EDIT: Since I've posted this, an English language version of the article has been published. Here is the link. @Mods: please let me know if I should replace it in the in the URL field as well, I'm going to leave it as is for know,
Article both in German and behind a paywall. I've translated the most relevant parts:
Donald Trump's most important security advisors discussed a military strike via signal chat. Research by [the German magazine] SPIEGEL now shows that the problem is even bigger. [...] Private contact details of US President Donald Trump's most important security advisors are available on the internet. Research by SPIEGEL revealed mobile numbers, email addresses and, in some cases, passwords.
For the research, information from commercial personal search engines and customer data published online was used. National Security Advisor Mike Waltz, US Intelligence Coordinator Tulsi Gabbard and Secretary of Defense Pete Hegseth are demonstrably affected by the leaks.
Most of the publicly accessible numbers and email addresses are probably still being used by those affected. Some of them are linked to profiles on Instagram and LinkedIn, among others. They were used to create Dropbox accounts and profiles in apps that track running data. There are WhatsApp profiles for the respective phone numbers, and in some cases even Signal accounts. [...] It is therefore conceivable that foreign agents were reading along when Gabbard, Waltz and Hegseth discussed a military strike in a signals chat with others.
Original German text
Donald Trumps wichtigste Sicherheitsberater diskutierten einen Militärschlag per Signal-Chat. SPIEGEL-Recherchen zeigen nun: Das Problem ist noch größer. Private Kontaktdaten der wichtigsten Sicherheitsberater von US-Präsident Donald Trump sind im Internet einsehbar. Recherchen des SPIEGEL förderten Mobilnummern, Mail-Adressen und teilweise Passwörter zutage.Für die Recherche wurden Informationen aus kommerziellen Personen-Suchmaschinen sowie im Netz veröffentlichte Kundendaten genutzt. Betroffen von den Leaks sind nachweislich der Nationale Sicherheitsberater Mike Waltz, US-Geheimdienstkoordinatorin Tulsi Gabbard und Verteidigungsminister Pete Hegseth.
Die meisten der öffentlich abrufbaren Nummern und Mail-Adressen werden von den Betroffenen wohl immer noch genutzt. Sie sind teilweise mit Profilen unter anderem bei Instagram und LinkedIn verbunden. Mit ihnen wurden Dropbox-Accounts und Profile in Apps angelegt, die Laufdaten tracken. Es finden sich zu den jeweiligen Telefonnummern WhatsApp-Profile, teilweise sogar Signal-Accounts. [...] Es ist daher denkbar, dass ausländische Agenten mitlasen, als Gabbard, Waltz und Hegseth in einem Signal-Chat mit anderen einen Militärschlag besprachen.
So…not to be dramatic or anything, but this sounds really fucking bad.
They're human. All sorts of people have personal accounts compromised, they don’t need flak for that.
What’s bonkers is that they are using at least some of it, casually, for sensitive professional talk. If you are anyone close to this position, you do whatever the heck security tells you without question, and it’s not over public signal or Dropbox accounts.
An analogy is trying not to get sick. Sure, people try their best in their personal lives. No one is perfect. But you would act very different in, say, a CDC lab working on Ebola. This would be like someone walking out with a Petri dish splattered all over their suit, and shrugging when someone with an accent scrapes it off your suit. It just screams "I have no regard for this institution's protocol or the consequences."
…But it’s worse than that. Like, I cannot describe the billions spent on even slightly influencing or penetrating these people's spaces, and it turns out they are operating like your boomer grandparents, apparently ignoring the direct instructions of the largest security institution on the planet like they know better.
Maybe i am naive, but i would think that looking for compromises on personal accounts would be part of a security on-boarding process. Even if they don't discuss sensitive information on their personal accounts. If for instance a foreign agent gets to read them sexting their affairs that creates quite some blackmail material.
I assure you you're not naive. They didnt do background checks or security onboarding for the cabinet "because it would take too long".
https://www.wxow.com/news/trump-s-team-skips-fbi-background-checks-for-some-cabinet-picks/article_62c6ad20-5a99-58c4-a5b5-9004725607d9.html
https://www.whitehouse.gov/presidential-actions/2025/01/memorandum-to-resolve-the-backlog-of-security-clearances-for-executive-office-of-the-president-personnel/