Full Report
WIRED has found four new Venmo accounts that appear to be associated with Trump officials who were in an infamous Signal chat. One made a payment with a note consisting solely of an eggplant emoji.
Analysis Summary
# Venmo Data Exposure Among Senior Government Officials
## Key Points
- Investigative findings by WIRED revealed four additional Venmo accounts belonging to high-ranking Trump administration officials that remained public or partially exposed.
- Exposed data includes granular transaction histories, personal contact lists, and social connections to spouses, service providers, and political associates.
- Security experts classify this as a significant counterintelligence risk, as "digital exhaust" allows foreign intelligence services to map social networks, identify leverage points (e.g., family members), and target individuals in the official's immediate circle (e.g., trainers, gardeners).
- The exposure is linked to officials who were previously identified in a compromised Signal group chat ("Houthi PC small group"), suggesting a pattern of poor operational security (OPSEC).
- Venmo’s default settings historically made friend lists public; while contact syncing has been deprecated, existing friend lists remain visible to the public unless users manually opt into private settings.
## Threat Actors
- **Foreign Intelligence Services (FIS):** Described by experts as "carnivorous" in data collection, using signals intelligence to identify patterns of life and points of coercion.
- **Adversarial Entities:** Exploiting "digital exhaust" for social engineering, blackmail, or targeting high-value US government personnel.
## TTPs
- **OSINT (Open Source Intelligence):** Monitoring public fintech platforms to extract metadata, transaction history, and social graphs.
- **Social Mapping:** Using publicly visible "friend lists" to identify spouses, children, and staff members of high-ranking officials to expand the attack surface.
- **Pattern-of-Life Analysis:** Analyzing the frequency, timing, and nature of payments (e.g., cat sitters, picnic expenses) to determine an official's routine and vulnerabilities.
- **Leverage Identification:** Finding personal connections that can be used for coercion or physical targeting.
## Affected Systems
- **Venmo (Mobile Payment Service):** Specifically accounts created prior to 2022 that utilized legacy contact syncing features.
- **Mobile Device Contacts:** Synced phone address books that populated public-facing friend lists.
- **US Government Executive Branch:** Multiple departments including the National Security Council (NSC), Treasury, State Department, and the National Counterterrorism Center.
## IoCs
*Note: The following accounts/links are defanged representations of the entities associated with this data leak.*
- **Individual Accounts (Observed with public/leaking data):**
- Brian McCormack (NSC)
- Dan Katz (Treasury)
- Joe Kent (NCTC nominee)
- Mike Needham (State Department)
- Morgan Ortagus (Special Envoy Deputy)
- Mike Waltz (National Security Adviser - previously exposed)
- Susie Wiles (White House Chief of Staff - previously exposed)
- **Relevant Platform URLs:**
- hxxps://venmo[.]com
- hxxps://www[.]wired[.]com/story/michael-waltz-left-his-venmo-public/
## Mitigations
- **Privacy Setting Hardening:** Users must navigate to **Settings > Privacy > Friends List** and select **Private** to ensure social networks are not visible to the public.
- **Transaction Privacy:** Ensure all transaction settings are set to "Private" rather than "Public" or "Friends."
- **OPSEC Training:** High-ranking officials and their staff should undergo rigorous training on the risks of "digital exhaust" and the counterintelligence implications of using third-party social/fintech apps.
- **Deprecation of Syncing:** Disable and remove synced phone contacts from third-party applications to prevent automatic social graph population.
- **Platform Accountability:** Tech providers should consider "private by default" configurations for users identified as high-risk or government-affiliated.
## Conclusion
The exposure of personal financial and social data of Cabinet-level officials represents a critical vulnerability. While individual transactions (like an eggplant emoji or payments for pet care) may seem trivial, the aggregate data provides a roadmap for foreign adversaries to conduct targeted operations. Immediate remediation through manual privacy adjustments is required for all personnel in sensitive roles to "put the toothpaste back in the tube."