Key Takeaways
- UK politician Andy Burnham exchanged messages with an individual impersonating Susie Wiles, former chief of staff to Donald Trump.
- The British Embassy raised the matter with White House officials after learning of the contact, citing national‑security concerns.
- Downing Street acknowledged the exchange but characterized the messages as insignificant.
- The episode echoes a broader pattern of malicious text‑and‑voice campaigns targeting senior U.S. officials, previously linked to Iranian‑state hackers during Trump’s 2024 campaign.
- Past breaches—including the compromise of Mike Waltz’s communications service and the Salt Typhoon operation—show that hostile actors continue to exploit impersonation tactics to gather intelligence and manipulate targets.
- The incident underscores the need for improved verification protocols, heightened vigilance against social‑engineering attacks, and tighter coordination between UK and US security agencies.
Introduction
In early November 2024, reports emerged that Andy Burnham—a prominent UK politician often mischaracterized in the press as the country’s prime minister—had engaged in a series of text messages with someone claiming to be Susie Wiles, the influential former chief of staff to then‑President Donald Trump. The story, first broken by Politico, quickly attracted attention from diplomatic and security circles because it involved a senior British official communicating with a person who was, in fact, an impersonator. While the exchanged messages themselves appeared mundane, the context in which they occurred raised alarms about the susceptibility of high‑profile figures to sophisticated social‑engineering schemes and the potential ramifications for bilateral security cooperation.
The Impersonation Incident
According to sources cited by Politico, Burnham received a series of messages from an account that purported to belong to Susie Wiles. The sender used language and references consistent with Wiles’s known style, leading Burnham to believe he was corresponding directly with her. The conversation reportedly touched on routine topics such as scheduling and informal pleasantries, with no overt requests for classified information or financial favors. Nevertheless, the very fact that a UK official was engaging with a fraudulent account triggered immediate concern within the British diplomatic establishment, prompting officials to verify the authenticity of the correspondent and to assess whether any sensitive information might have been inadvertently disclosed.
Response from the British Embassy and Downing Street
Upon learning of the exchange, the British Embassy in Washington, D.C., formally raised the matter with their White House counterparts. Embassy officials expressed worry that the incident might indicate a renewed compromise of Wiles’s personal communications, recalling a similar impersonation episode in May 2025 when an unknown actor had allegedly sent texts and placed calls to her contacts in an attempt to solicit financial contributions and presidential pardons. Downing Street, while confirming that Burnham had indeed been in touch with the impersonator, sought to downplay the significance of the interaction, asserting that the content of the messages was innocuous and that no breach of security protocols had occurred. Nonetheless, the episode prompted an internal review of how UK officials verify the identities of foreign counterparts before engaging in digital communication.
Broader Cyber Threat Landscape
The Burnham‑Wiles impersonation fits into a wider trend of malicious text‑and‑voice campaigns aimed at senior government officials. In late 2024, US intelligence agencies issued a warning about an “ongoing malicious text and voice messaging campaign” in which threat actors posed as senior American figures to manipulate targets into divulging information, transferring funds, or taking actions beneficial to the attackers. These campaigns often employ sophisticated social‑engineering tactics, such as spoofing phone numbers, mimicking writing styles, and leveraging publicly available personal details to create convincing facades. The goal is typically to exploit trust relationships and extract intelligence that can be used for espionage, financial gain, or geopolitical leverage.
Historical Precedents and Iran‑linked Campaigns
US authorities have previously attributed similar impersonation operations to hackers acting on behalf of Iran, particularly during the final months of Donald Trump’s 2024 presidential campaign. In those instances, Iranian‑state‑sponsored groups used fabricated messages to sow confusion, attempt to influence political narratives, and gain access to sensitive communications. One notable breach occurred in April 2025 when a hacker infiltrated the communications service used by Mike Waltz, a senior National Security Council official, thereby intercepting messages from a range of American officials. Additionally, the White House has acknowledged that the Salt Typhoon threat group—identified as a Chinese‑state‑aligned actor—had targeted and recorded calls of “top” American figures, demonstrating that multiple foreign adversaries are actively exploiting voice and text channels to gather intelligence.
Implications for UK‑US Relations and Security Protocols
While the Burnham‑Wiles exchange did not result in an overt security breach, it highlights several areas where UK‑US cooperation could be strengthened. First, the incident underscores the necessity of robust identity‑verification mechanisms for digital communications between senior officials, such as multi‑factor authentication, encrypted messaging platforms with verified contacts, and routine confirmation calls through known, secure channels. Second, it points to the value of joint threat‑intelligence sharing regarding emerging social‑engineering tactics, enabling both nations to issue timely advisories and update defensive measures. Finally, the episode serves as a reminder that diplomatic and political figures remain high‑value targets for cyber‑espionage, necessitating ongoing training and awareness programs to help them recognize and resist impersonation attempts.
Conclusion
The brief episode in which Andy Burnham communicated with an impersonator posing as Susie Wiles may appear trivial at first glance, but it sits within a larger, persistent pattern of hostile actors exploiting text and voice channels to deceive senior officials. The reaction from the British Embassy and the subsequent statements from Downing Street illustrate how seriously such incidents are taken, even when the immediate content seems harmless. By situating this event within the context of prior Iranian‑linked campaigns, the Mike Waltz breach, and the Salt Typhoon operation, it becomes clear that the threat landscape is evolving and that both the UK and the United States must continuously adapt their defenses. Enhanced verification protocols, increased information sharing, and sustained vigilance will be essential to mitigate the risk posed by increasingly sophisticated impersonation schemes in the years ahead.

