I laughed about Signalgate until I made my own massive privacy mistake

I made a huge privacy mistake and realized that sending sensitive information to the wrong person is easier than you might think.

Apr 7, 2025 - 18:53
 0
I laughed about Signalgate until I made my own massive privacy mistake

Raise your hand if you have accidentally sent personal or sensitive information to the wrong person. I see you out there, US National Security Adviser Mike Waltz, and, if I'm being honest, I'm raising my hand right along with you.

By now, we all know the embarrassing tale of military action plans accidentally sent to an Atlantic editor who was somehow added to a secure Signal chat. It was embarrassing, but now it sounds like it might have been a shockingly relatable mistake and one we can all learn from – including me.

Essentially, a new report claims that Atlantic EIC Jeffry Goldberg's phone number was listed as an alternate contact number for a National Security spokesperson. That's possibly how Goldberg ended up in the incredibly sensitive chat. Waltz selected his spokesperson to add, but the number chosen was Goldberg's.

When I read this I had a shudder of recognition. Our contact systems are smart, fluid, and maybe a bit too fleet-footed at times. Allow me to unburden myself.

What did I just do?

A few weeks back, I was working on some personal and rather sensitive documents that I then wanted to send to my wife. I quickly compiled what I needed, opened Gmail, typed in the recipient, attached the documents, and hit send. I didn't think much of it until my wife quizzed me about the whereabouts of said documents.

I knew I sent them, but I wondered if they'd gotten stuck in the outbox – a rare occurrence that would usually indicate a network issue. Nope, the email showed up in Sent – and then I noticed something horrifying. I had not sent the documents to my wife. Instead, they went to a random business contact whose name and email address also started with "L."

Gmail had autocompleted the address with the first matching email address, and I never looked twice. It was a whopper of a mistake – not national security level, but still big in my world. It was too late to recall the message, so I sent a follow-up to the contact, begging them not to open the doc and delete the email.

It was not my best moment, and I again had a twinge of empathy for Waltz.

Slow down, dude

The reality is that our social media, communications, and email systems are not there to ensure that you use the right phone numbers, handles, and email addresses.

Instead, they go for speed and, in email, autocompleted addresses, which can help you find long or forgotten ones, can be quite useful. But they're also a little dangerous.

Unless you're a salesperson with a customer relationship management (CRM) system, you probably don't spend much time managing the details of any contact.

You might only have an email address. Maybe only a first name. Your contacts may have duplicates with different and old email addresses and phone numbers (the startup Sunshine Contacts is supposed to address some of this).

You might get a new number for a contact and add that. On my iPhone, when I add or update a contact's info, there is a moment of trepidation as I try to figure out if this is a new contact or details for one I already have on my iPhone.

We don't spend enough time, I think, making sure our contact databases on our iPhones and mail systems are up to date, and perhaps we're not being careful enough about our contacts across all our systems.

Caught in a random loop

Think about how many times a random number pops up on your phone with a text or call. Usually, it has no name attached, and your phone is of little use in helping you ferret out if this is a known or unknown person.

For instance, my iPhone sometimes indicates that something is potential SPAM, but it does not do this often enough.

Perhaps because I talk to so many people through Slack or text, I barely know anyone's phone number by heart (I'm even worse with email addresses). It's no wonder I don't know the difference between known and unknown numbers.

I also have way too many email addresses in my system and need a smarter way of cleaning and managing them. I cannot afford to (again