Skip to main content

EU Cyber Body Confirms State-Linked Account Takeover Campaign Against Senior Officials on WhatsApp and Signal

STATUS: Confirmed Account Takeover Campaign SEVERITY: 8/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads  

Aug 28, 2026

·

Blog

·

Secure Communications

An internal presentation from the EU's Interinstitutional Cybersecurity Board, delivered to national governments, marks the first official EU acknowledgment that a foreign government targeted senior officials' WhatsApp and Signal accounts, listing account takeover among the bloc's top threats this year and citing eight significant incidents. 

What Happened  

Same technique as before. Now it has an official name on the threat list. 

An internal EU cyber presentation, delivered to national governments in July, lists account takeover targeting high-ranking officials among the bloc's top threats this year, citing eight significant incidents.1 It is the first time an EU authority has formally attributed attacks of this kind to a foreign government.1 

The mechanism matches what national agencies described in March, when at least five national cyber and intelligence agencies publicly warned about campaigns running on Signal and WhatsApp.1 Attackers pose as a Signal support chatbot and persuade the target to hand over a linking code. That single step is enough to attach a second device to the account and begin reading incoming messages and group chats.1 One agency reported that access persisted even after the target switched to a new phone.1 

The campaign has already reached the top of national governments. One national warning confirmed a sitting Bundestag President's account was breached and named the wider target set: high-ranking individuals in politics, the military, and diplomacy, along with investigative journalists.2 Earlier this year, the European Commission asked a group of its most senior officials to abandon a Signal chat over compromise concerns, before the EU had formally acknowledged the pattern behind that decision.2

The EU presentation also names a second, more tailored technique alongside direct account takeover: state-sponsored spear phishing that disguises malicious links or files as material tied to the target's actual work: a sanctions package under discussion, an urgent official statement. These are the messages senior officials open without hesitation.3 The same presentation flags a structural problem behind both techniques: EU institutions lack a standardized, common system for secure communications, leaving officials to default to consumer apps for sensitive, informal discussion.4

What They Found and What It Means 

Finding 
What It Means 
Operational Consequence 
Open Question 
An internal EU cyber presentation formally attributes account takeover of senior officials to a foreign government for the first time, citing eight significant incidents this year. 
What national agencies described in March as an isolated technique is now an EU-confirmed, top-tier institutional threat. 
Senior officials across EU institutions, and their national counterparts, are a confirmed and ongoing target set, with incidents already on record. 
How many of the eight incidents involved account access that were never publicly disclosed to the affected individuals?
The device linking hijack technique reportedly persisted even after at least one target switched to a new phone. 
Replacing the hardware doesn't necessarily end the compromise if the account-level authorization carries over to the new device. 
Replacing the device is standard incident response but it leaves the account, where the compromise actually sits, untouched. 
Whether affected organizations have a process to audit and revoke linked devices as a standard step, rather than treating a phone swap as sufficient remediation. 
EU institutions lack a standardized secure communications system, leaving senior officials to default to consumer apps for informal but substantive discussion. 
The gap is structural. Officials are choosing between an unmanaged app and no channel at all. 
Telling officials to stop using Signal or WhatsApp does not address the need for a fast, informal channel, so the behavior continues on the same unmanaged apps. 
What a sanctioned replacement would need to offer to be adopted instead of quietly ignored. 

Why This Matters

Old Assumption 
Current Reality 
BlackBerry Response 
Encrypted consumer messaging apps are an acceptable channel for informal but sensitive government discussion. 
An EU cyber body has now formally listed account takeover of senior officials as a top threat this year, with a sitting national parliament president among the confirmed breaches. 
BlackBerry® SecuSUITE® gives officials a sanctioned channel for the exact informal, fast coordination that currently defaults to WhatsApp and Signal, with enrollment the organization controls rather than a public device-linking flow. 
Replacing a compromised device ends the compromise. 
Reported cases show account-level access persisting after a target switched phones,  because the authorization sits with the account and follows the user onto the new device. 
BlackBerry® UEM ties device compliance to an administered account relationship, so a device swap is paired with an actual audit of what's authorized to represent that account, not a hardware refresh alone. 
Telling officials to stop using a compromised app is sufficient guidance on its own. 
The EU's own presentation flags the absence of a standardized secure system as a structural problem, meaning “stop using it” has no destination and often gets ignored. 
BlackBerry SecuSUITE gives an institution a governed channel to move the workflow into, so the directive has a destination. 
IMMEDIATE 
Audit linked devices on any WhatsApp or Signal account used by senior personnel for official business. Treat an unrecognized linked device as an active compromise, regardless of how the account was previously secured. 
IMMEDIATE 
Do not treat a device replacement as remediation on its own. Confirm the account's authorized device list is clean before considering an incident closed. 
SHORT-TERM 
Identify which informal, time-sensitive workflows currently run on consumer messaging apps and evaluate a sanctioned replacement before issuing a “stop using this app” directive with nowhere for that workflow to go. 
SHORT-TERM 
Treat unsolicited “support” messages inside Signal or WhatsApp, including any request for a linking code, as compromise attempts by default. 
ONGOING 
Track whether the organization has a standardized secure communications system at all, rather than relying on ad hoc guidance issued after each new warning. 

BlackBerry Secure Communications Position

The formal EU attribution puts this threat on the record, but it doesn’t explain why officials were on WhatsApp and Signal in the first place: nothing sanctioned was fast enough to compete with a customer app they already had on their phone. Telling officials to stop, without offering a viable alternative guarantees the same conversation will happen on similar, unmanaged channels, in the future.  

Citations:

  1. State-backed hackers targeted EU officials on WhatsApp, document shows (Politico, internal EU cyber presentation findings, as reported by TheNextWeb, August 25, 2026). 

  2. Russian Hackers Phish EU Officials Over Messaging Apps (Dark Reading, coverage of national agency warnings on Signal and WhatsApp campaigns, August 27, 2026). 

  3. State-Backed Hackers Target High-Ranking EU Officials Through WhatsApp and Signal  (The420.in, coverage of the EU Interinstitutional Cybersecurity Board presentation, August 26, 2026). 

  4. State actors tried to hack EU officials' messaging apps, cybersecurity body warns (Euronews, European Commission confidential presentation coverage, August 26, 2026). 

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now