Key Takeaways

  • Russia-linked actors are targeting EU officials through trusted messaging apps rather than relying only on email.
  • Attackers use fake support alerts, stolen PINs and malicious QR codes to link their devices to officials’ accounts.
  • European governments are pursuing sovereign communication systems, but internal platforms still require strong identity, device and monitoring controls.

European officials face a widening account-takeover campaign built around a deceptively simple insight: people behave differently on messaging apps than they do in email.

Russian state-linked actors have been approaching politicians, military personnel, diplomats and civil servants through Signal and WhatsApp. Instead of exploiting a software vulnerability, they impersonate support personnel, manufacture urgent security problems and persuade targets to disclose account PINs or scan QR codes. A successful scan can link an attacker-controlled device to the victim’s account.

That distinction matters. Signal and WhatsApp may provide end-to-end encryption, but encryption does not establish whether the person requesting a PIN is genuine. Nor does it protect a user who authorizes an unfamiliar linked device. The campaigns attack trust and identity rather than the underlying cryptography.

The scale is becoming clearer. The Interinstitutional Cybersecurity Board said more than 190 threat actors targeted the EU ecosystem during the past 12 months. Eight significant incidents in H1 2026 involved state-sponsored spearphishing against officials’ messaging accounts.

Phishing remains the broader entry point. The ENISA Threat Landscape 2025 report found that it was the initial vector in nearly 60% of analyzed cyber incidents affecting EU entities between July 2024 and June 2025. Public institutions represented 38% of targets. ENISA has also reported increased cyberespionage against public administration by state-aligned groups, including campaigns supported by reusable Phishing-as-a-Service kits.

Germany offered an early warning. On Feb. 6, German authorities issued a joint security notice describing a likely state-controlled actor targeting senior figures across politics, diplomacy and the military. Authorities later attributed the fake Signal support campaign, which compromised about 300 political accounts, to Russia-linked actors. The Bundestag president was among the reported victims, while the German chancellor was not compromised.

Investigators also identified 31 websites hosted in Russia, including 29 suspected phishing domains, connected to targeting politicians, security officials and journalists. The Dutch government subsequently reported related activity across both Signal and WhatsApp.

Moving a conversation outside email also moves it beyond familiar corporate defenses. Secure email gateways, attachment scanning and centralized logging offer little visibility into a disappearing Signal message received on a personal phone. Attackers can begin with email and shift the victim to Telegram, LINE, WhatsApp or Signal once contact is established.

Banning consumer messaging apps outright risks ignoring operational realities. If officials lose a fast communication channel without receiving a usable replacement, sensitive conversations may migrate to other unsanctioned services.

France, Germany and Belgium have introduced internal messaging systems, while Luxembourg, Poland and the Netherlands are pursuing similar projects. The European Commission’s 2025 Cyber Blueprint calls for EU entities to agree by the end of 2026 on interoperable secure communications covering voice, messaging, video, collaboration and document sharing.

Internal ownership, however, is not the same as immunity. France’s Tchap, launched in 2019 and made mandatory for civil servants in 2025, was breached in 2026. Three years of sensitive communications involving 73,000 government employees were reportedly leaked to the Dark Web. Centralization can improve governance, but it can also concentrate valuable information.

A more durable response combines sanctioned communications with zero-trust practices: directory-bound identities, managed devices, restricted linking of secondary devices, rapid account revocation and separate channels for classified material. Officials also need training tailored to messaging behavior, particularly fake support requests and QR-code enrollment. Signal, WhatsApp (Meta), Threema and Microsoft 365 can each play roles at different sensitivity levels, but product choice alone will not resolve identity risk. The tougher job is building a communication environment that officials will use without creating new blind spots for attackers.