The European Union (EU) confirmed that state-sponsored hackers have been spear-phishing government officials on popular messaging apps rather than email.
Nation-state advanced persistent threats (APTs) commonly socially engineer their nation-state targets over email, impersonating quotidian business to trick targets into opening malicious websites or attachments. Yet email is where most employees expect malicious messages to come from. Messaging apps don’t carry the same reputation, and encrypted ones — like WhatsApp and Signal in particular — add an extra sheen of trusted security.
Recently, state APTs have shifting their phishing campaigns, looking to leverage the trust high-level government employees have in their messaging apps — the blitheness and urgency with which they open and respond to instant messages. The problem is particularly bad in Europe. According to an internal document recently obtained by Politico, EU bloc governments have faced eight “significant incidents” of spear-phishing over WhatsApp and Signal in 2026.
EU Officials Phished Over WhatsApp & Signal
On Feb. 6, two German government authorities published a joint security notice indicating that a “likely state-controlled” threat actor was using messaging services like Signal to target high-ranking individuals in the military, diplomacy, and politics, both in Germany and Europe more broadly.
The incidents involved no software vulnerabilities or malware, only social engineering. In some cases, attackers were impersonating Signal’s official support team or support chatbot, reaching out to targets with urgent security alerts that suggested they were at risk of losing their data and goading them into providing their account PINs. In other cases, attackers reached out to targets with whatever pretext might convince them to scan QR codes. Targets didn’t realize that those QR codes linked attackers’ devices to their accounts.
“There is definitely a trend of threat actors moving communications outside of email with their phishing attacks,” says Volexity president Steven Adair. “Sometimes the initial outreach is via Signal, WhatsApp, Telegram, LINE, etc. Otherwise, we often see email as the starting point with an attempt to move the follow-on communication to these other platforms.”The trend is becoming common among Russian, Chinese, and Iranian threat actors, he says, because “Moving to these other channels often puts actual detailed communication and phishing lures outside of the visibility of security monitoring. Further, many of these alternative communication channels allow the messages to be deleted — something you cannot really do with email.”
The Signal campaign in Germany proved surprisingly successful. Though attackers didn’t compromise German chancellor Friedrich Merz, they did breach Bundestag president Julia Kloeckner. In the weeks and months that followed, a cascade of EU governments realized that they, too, were being targeted. In early March, the Dutch government reported that its attacks spanned WhatsApp and Signal, and targeted dignitaries, military personnel, and civil servants.
Around the same time, the European Commission insisted that a group of senior officials abandon a Signal group they were in, for fear that it might be compromised. The Dutch, and then the Germans, identified Russia as the perpetrator of these campaigns.
In July, the EU’s Joint Cyber Unit confirmed the severity of these attacks in a presentation to European government officials, since obtained by Politico. The presentation cited the eight spear-phishing attacks against high-ranking government employees, and emphasized that account takeover targeting high-ranking officials was one of the greatest threats to EU governments in 2026.
Are Internal Apps Safer Than Commercial Ones?
“The more useful finding sits below the headline,” says Collin Hogue-Spears, senior director of solution management at Black Duck. “No common system exists for exchanging sensitive and classified documents across EU institutions, and the security stacks underneath differ. Absent a common secure platform, consumer messaging keeps absorbing official traffic, which is the condition every one of these campaigns depends on.”
Hogue-Spears adds that without a replacement, even taking a proactive step like shutting down a Signal group chat isn’t going to do much good. “Removing an app from a workflow removes the app, not the workflow. Government CISOs must stand up a sanctioned channel before withdrawing the consumer one. Run a self-hosted messenger on the Matrix protocol, with identity bound to the government directory and device enrollment under mobile device management,” he advises. “Publish one rule alongside it: Signal and WhatsApp carry meeting logistics and nothing further.”
In fact, this is more or less what some EU governments are already doing. Be it for security or data sovereignty, France, Germany, and Belgium (in that order) have all rolled out their own in-house messaging services. According to Politico, Luxembourg, Poland, and the Netherlands are pursuing similar projects.
The European Commission (EC) itself, in a 2025 “Cyber Blueprint,” wrote that EU entities “should agree by end 2026 on an interoperable set of secure communication solutions for relevant Union actors. These solutions should cover the full range of communication modes required (voice, data, video-teleconferencing (VTC), messaging, collaboration and document sharing and consultation). The solutions should reflect key principles such as Union security interests, technological sovereignty, and confidentiality, as well as features such as usability, security-by design, certification by European information security bodies, end-to-end encryption, authentication, availability, and post-quantum cryptography.”
Though internal apps might afford government organizations more control over their own security, they’re certainly no guarantee of it. France’s pioneering Tchap app, for example, launched in 2019, and became mandatory for civil servants in 2025. Then in 2026, once all government communications were gathered in the same place, that place was breached. Reportedly, three years of sensitive communications between 73,000 government employees all leaked to the dark web.

Comments are closed