U.S. Secret Service agents routinely used personal smartphones during foreign assignments because government-issued devices were too restricted for operational needs. Auditors said official devices often could not support basic tasks such as WhatsApp communication with foreign counterparts, internet research, group texting, or sending and receiving images, pushing personnel to use unmanaged personal devices despite policy prohibitions.
The audit warned that this practice exposed communications, personnel, and protectees to interception, tracking, malware, and other compromise risks, while also identifying weaknesses in the agency’s own mobile security controls. Findings included delayed deployment of mobile threat defense software, failures to wipe devices after foreign travel as required, and inadequate security assessment of a third-party archived messaging app apparently referring to TeleMessage, which the Secret Service stopped using in May 2025; the agency agreed to five recommendations covering device management, training, overseas device security, app testing, and enforcement of the ban on personal device use.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Following the audit findings, the Secret Service agreed to five recommendations covering device management, training, overseas device security, app testing, and enforcement of the ban on personal device use. This marked the agency's formal response to the audit.
A DHS audit found that U.S. Secret Service agents routinely used personal smartphones during foreign assignments because government-issued devices were too restricted for operational needs. The audit also identified related mobile security weaknesses, including delayed mobile threat defense deployment, failures to wipe devices after foreign travel, and inadequate assessment of an archived messaging app.
The DHS inspector general report said U.S. Secret Service government devices used overseas did not have required mobile threat defense software until August 2025. The delayed deployment was cited as a security weakness that increased the risk to sensitive official communications.
Auditors said the Secret Service stopped using a third-party archived messaging app apparently resembling TeleMessage. The cessation was explicitly anchored as occurring in May 2025.
On July 13, 2024, shortly before the attempted assassination of Donald Trump in Butler, Pennsylvania, a Secret Service employee used a personal device to receive an image of the suspect because a government-issued phone could not support the need. The inspector general later cited the incident as an example of operational risk created by mobile device limitations.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourcetheregister.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.