Russian hackers have been exploiting a new vulnerability in European Union (EU) cybersecurity defenses by phishing government officials on popular messaging apps like WhatsApp and Signal. This trend marks a shift away from email, where nation-state threat groups typically conduct their socially engineered attacks.
The EU has confirmed that state-sponsored hackers have successfully spear-phished government officials using messaging apps, often impersonating the official support team or sending urgent security alerts to trick targets into providing sensitive information. In some cases, attackers used QR codes linked to malicious websites, allowing them to gain access to targeted accounts without even requiring a password.
The problem is particularly severe in Europe, where eight significant incidents of spear-phishing on WhatsApp and Signal have been reported this year alone. The European Commission has taken steps to mitigate the risk, advising senior officials to abandon groups they were part of due to fears that they might be compromised. Dutch authorities identified Russia as the perpetrator of these campaigns after discovering that their own government had been targeted.
“This trend of threat actors moving communications outside of email is becoming increasingly common among Russian, Chinese, and Iranian threat actors,” says Steven Adair, president of Volexity. “By using alternative communication channels like messaging apps, attackers can evade security monitoring and delete messages once they’ve achieved their goal.”
The shift from email to messaging apps is attributed to the fact that many government employees consider these platforms to be more secure due to end-to-end encryption. However, this blind spot has created an opportunity for nation-state hackers to exploit trust in these platforms.
In Germany, a group of state-sponsored hackers successfully breached Bundestag President Julia Klöeckner’s account using Signal. The incident sparked a wave of similar attacks across the EU, with Dutch authorities confirming that their own government had been targeted on WhatsApp and Signal. The European Commission has emphasized that account takeover targeting high-ranking officials is one of the greatest threats to EU governments in 2026.
EU officials are now working to educate employees about the risks associated with using messaging apps for official communication. “We’re seeing a lot more attacks happening through these alternative channels,” says Adair. “It’s essential that organizations and individuals take steps to protect themselves, including implementing robust security measures and educating users on how to identify phishing attempts.”
As a user of popular messaging apps, it’s essential to be aware of the risks associated with using these platforms for official communication. Be cautious when receiving unexpected messages or alerts, especially if they request sensitive information like account PINs or login credentials. Remember that even encrypted messaging apps can be vulnerable to social engineering attacks. By being vigilant and taking steps to protect yourself, you can reduce your risk of falling victim to these types of attacks.
Source: Dark Reading — 2026-08-27