Russian Hackers Phish EU Officials Over Messaging Apps

Russian Hackers Phish EU Officials Over Messaging Apps, Exposing Vulnerabilities in Encrypted Channels

A growing trend among nation-state hackers has seen them shift their phishing campaigns from email to popular messaging apps like WhatsApp and Signal. This shift in tactics has exposed vulnerabilities in encrypted channels, with eight “significant incidents” of spear-phishing reported against high-ranking EU government officials in 2026 alone.

The use of messaging apps by threat actors is not new, but the scale and sophistication of these attacks have increased significantly in recent months. The attackers are leveraging the trust that government employees have in their messaging apps, often impersonating official support teams or chatbots to trick targets into providing sensitive information. In some cases, they’ve even used QR codes to link attackers’ devices to victims’ accounts.

According to an internal document obtained by Politico, EU governments have faced a series of attacks on WhatsApp and Signal, with the Dutch government reporting that its attacks spanned both platforms in early March. The European Commission was also forced to ask senior officials to abandon a Signal group they were part of, citing concerns that it might be compromised.

The attackers’ tactics are particularly effective because messaging apps don’t carry the same reputation as email for malicious activity. Encrypted channels like WhatsApp and Signal add an extra layer of security, making it more difficult for threat actors to intercept communications. However, this also means that these channels can be used to evade detection by security monitoring systems.

“It’s a trend we’re seeing among Russian, Chinese, and Iranian threat actors,” says Volexity president Steven Adair. “They’re moving their communications outside of email because it puts actual detailed communication and phishing lures outside of the visibility of security monitoring.” This shift in tactics makes it more challenging for organizations to detect and prevent these types of attacks.

The EU’s Joint Cyber Unit has confirmed the severity of these attacks, citing account takeover targeting high-ranking officials as one of the greatest threats to EU governments in 2026. The trend highlights the need for government agencies to review their communication protocols and security measures to protect against these types of attacks.

As a result of these incidents, EU governments are now working to move away from popular messaging apps and towards more secure channels for official communications. This shift is not just about reducing the risk of phishing attacks but also about promoting a culture of cybersecurity awareness among government employees.

For individuals and organizations, this trend serves as a reminder that no communication channel is completely safe from threat actors. It’s essential to be cautious when interacting with messages or links from unknown sources, even if they appear to come from trusted platforms like WhatsApp or Signal. By being aware of these vulnerabilities and taking steps to secure our online communications, we can reduce the risk of falling victim to these types of attacks.


Source: Dark Reading — 2026-08-27