ProBackend
cybersecurity
2 hours ago6 min read

EU Officials Targeted by Russia-Backed Signal and WhatsApp Phishing Campaigns

Nation-state threat groups have shifted focus from email to Signal and WhatsApp for phishing EU and government officials, using social engineering to steal security codes and gain account access. Dutch and German intelligence warn that encrypted messaging apps are now primary targets despite end-to-end encryption.

Nation-state threat groups have shifted focus from email to Signal and WhatsApp for phishing EU and government officials, using social engineering to steal security codes and gain account access. Dutch and German intelligence warn that encrypted messaging apps are now primary targets despite end-to-end encryption.

The pivot from email to encrypted apps

For years, government email systems were the preferred attack vector for intelligence agencies seeking to infiltrate political circles. The perimeter was familiar, the protocols well-documented, and the defenses layered. Then the calculus changed. Russian-backed operatives pivoted to Signal and WhatsApp, drawn by the very end-to-end encryption that ordinary users prize. Government officials, accustomed to sharing sensitive coordination on these platforms, suddenly found themselves in the crosshairs. The shift isn't accidental — it's a calculated exploitation of trust. As Vice-Admiral Peter Reesink of the MIVD put it, "Despite their end-to-end encryption option, messaging apps such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information." That warning lands with the force of a policy rewrite, not a technical footnote.

The anatomy of the phishing campaign

Chatbot impersonation and the PIN trap

The most frequent entry point is deceptively simple. Hackers masquerade as a Signal Support chatbot, initiating contact with a target under the guise of a security alert. The message warns of suspicious activity on the account and urges immediate action. If the user follows the instructions — entering a PIN, scanning a QR code — the account is silently linked to an external device controlled by the attackers. Federal prosecutors in Germany have been conducting a preliminary investigation since mid-February 2026 into these alleged cyberattacks on Signal accounts, and their findings so far are stark: around 300 Signal accounts belonging to individuals within the political sphere were compromised. The fake security chatbot told targeted users to take immediate action, and in following those instructions, users unwittingly handed over the keys to their own conversations.

Linked devices and silent takeovers

A second vector leverages Signal's own "linked devices" function. Once a user enters a PIN or scans a code under false pretenses, the hacker gains access to link their own device to the victim's account. From there, they can read past chats, follow ongoing conversations, and even inspect address books and other stored data. The subtlety of this method makes it particularly dangerous — there may be no obvious sign of intrusion beyond the anomalous behavior the Dutch agencies flagged: contacts appearing twice in a user's list, or phone numbers showing up as "deleted account." These small clues are the digital equivalents of a door left slightly ajar.

Intelligence community responses

Dutch advisory and German investigation

The Dutch response arrived first, with the AIVD and MVD warning that Russian state hackers are engaged in a large-scale global cyber campaign to gain access to Signal and WhatsApp accounts belonging to dignitaries, military personnel and civil servants. Dutch authorities issued a cyber advisory notifying government colleagues of the vulnerability and providing assistance to eliminate the threat. The German government, for its part, suspects Russia is behind a series of phishing attacks on Signal targeting high-ranking politicians, including two government ministers, military personnel and journalists. However, the attribution is not yet official, the German government has still not formally attributed the attacks to Russia, even as Der Spiegel reported, quoting governmental sources, that around 300 Signal accounts were compromised. Federal prosecutors confirmed a preliminary investigation has been underway since mid-February 2026, exploring suspicions of espionage among other things.

The Russian embassy in Berlin did not respond to an AP request for comment, and Moscow has repeatedly denied any spying on other countries. Alexander Graf Lambsdorff, the German ambassador to Russia, was summoned to the Russian Foreign Ministry, though Lambsdorff dismissed the likelihood that the Russian side could substantiate its accusations. Relations between the two countries have been tense for years, and this latest episode adds another layer to an already fraught diplomatic landscape.

Scale and targets

Both Dutch and German warnings converge on the same concerning picture: the targets are not random. Government employees, high-ranking politicians, military personnel, and journalists are the primary focus. The Dutch authorities specifically warned that targets include Dutch government employees and that journalists may also have been targeted. The scope is global, with the campaign reaching across borders and institutional lines. The sheer number, approximately 300 compromised Signal accounts, suggests this is no isolated operation but a sustained effort to infiltrate political and media circles.

The classified information dilemma

The intersection of end-to-end encryption and government secrecy creates a persistent tension. Messaging apps offering E2E encryption are popular with government officials precisely because they allow secure communication of confidential or classified information. Yet the very feature that makes them attractive, encryption that even the provider cannot bypass, also makes them attractive to adversaries who want to intercept those communications. The Dutch MIVD director's warning encapsulates the dilemma: "Despite their end-to-end encryption option, messaging apps such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information." The statement is blunt, perhaps even inconvenient for officials who have integrated these tools into daily workflows. But it reflects a risk assessment that the social-engineering vulnerabilities outweigh the encryption benefits when adversaries are actively exploiting the human element.

What needs to change

The pipeline from phishing message to compromised account is short enough that a single moment of inattention can hand over control. The methods, fake chatbots, linked-device abuse, PIN tricking, all rely on the same human factor: the urge to respond to a perceived security emergency. What's needed is a concerted shift in operational culture. Government agencies must treat Signal and WhatsApp with the same caution they once reserved for email, implementing stricter verification protocols before any code entry or device linking. Training that treats these scenarios as real-world threat simulations, not theoretical exercises, would help officials recognize the patterns before it's too late. And at the policy level, the explicit warnings from Dutch and German intelligence should translate into concrete guidance: if sensitive information must be shared, encrypted government channels remain the gold standard, and consumer messaging apps should be reserved for non-sensitive coordination at most.

The evidence is mounting that the threat is persistent, evolving, and broadly scoped. Russian-backed actors have demonstrated they are willing to adapt their tactics, moving from email to encrypted messaging apps with efficiency. The Dutch and German warnings are not separate data points, they are signposts pointing to the same underlying reality. Officials who continue to use these platforms for sensitive communications do so at their own risk, and the intelligence community's job is to make sure that risk is well-understood, clearly communicated, and actively mitigated.

Source: Economic Times, Russia-backed hackers breach Signal, WhatsApp accounts of officials, journalists, Netherlands warns; AP News, German government suspects Russia in Signal phishing attacks on politicians

the pivot from email to encrypted apps

More blogs