Has Signal Ever Been Hacked? The Honest History

Published: October 7, 2026 · Updated: October 8, 2026

Short answer: no, Signal's message encryption has never been publicly broken, and no breach of Signal's servers has ever exposed message contents. The one real incident was in 2022, when attackers breached a vendor (Twilio) and accessed SMS verification codes for about 1,900 users, no messages, no contact lists. Almost every "Signal hacked" story you see is actually a user-level attack: phishing, SIM swapping, or spyware on the phone itself.

"Has Signal been hacked" is a fair question, and it deserves a straight answer instead of marketing. This guide gives you the honest history: what actually happened, what did not, what "hacked" claims usually turn out to be, and what to do if you think your account is compromised.

Get the official Signal APK

from Signal's official site — file hosted by Signal, not by us

Timeline of Signal security history: audits, the 2022 vendor incident, and no message-content breach

The record: what has and has not happened

The 2022 Twilio vendor incident, carefully explained

In August 2022, attackers carried out a phishing attack against Twilio employees and gained access to Twilio's systems. Signal used Twilio to deliver SMS verification codes when users register or re-register their phone numbers. Here is exactly what was and was not exposed (Signal's own incident write-up: Twilio Incident: What Signal Users Need to Know):

The honest lesson: the weakest link was not Signal's encryption or servers, it was a third-party vendor and SMS-based verification. Signal has since moved toward reducing dependence on phone numbers, including usernames that let you connect without sharing your number. The incident is also a good argument for enabling registration lock, covered below.

What "Signal hacked" stories usually turn out to be

When someone says "my Signal was hacked," investigation almost always finds one of these, none of which is a breach of Signal itself:

The attacks that actually target Signal users

Real attack vectors against Signal users
AttackTargetDefense
SIM swappingYour carrier accountCarrier PIN; Signal registration lock PIN
Phishing linksYou (credentials, malware)Never tap verification links; verify senders
Device spywareYour phoneOS updates; avoid sketchy APKs; screen lock
Physical phone accessYour unlocked deviceStrong lock screen; Signal screen lock; disappearing messages
Fake Signal appsYour install sourceDownload only from signal.org/android/apk; verify the signature

Notice the pattern: every row is defended by something you control, not by something Signal failed to do. That is what "end-to-end encrypted with minimal data collection" buys you: the remaining risks move to the endpoints, which are yours to harden.

Flow of real attacks on Signal users: phishing for verification codes and SIM swaps, not breaking encryption
Attackers do not break the encryption. They steal your number or your code.

If you think you are compromised: response checklist

Work through this in order. Do not skip steps because one of them "seems unlikely."

  1. Re-register your number on a phone you physically control. This kicks any attacker's device off your account.
  2. Enable registration lock with a strong PIN you do not reuse elsewhere (Signal settings). This blocks future re-registration without the PIN, even after a SIM swap.
  3. Review linked devices in Signal's settings and unlink anything you do not recognize. Check this on a regular schedule afterwards.
  4. Contact your carrier about unauthorized SIM changes. Ask about a SIM-swap lock or port-out PIN on your mobile account.
  5. Check the phone itself. Update the OS, remove apps you do not recognize, and consider a factory reset if you suspect spyware. No account-level fix helps on a compromised device.
  6. Warn your contacts if the attacker may have messaged them as you. A quick "ignore anything odd from my number yesterday" prevents follow-on scams.
  7. Turn on disappearing messages for sensitive chats going forward, so a future compromise exposes less history.
Checklist for suspected compromise: re-register, check linked devices, enable registration lock
Act fast and in order: re-register, audit devices, lock registration.

Preventing it in the first place

The bottom line is genuinely good news: Signal's core has held up, the one real incident was contained and disclosed, and the attacks that succeed are the ones you can defend against yourself. For the full picture, read Signal's security audits and is the Signal APK safe.

Frequently asked questions

Has anyone ever read Signal messages by hacking Signal?

There is no publicly known case of anyone compromising Signal's servers or encryption to read message contents. Signal's servers do not store readable messages, so there is nothing to steal that way.

What happened in the 2022 Twilio incident?

Attackers breached Twilio, a vendor Signal used for phone-number verification SMS. They accessed verification codes and phone numbers for about 1,900 Signal users. No message content, contact lists, or profile data were exposed, because Signal does not give that data to vendors.

Can my Signal account be hacked through SIM swapping?

Your Signal account is tied to your phone number, so a SIM-swap attack on your carrier can let an attacker re-register your number on their device. Enabling Signal's registration lock PIN is the defense: it blocks re-registration without the PIN even with a swapped SIM.

What should I do if I think my Signal was compromised?

Re-register your number on a device you control, enable registration lock with a strong PIN, review linked devices and unlink anything unfamiliar, and check with your carrier about SIM changes. Details are in the response checklist on this page.

Related guides