CERT-EU has formally warned that state-backed actors are conducting tailored spearphishing and social-engineering campaigns against senior European Union officials on WhatsApp and Signal. Attackers used impersonation lures, including a fraudulent Signal support chatbot, to steal authentication codes, take over messaging accounts, and gain access to incoming communications and group chats. Dutch intelligence attributed related activity to Russia, while German authorities warned that political, military, diplomatic, and investigative-journalist targets were at risk.
An internal CERT-EU presentation delivered to national-government officials identified messaging-account takeover as a leading threat and reported eight significant incidents affecting EU institutions since the start of 2026. The warning also highlighted fragmented security tooling across EU bodies and the absence of a shared platform for exchanging sensitive or classified documents, leaving high-value communications exposed to targeted compromise.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
By August 2026, EU cybersecurity officials reported that EU institutions had experienced eight significant cyber incidents since the start of the year. Officials also cited fragmented cybersecurity tooling and the absence of a common system for exchanging sensitive or classified documents.
In July 2026, CERT-EU delivered an internal presentation to EU national-government representatives identifying state-sponsored spearphishing and account takeover attempts against high-ranking EU officials' messaging accounts. The activity used tailored lures and a fraudulent Signal support chatbot to obtain authentication codes, enabling access to victims' incoming messages and group chats.
In March 2026, at least five national cyber and intelligence agencies publicly warned of campaigns targeting Signal and WhatsApp users. Dutch intelligence attributed the activity to Russia, while German authorities warned that senior political, military, diplomatic and investigative-journalist figures were targeted.
Earlier in 2026, the European Commission instructed some senior officials to shut down a Signal group because of concerns about hacking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.