Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

The Intercept warns of compromised Signal tipline username

  • What: Signal tipline username compromised by impersonator
  • Impact: Risk to confidential sources and investigative journalism
Read Full Article →

Identity The Intercept warns of compromised Signal tipline username July 9, 2026 Share By SC Staff (Adobe Stock) As noted by Cyber Insider, The Intercept has alerted the public to a security breach involving its official Signal tipline username. An impersonator gained control of the username, posing as the investigative news outlet and potentially jeopardizing confidential sources who attempted to submit sensitive information. An analysis by Dr. Martin Shelton of the Freedom of the Press Foundation suggests several ways the Signal username could have been compromised. The impersonator reportedly began soliciting tips as early as February 2026, actively promoting the compromised username across social media and responding to lawmakers and federal officials approximately 100 times between April and May. During this period, the fraudulent username remained listed on The Intercept's public tip page, increasing the risk of sources unknowingly contacting the impersonator. The Intercept publicly acknowledged the issue on June 30, updating its contact information and instructing users to avoid the previous username, TheIntercept.01. Possible causes for the compromise include Signal accounts becoming inactive and their usernames being released for reuse after about 120 days, or a change in username making the previous one available. SIM-swapping attacks are also a less common possibility. The Freedom of the Press Foundation recommends keeping Signal accounts active, avoiding frequent username changes, securing accounts against SIM-swapping, and enabling Signal's Registration Lock and PIN protection to mitigate future risks. Source: Cyber Insider SC Staff Related Identity New Helix data extortion group uses identity-focused tactics to target SharePoint SC Staff July 9, 2026 Helix initiates contact through vishing, sometimes impersonating managers via caller ID spoofing, to trick targets into device-code phishing schemes for account access, according to a report by ReliaQuest. Privacy 8 victims sue spyware firm Intellexa over Predatorgate scandal SC Staff July 9, 2026 The plaintiffs, including journalist Thanasis Koukakis, lawyers, and intelligence officials, are each seeking €1 million in moral damages. Identity Hackers selling UK government login credentials on dark web amid FortiBleed campaign SC Staff July 9, 2026 The FortiBleed campaign targets internet-facing Fortinet VPNs and firewalls, with over 70,000 devices in 194 countries believed to be affected. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article