Even Teams flags external participants to a chat. How was a phone number not known to be within the government perimeter allowed to be added with no alarm to a chat thread in an app pre installed and approved by the agency ?
There are more questions than answers here and its clearly suspicious to say the least that a prominent threat vector such as a mistaken phone number could go unnoticed and not trip a single flag. We're not talking about compromised sim cards or anything, a simple fat finger could expose a secure messaging app thread to an external participant and this is approved by the department for years? How many "Mistakes" over the years have gone unreported ?
Waltz or anyone on that thread isn't responsible for IT, so who ultimately didn't secure this vector?