LONDON — When the text appeared on his screen, it looked like a message from the most powerful aide in the White House. For a brief window, UK Prime Minister Andy Burnham was exchanging messages with someone he believed to be Susie Wiles, Donald Trump’s chief of staff and among the most closely guarded officials in Washington.
He was not.
The incident, first reported by the Sunday Times and confirmed Sunday by Anadolu Agency, adds the sitting British prime minister to a growing list of targets caught in a sophisticated impersonation campaign tied to the May hack of Wiles’ personal phone. Attackers who breached her device did not just steal data. They walked away with her contact list, a directory of world leaders, senior diplomats, and intelligence officials who had trusted her name on a screen.
The source of the impersonation attempt was not a crude phishing message. It exploited contact initiated using Wiles’ own stolen credentials, routed through communication channels that prime ministerial offices routinely use for informal senior-level diplomatic contact. That detail matters because it suggests the attackers understood the communications architecture, not just that Wiles had a phone, but how her contacts used it, and under what circumstances a message from her would be accepted without independent verification.
According to a source cited by Anadolu Agency, the messages exchanged were “of no significance.” The texts were “quickly reported to the appropriate authorities” once they grew suspicious. The UK government offered its standard response when national security is invoked: “We do not comment on national security matters.”

Susie Wiles is not simply an administrative official. She served as Trump’s de facto campaign manager in 2024, guided the transition, and runs the White House’s internal operations with a low public profile that belies the reach of her access. She controls who gets time with the president, manages the personnel process, and is among the handful of people in the world whose messages a sitting prime minister would open without hesitation. Her contacts list is, in practical terms, a map of the Western security and diplomatic establishment.
That list was compromised in May. The attack on Wiles’ phone, the method of which has not been publicly detailed by US officials, was already under FBI investigation before this weekend’s reporting on Burnham. The bureau has been working to identify the actors behind the original breach and to determine how the extracted contacts are being used. The Burnham case appears to be one answer to that last question.
Trump had publicly signaled his expectations for UK-US relations after Andy Burnham prime minister Trump relations were established in late July, creating precisely the kind of diplomatic context an impersonation operation could exploit. A new prime minister seeking to establish his footing with Washington, a chief of staff whose name he would recognize: the combination made a fraudulent opening exchange plausible.
The Burnham episode illustrates a strategic shift in how foreign intelligence operations target allied governments. Traditional signals intelligence, hacking into secure government communications systems, is technically difficult, resource-intensive, and increasingly well-defended by government security frameworks. Impersonating a trusted human contact, using stolen but authentic contact information, requires none of that. The attack surface is not a server. It is the human assumption that a known name on a screen corresponds to the person behind it.
That assumption has long been the basis for informal leader-level communication. No verification protocol exists, or is typically considered necessary, when a message arrives from a number that senior officials recognize. The May breach of Wiles’ phone turned that trust architecture into an attack vector.
Britain has been managing a compressed domestic crisis in parallel. Burnham had already declared a national UK wildfire emergency this month, warning that the country had become a “tinderbox.” His attention has been divided between that domestic crisis and establishing his diplomatic footing with Washington. The impersonation attempt found him at precisely the moment when a message from a senior Trump aide would have made situational sense.
Whether Burnham was the only world leader in Wiles’ contact list to receive and respond to such a message has not been established. The scope of the campaign, how many targets were approached, how many responded, and what the impersonators sought from each exchange, remains unknown. US and British authorities have not publicly commented on those dimensions of the investigation.
What the impersonators were seeking, beyond an opportunity to establish a channel, is not known. Whether the goal was intelligence extraction, the planting of disinformation, or something else entirely has not been disclosed. The messages may have been meaningless. The vulnerability they revealed is not.
For Burnham, the episode arrives early in his premiership, at a moment when the administrative and security infrastructure around his office is still being shaped and tested. For Washington, it is a reminder that the consequences of the May Wiles hack are still unfolding, months after the breach was first identified, and that a contact list, once stolen, does not stop being useful.

