But, it's a flagrant leak of classified info. Using a medium explicitly prohibited by policy. And likely now lost to time (Signal messages can be configured to auto-delete on a timer), when all of this sort of correspondence is legally required to be retained.
The basic Signal vulnerability even if the protocol is perfectly sound is that they can push effectively silent automatic app updates to do whatever. Presumably they didn't want to signup for this but that's how app distribution works nowadays, and it's certainly not fit for classified information.
But, it's a flagrant leak of classified info. Using a medium explicitly prohibited by policy. And likely now lost to time (Signal messages can be configured to auto-delete on a timer), when all of this sort of correspondence is legally required to be retained.