How a Journalist Ended Up in a Bunker Planning Conversation
In March 2025, something happened that should have been impossible under basic operational security protocol. Jeffrey Goldberg, editor-in-chief of The Atlantic, found himself added to a Signal group chat where senior Trump cabinet officials including Defense Secretary Pete Hegseth were discussing imminent military strikes on Houthi targets in Yemen. Someone made a mistake. Someone added the wrong contact. And suddenly, a sitting journalist had a front-row seat to real-time strategic military planning that had not yet been announced to the public.

I have spent twenty years in this profession calling police departments, city councils, and the occasional panicked communications director. I know what happens when information gets loose. I know the feeling when someone realizes they have said too much. But this incident cuts at something deeper than a typical leak or communications failure. This was not Deep Throat meeting in a parking garage. This was institutional machinery so normalized around commercial communication platforms that classified discussions were happening on an app designed for teenagers to share memes without their parents seeing them.
What made this possible, according to intelligence law experts at Georgetown Law who have publicly flagged the issue, is a stubborn gap in federal statute. The Espionage Act of 1917, the foundational legal framework governing how government handles classified information, does not explicitly prohibit the use of commercial encrypted messaging applications like Signal for sensitive government discussions. We are living under a century-old law trying to manage a twenty-first-century problem, and the seams are showing.

The Policy-Practice Canyon
Here is where the story gets interesting from a source-criticism perspective. On paper, restrictions do exist. The NSA, updating its internal policy in 2023, explicitly barred the use of commercial apps including Signal for anything classified above UNCLASSIFIED//FOR OFFICIAL USE ONLY. This is not ambiguous language. It is a direct prohibition. Yet Defense Secretary Hegseth and his colleagues were apparently comfortable enough with the risks to use Signal anyway for discussions about active military operations.
This gap between written policy and actual practice tells us something important about how information actually flows through federal institutions. A policy memorandum issued from NSA headquarters carries weight, certainly. But it carries no enforcement mechanism that matches the friction of everyday work. Signal is convenient. Signal is familiar. Signal does not require IT department approvals. Signal works on your personal phone. The policy exists in one reality, and the officials exist in another.
I have learned covering municipal government that the difference between formal procedure and street-level practice often comes down to one variable: friction. Make something too hard to do, and people find workarounds. This does not stop applying just because the stakes involve national security. In fact, the higher the stress environment, the more likely people are to reach for the path of least resistance.
Congressional Letters and Delayed Answers
Senator Mark Warner of Virginia, a member of the Senate Intelligence Committee and someone I have found over the years to be genuinely committed to oversight rather than theatrical outrage, sent congressional letters in March 2025 demanding reviews from the NSA and DOD Inspector General. He wanted accountability. He wanted to know how this happened and what safeguards would prevent it from happening again.
As of early 2026, nearly a year later, neither review had been publicly released.
This is not shocking. I have watched municipal bureaucracies take six months to respond to FOIA requests about parking tickets. But this is different. This involves national security. This involves a journalist having access to information about military operations before they were public. This involves questions about whether anyone in the chain of command faced consequences or whether procedures were actually changed. The public silence suggests answers that nobody particularly wants to give.
The The Atlantic’s Original Signal Chat Report was thorough and documented. But reporting alone cannot substitute for institutional accountability. Reporters can tell you what happened. Inspectors General can theoretically tell you whether rules were broken and what needs to change. The fact that we have neither in this case, months after the incident became public, is itself a form of data.
The Broader Pattern of Undisclosed Incidents
In early 2026, the Project on Government Oversight released a report that should have alarmed everyone paying attention. They found that at least nine other incidents of sensitive government business being conducted on commercial platforms had been internally documented but never publicly disclosed since 2021. Nine. Not one mistake by one cabinet secretary. A pattern of behavior, documented internally, kept quiet externally.
This is the researcher’s nightmare and the transparency advocate’s confirmation of their worst suspicions. The information exists. Someone knows about it. But it stays in the system. It does not leak. It does not become public. It just sits there, filed away, creating a historical record that citizens are technically not allowed to know about.
The Project on Government Oversight Federal Transparency Reports have documented other instances of this pattern across federal agencies. Incidents logged, investigations conducted, lessons supposedly learned, and yet the public remains unaware until an independent watchdog organization conducts research and forces the issue into daylight. This is not how accountability is supposed to work. Accountability is supposed to be visible. It is supposed to create consequences that other officials observe and internalize.
What the Gaps in Law Actually Mean
The technical legal question here matters, but the practical institutional question matters more. Congress could tomorrow close the statutory gap in the Espionage Act. They could write explicit language prohibiting commercial encrypted messaging for classified discussions and create enforcement mechanisms with teeth. Would that solve the underlying problem?
Maybe partially. But it would not address the friction problem. It would not address the reality that officials under stress reach for the easiest tool available. It would not address the fact that compliance is genuinely difficult when policies make work harder without offering better alternatives. An IT-secure messaging system that requires approvals and passwords and time might technically satisfy the law while remaining something people avoid whenever possible.
The real story buried in Signal-Gate is not about one journalist’s accidental access or one cabinet secretary’s communication choice. It is about a federal government where information management has not caught up with the tools people actually use. Policies on paper, realities in practice, living in separate worlds. Oversight mechanisms that are supposed to keep institutions accountable but that operate largely outside public view.
Why This Matters Beyond the Headline
I keep my police scanner on my desk because I believe information should move. Because sunlight is the best disinfectant. Because people behave differently when they know they are being watched. Institutional accountability depends on visibility. It depends on the public and press knowing what happened, being able to assess it, and holding officials accountable through election, appointment, and institutional consequence.
When incidents remain internal, when reviews are delayed, when patterns of behavior go undisclosed, when the statutory framework fails to address modern communication realities, these are not separate failures. They are a system that is not quite working the way it is supposed to.
If you have worked in government or observed it closely, you have seen how this happens. Good people making reasonable decisions in complicated circumstances. A policy that looks fine on paper but creates too much friction in practice. A legal framework that simply was not written for this moment. None of it is usually malicious. But that does not make it acceptable.
I would be interested in hearing from readers who have observed similar gaps between policy and practice in their own institutional experience. Whether you work in government, private sector security, nonprofit oversight, or academia, these tensions between formal rules and operational reality are everywhere. The specific context matters less than understanding how these failures happen and what actually prevents them. Send me an email. Tell me what you have seen. That is how we understand systems well enough to fix them.