If Compromised
When something goes wrong — a device is lost, a member is arrested, a breach is suspected — you need a clear response. Here's how to handle it.
Types of Compromise
| Level | Description | Response |
|---|---|---|
| Device Lost/Stolen | Member's phone is missing | Individual response |
| Device Seized | Phone taken by authorities | Segment assessment |
| Member Arrested | Member detained by authorities | Segment + cell response |
| Suspected Infiltrator | Concern about a member's loyalty | Investigation + containment |
| Active Surveillance | Evidence of ongoing monitoring | Cell-wide response |
Immediate Response: All Situations
- Pause: Stop ongoing activities until situation is assessed
- Alert: Notify stewards through separate/backup channel
- Assess: What information may be compromised?
- Contain: Who needs to know? Who needs to change behavior?
- Respond: Take appropriate action based on assessment
Device Lost or Stolen
Member Actions
Immediately:
- Use another device to sign out of Signal remotely (if possible)
- Alert segment lead through alternate means
- Change passwords for any accounts on device
Signal Deregistration:
- On new device, install Signal with same number
- This deactivates Signal on the lost device
Cell Actions
- Remove member from groups until secured
- Assess: Was device locked? Encrypted? What was on it?
- If low-risk (locked, encrypted, nothing sensitive): resume
- If higher-risk: notify affected members
Device Seized by Authorities
Member Actions
- Do not unlock if asked — you can refuse (though there may be consequences)
- Say: "I do not consent to a search of my device"
- Contact an attorney immediately
- Alert cell through alternate means when possible
Cell Actions
- Assume all content is accessible — encrypted devices can potentially be broken
- Remove member from all groups immediately
- Notify affected members: "Someone with access to our group has had their device seized"
- Assess what information was on the device
- Rotate sensitive information (meeting locations, etc.)
- Do NOT discuss response in compromised channels
Member Arrested
Immediate Actions
- Confirm facts: Who, when, where, by which agency
- Contact attorney: Immigration attorney for immigration detention, criminal defense for other arrests
- Contact family: Follow the member's emergency plan
- Alert cell stewards: Through secure channel
Cell Assessment
- What did this member know?
- Which segments were they in?
- What activities were they involved in?
- What communications did they have access to?
Cell Response
- Minimize exposure: Pause activities this member knew about
- Notify affected members: Without revealing the arrested member's identity to those who don't need to know
- Support the member: Legal support, family support (if this won't compromise others)
- Monitor situation: Is there evidence of broader enforcement?
Suspected Infiltrator
This is the most difficult scenario — you suspect someone isn't who they claim.
Warning Signs
- Asking lots of questions about operations, other members
- Pushing for information beyond their segment
- Encouraging illegal activity
- Inconsistencies in their story
- Voucher expresses doubts or distances themselves
- Gut feeling shared by multiple people
Response
- Don't confront directly — this tips them off
- Discuss with stewards only — in person, not on Signal
- Freeze their access: Don't add to new groups, don't include in new activities
- Assess exposure: What do they already know?
- Create distance: Gradually reduce their involvement
- If confirmed: Remove from all groups, notify affected members without details
Important
You may be wrong. Act carefully. Wrongly accusing someone damages trust.
Active Surveillance
If you have evidence of surveillance (not just suspicion):
Evidence Examples
- Consistent vehicle observation
- Confirmed physical following
- Device tampering
- Legal papers revealing monitoring
Response
- Full pause: Stop all sensitive activities
- In-person steward meeting: No devices, private location
- Assess scope: Is it targeted (one person) or broad (the cell)?
- Seek legal counsel: Understand your exposure
- Decide: Restructure, pause, or dissolve depending on severity
Communication During Compromise
What to Say
- Keep it brief and factual
- "There has been a security concern. Pause all activities until further notice."
- "We are assessing a situation. Stewards will follow up."
What Not to Say
- Don't speculate
- Don't assign blame
- Don't share more than people need to know
- Don't discuss on potentially compromised channels
Backup Communication
Every cell should have a backup communication plan:
- Secondary Signal contact for each member
- In-person meeting location/time if communications go dark
- Designated all-clear signal to resume