Russian state-sponsored hacking groups are mounting an aggressive global cyber-espionage campaign targeting government officials, military personnel, diplomats, and journalists through widely used messaging applications like Signal and WhatsApp, according to security warnings issued by intelligence agencies in Europe and the United States.
The campaign bypasses end-to-end encryption by exploiting the human element rather than software vulnerabilities. According to a presentation shared with European Union government representatives by cybersecurity officials, attackers are executing spearphishing operations and employing social engineering tactics to compromise individual accounts. The European Union documented eight significant cyber incidents targeting its institutions since the beginning of the year, identifying the takeover of senior officials’ accounts as a primary threat.
How the Messaging App Hijacking Works
Security agencies report that hackers do not break the underlying encryption protocols of platforms like Signal and WhatsApp. Instead, attackers impersonate technical support accounts—such as a fake “Signal Support” profile—or trusted colleagues to trick victims into sharing verification codes or PINs. According to a joint advisory from the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), a malicious actor will alert a target about a fake suspicious login attempt and ask for a verification code in response.
Once the victim provides the numerical code or clicks a fraudulent link, the attackers register the account on a new device or link it through the “linked devices” feature. This grants the hackers total control over the victim’s profile, allowing them to monitor incoming communications, access stored files, and impersonate the user to launch further phishing messages against their professional contacts. The Dutch military intelligence service MIVD and civilian intelligence service AIVD confirmed that this large-scale operation specifically harvests data from individuals operating in political, military, and diplomatic spheres.
Institutional Security Gaps in the European Union
The disclosures mark the first time an EU authority has formally linked such targeted chat-based attacks to a foreign government. National security agencies in Germany and the Netherlands previously flagged similar intrusions targeting prominent political, military, diplomatic and journalistic figures earlier this year. In response to mounting risks, the European Commission previously advised its top executives to deactivate a communication group on Signal amid security concerns, echoing warnings from national authorities urging institutions to reduce reliance on commercial consumer chat apps for official duties.
Internal EU security assessments reveal persistent structural vulnerabilities across the bloc. According to the July briefing for national government representatives, various European institutions continue to maintain fragmented cybersecurity defenses, lacking a unified and standardized system for sharing sensitive and classified documents securely. Major messaging platform providers have not issued immediate public comments regarding the ongoing intelligence warnings.
Mitigation and Defense Recommendations
Western cybersecurity authorities emphasize that messaging applications designed for consumer use carry inherent operational risks when deployed in government settings. Vice Admiral Peter Reesink, director of the MIVD, noted that despite effective end-to-end encryption, apps like Signal and WhatsApp remain unsuitable channels for classified, confidential, or sensitive state information.

To counter account takeovers, the FBI and CISA advise users to treat unsolicited messages from unknown contacts with suspicion, block and report suspicious accounts immediately, and activate available security functions in messaging apps.