Desk live·
ForensicPost
Breaches/Third party/File 22-0815

Signal Says Twilio Breach Exposed 1,900 Users, With Three Numbers Targeted by Name

Signal holds almost nothing about its users by design. It still needed Twilio to deliver verification codes — and when Twilio was phished, 1,900 Signal users were exposed and the intruder went looking for three of them by name.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSignal
ActorUnattributed
S. Rosler11 min readConfidence: high3 sources reviewed

Following the phishing compromise of Twilio filed at 22-0808, Signal disclosed on 15 August 2022 that approximately 1,900 of its users were affected. For those users, either their phone number was potentially revealed as being registered to a Signal account, or the SMS verification code used to register was exposed.

Signal notified those users directly and required them to re-register the application on their devices, completing that by 16 August. It stated that message history, contact lists, profile information and block lists were unaffected. Reporting indicates the attacker explicitly searched for three specific Signal numbers.

The Application That Holds Nothing Still Had A Dependency

Signal’s architecture is built so that a compromise of Signal reveals as little as possible. That design held: no messages, contacts or profiles were exposed, because Signal does not have them in a readable form.

What it did have was a supplier in the registration path, because delivering an SMS requires somebody who can deliver an SMS. We have argued concentration at 26-0713, 23-0614 and 22-0412 — that the security of a system is the security of everyone it has delegated to. This is the strongest available demonstration, because the delegating party had minimised its own holdings more rigorously than almost anyone in this database and it did not matter to the exposed metadata.

Three Numbers Is Not A Breach Statistic

The reported detail that the intruder searched for three particular numbers changes what this incident is. 1,900 is the exposure; three is the objective.

This corpus is organised around counts because counts are what gets published, and it records at 22-0118 and 23-0808 that harm follows the situation of the person rather than the size of the set. Somebody using Signal specifically is frequently somebody with a reason to. For those three, the question of who wanted to find them is the entire incident, and no notification scheme has a field for it.

Re-Registration Was A Real Remedy

Signal identified the affected users, told them, and forced a re-registration that invalidated what had been exposed — within about a day.

The corpus almost never gets to record that. The usual remedy is two years of credit monitoring against an identifier that never expires, filed at 22-0617 and 26-0721b. Here the exposed thing was a registration binding, and a registration binding can be reissued. That is a property of the data, not a credit to the response — but the response used it immediately.

How we reported this

Compiled from Signal’s own support notice and contemporaneous reporting, listed below. The report that the attacker explicitly searched for three specific Signal numbers is as reported and is carried as reported, not as a finding of this desk. The underlying Twilio compromise is filed separately at 22-0808 and its figures are not restated here. No individual or number is named. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Twilio Incident: What Signal Users Need to KnowSignal
  2. Signal says 1,900 users’ phone numbers exposed by Twilio breachTechCrunch
  3. Twilio attacker ‘explicitly’ looked for 3 Signal numbersThe Register
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary