EU Cyber Body Confirms State-Linked Account Takeover Campaign Against Senior Officials on WhatsApp and Signal
STATUS: Confirmed Account Takeover Campaign SEVERITY: 8/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Aug 28, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
An internal presentation from the EU's Interinstitutional Cybersecurity Board, delivered to national governments, marks the first official EU acknowledgment that a foreign government targeted senior officials' WhatsApp and Signal accounts, listing account takeover among the bloc's top threats this year and citing eight significant incidents.
What Happened
Same technique as before. Now it has an official name on the threat list.
An internal EU cyber presentation, delivered to national governments in July, lists account takeover targeting high-ranking officials among the bloc's top threats this year, citing eight significant incidents.1 It is the first time an EU authority has formally attributed attacks of this kind to a foreign government.1
The mechanism matches what national agencies described in March, when at least five national cyber and intelligence agencies publicly warned about campaigns running on Signal and WhatsApp.1 Attackers pose as a Signal support chatbot and persuade the target to hand over a linking code. That single step is enough to attach a second device to the account and begin reading incoming messages and group chats.1 One agency reported that access persisted even after the target switched to a new phone.1
The campaign has already reached the top of national governments. One national warning confirmed a sitting Bundestag President's account was breached and named the wider target set: high-ranking individuals in politics, the military, and diplomacy, along with investigative journalists.2 Earlier this year, the European Commission asked a group of its most senior officials to abandon a Signal chat over compromise concerns, before the EU had formally acknowledged the pattern behind that decision.2
The EU presentation also names a second, more tailored technique alongside direct account takeover: state-sponsored spear phishing that disguises malicious links or files as material tied to the target's actual work: a sanctions package under discussion, an urgent official statement. These are the messages senior officials open without hesitation.3 The same presentation flags a structural problem behind both techniques: EU institutions lack a standardized, common system for secure communications, leaving officials to default to consumer apps for sensitive, informal discussion.4
What They Found and What It Means
Finding | What It Means | Operational Consequence | Open Question |
An internal EU cyber presentation formally attributes account takeover of senior officials to a foreign government for the first time, citing eight significant incidents this year. | What national agencies described in March as an isolated technique is now an EU-confirmed, top-tier institutional threat. | Senior officials across EU institutions, and their national counterparts, are a confirmed and ongoing target set, with incidents already on record. | How many of the eight incidents involved account access that were never publicly disclosed to the affected individuals? |
The device linking hijack technique reportedly persisted even after at least one target switched to a new phone. | Replacing the hardware doesn't necessarily end the compromise if the account-level authorization carries over to the new device. | Replacing the device is standard incident response but it leaves the account, where the compromise actually sits, untouched. | Whether affected organizations have a process to audit and revoke linked devices as a standard step, rather than treating a phone swap as sufficient remediation. |
EU institutions lack a standardized secure communications system, leaving senior officials to default to consumer apps for informal but substantive discussion. | The gap is structural. Officials are choosing between an unmanaged app and no channel at all. | Telling officials to stop using Signal or WhatsApp does not address the need for a fast, informal channel, so the behavior continues on the same unmanaged apps. | What a sanctioned replacement would need to offer to be adopted instead of quietly ignored. |
Why This Matters
Old Assumption | Current Reality | BlackBerry Response |
Encrypted consumer messaging apps are an acceptable channel for informal but sensitive government discussion. | An EU cyber body has now formally listed account takeover of senior officials as a top threat this year, with a sitting national parliament president among the confirmed breaches. | BlackBerry® SecuSUITE® gives officials a sanctioned channel for the exact informal, fast coordination that currently defaults to WhatsApp and Signal, with enrollment the organization controls rather than a public device-linking flow. |
Replacing a compromised device ends the compromise. | Reported cases show account-level access persisting after a target switched phones, because the authorization sits with the account and follows the user onto the new device. | BlackBerry® UEM ties device compliance to an administered account relationship, so a device swap is paired with an actual audit of what's authorized to represent that account, not a hardware refresh alone. |
Telling officials to stop using a compromised app is sufficient guidance on its own. | The EU's own presentation flags the absence of a standardized secure system as a structural problem, meaning “stop using it” has no destination and often gets ignored. | BlackBerry SecuSUITE gives an institution a governed channel to move the workflow into, so the directive has a destination. |
Recommended Actions
IMMEDIATE | Audit linked devices on any WhatsApp or Signal account used by senior personnel for official business. Treat an unrecognized linked device as an active compromise, regardless of how the account was previously secured. |
IMMEDIATE | Do not treat a device replacement as remediation on its own. Confirm the account's authorized device list is clean before considering an incident closed. |
SHORT-TERM | Identify which informal, time-sensitive workflows currently run on consumer messaging apps and evaluate a sanctioned replacement before issuing a “stop using this app” directive with nowhere for that workflow to go. |
SHORT-TERM | Treat unsolicited “support” messages inside Signal or WhatsApp, including any request for a linking code, as compromise attempts by default. |
ONGOING | Track whether the organization has a standardized secure communications system at all, rather than relying on ad hoc guidance issued after each new warning. |
BlackBerry Secure Communications Position
The formal EU attribution puts this threat on the record, but it doesn’t explain why officials were on WhatsApp and Signal in the first place: nothing sanctioned was fast enough to compete with a customer app they already had on their phone. Telling officials to stop, without offering a viable alternative guarantees the same conversation will happen on similar, unmanaged channels, in the future.
Citations:
State-backed hackers targeted EU officials on WhatsApp, document shows (Politico, internal EU cyber presentation findings, as reported by TheNextWeb, August 25, 2026).
Russian Hackers Phish EU Officials Over Messaging Apps (Dark Reading, coverage of national agency warnings on Signal and WhatsApp campaigns, August 27, 2026).
State-Backed Hackers Target High-Ranking EU Officials Through WhatsApp and Signal (The420.in, coverage of the EU Interinstitutional Cybersecurity Board presentation, August 26, 2026).
State actors tried to hack EU officials' messaging apps, cybersecurity body warns (Euronews, European Commission confidential presentation coverage, August 26, 2026).
%3Aquality(100)&w=3840&q=75)