Russian Hackers Are Phishing EU Officials on WhatsApp and Signal

Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

ThreatVectr Newsdesk· 4 min read
A smartphone resting on a car dashboard at night, its screen glowing with an incoming call notification, rain-blurred streetlights visible through the windscree
Share

Key points

  • Eight significant spear-phishing attacks, meaning highly targeted digital cons, hit senior EU government staff via WhatsApp and Signal in 2026, according to an internal EU document obtained by Politico.
  • Germany identified Russia as responsible for campaigns that successfully broke into the account of Bundestag President Julia Klöckner.
  • Attackers used no malware at all: only fake security alerts and QR codes to steal account access.
  • The European Commission's own 2025 security plan calls for a shared, EU-wide secure messaging platform agreed by end of 2026.
  • France's attempt at an in-house alternative, an app called Tchap, was itself breached in 2026, leaking three years of communications from 73,000 civil servants.

Most people expect a suspicious message to arrive by email. Criminals know this.

That is the quiet insight behind a wave of attacks on European Union officials that security agencies have been watching build since February 2026. Rather than sending fake emails, hackers linked to Russia have been sliding into government inboxes on WhatsApp and Signal, two popular encrypted messaging apps that people tend to trust precisely because they feel informal and private.

How did the hackers actually get in?

They didn't break software. They broke people.

In some cases, attackers pretended to be Signal's official support team, sending urgent messages warning targets they were about to lose all their data. To "save" their account, officials were asked to hand over their account PIN. In other cases, the attackers sent QR codes, those square barcode images you scan with a phone camera. Scanning them silently linked the attacker's device to the victim's Signal account, giving full read access to messages going forward.

On 6 February, German intelligence authorities issued a joint warning that a state-controlled group was targeting senior figures in the military, diplomacy, and politics across Germany and the wider EU. The Dutch government confirmed its own officials faced identical attacks weeks later, spanning both WhatsApp and Signal and targeting civil servants and military personnel.

The EU's Joint Cyber Unit later briefed European governments that account takeover of senior officials now ranks among the gravest threats facing EU institutions in 2026, first reported by Dark Reading citing the Politico document.

Why are messaging apps such an easy target?

They sit outside the security tools most organisations run on email.

Steven Adair, president of cybersecurity firm Volexity, put it plainly: moving to apps like Signal or WhatsApp places the actual conversation "outside of the visibility of security monitoring." Messages can also be deleted, something email does not really allow. Russian, Chinese, and Iranian hackers have all adopted this approach for exactly those reasons.

The deeper problem, as security consultant Collin Hogue-Spears of Black Duck notes, is structural. No shared secure messaging platform exists across EU governments. So officials fill the gap with consumer apps, and consumer apps become the attack surface.

Event Date Detail
German security warning issued 6 Feb 2026 Named likely state-controlled actor using Signal
Bundestag President's account breached Early 2026 Julia Klöckner's account taken over
Dutch government reports attacks Early March 2026 WhatsApp and Signal both used
EU Joint Cyber Unit briefing July 2026 Eight significant incidents confirmed
France's Tchap app breached 2026 73,000 staff, three years of messages leaked

Should ordinary people worry?

This particular campaign targeted heads of state, diplomats, and senior civil servants, not the general public. But the tactics are not unique to espionage.

Fake support messages and malicious QR codes are appearing in everyday scams too. If you receive an unexpected security alert on any messaging app asking for a PIN or asking you to scan a code, treat it the way you would a suspicious email: ignore it, and report it through official channels.

Common questions

Would stronger passwords have stopped this?

No. These attacks bypassed passwords entirely by tricking people into handing over account access directly. A strong password would not have helped; recognising the fake support message before responding would have.

Are encrypted apps like Signal actually safe to use?

Signal's encryption is strong: the app itself has not been broken. What failed here was how people used it, specifically, trusting messages that appeared to come from Signal's own support team. The app is safe; the social engineering around it is not.

© 2026 Threat Vectr