EU Officials Targeted by State-Sponsored Hacking Campaigns via Signal and WhatsApp
A confidential European Commission presentation, obtained by Euronews, reveals that state-backed threat actors have been actively attempting to compromise the Signal and WhatsApp accounts of EU officials. The document, prepared by the Interinstitutional Cybersecurity Board established in January 2024 to enforce EU cybersecurity compliance marks the first public acknowledgment by an EU body of such targeted attacks.
The attacks primarily employ spearphishing, a method where hackers send personalized messages to high-profile individuals to steal data or deploy malware. Two key tactics have been identified: account takeovers of messaging apps and social engineering schemes referencing EU-related topics, such as sanctions or official statements.
In February 2026, Germany’s security agencies issued warnings about an ongoing phishing campaign linked to state actors, specifically targeting Signal users among politicians, military personnel, diplomats, and journalists. The EU presentation also highlighted that over 190 threat actors have targeted the EU ecosystem in the past year, with eight significant incidents recorded in the first half of 2026 alone.
A Euronews journalist reported receiving a suspicious message in October 2025 from an account impersonating Signal Support, requesting a verification code under the pretext of a "data leak." Beyond messaging apps, the presentation details a cloud data breach in late March 2026, where hackers compromised Amazon Web Services accounts hosting parts of the Europa.eu website. Additional vulnerabilities have been exploited in Microsoft productivity software and hardware components.
While EU institutions have strengthened internal protections including encrypted tools for handling sensitive information challenges persist. These include inconsistent digital signatures and certificates across EU bodies, the lack of a unified platform for secure document collaboration, and discrepancies in how documents are classified. The report underscores a unified recognition among EU institutions of the urgent need to safeguard sensitive data.
European External Action Service cybersecurity rating report: https://www.rankiteo.com/company/european-external-action-service
"id": "EUR1787747248",
"linkid": "european-external-action-service",
"type": "Cyber Attack",
"date": "1/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'EU officials, diplomats, '
'politicians, journalists',
'industry': 'public sector',
'location': 'European Union',
'name': 'European Commission',
'size': 'large',
'type': 'government'},
{'industry': 'public sector',
'location': 'European Union',
'name': 'Europa.eu',
'type': 'website'}],
'attack_vector': ['messaging apps (Signal, WhatsApp)',
'cloud services (AWS)',
'Microsoft productivity software',
'hardware components'],
'data_breach': {'personally_identifiable_information': 'potentially (targeted '
'individuals)',
'sensitivity_of_data': 'high',
'type_of_data_compromised': ['sensitive EU-related documents',
'official statements',
'sanctions-related data']},
'date_detected': '2026-02-01',
'date_publicly_disclosed': '2026-06-01',
'description': 'State-backed threat actors have been actively attempting to '
'compromise the Signal and WhatsApp accounts of EU officials '
'through spearphishing, account takeovers, and social '
'engineering schemes. The attacks reference EU-related topics '
'such as sanctions or official statements. A cloud data breach '
'in late March 2026 also compromised Amazon Web Services '
'accounts hosting parts of the Europa.eu website.',
'impact': {'brand_reputation_impact': "damage to EU institutions' credibility "
'and trust',
'data_compromised': 'sensitive EU-related data, including '
'sanctions and official statements',
'identity_theft_risk': 'high risk for targeted individuals',
'operational_impact': 'compromised secure communication channels '
'for EU officials',
'systems_affected': ['Signal',
'WhatsApp',
'Amazon Web Services (Europa.eu)',
'Microsoft productivity software']},
'initial_access_broker': {'high_value_targets': ['EU officials',
'politicians',
'military personnel',
'diplomats',
'journalists']},
'investigation_status': 'ongoing',
'lessons_learned': 'Urgent need for unified cybersecurity measures across EU '
'institutions, including consistent digital signatures, a '
'unified secure document collaboration platform, and '
'standardized document classification.',
'motivation': ['data theft', 'espionage'],
'post_incident_analysis': {'corrective_actions': ['strengthen internal '
'protections',
'implement encrypted tools '
'for sensitive data',
'address inconsistencies in '
'digital signatures and '
'document classification'],
'root_causes': ['state-sponsored cyber espionage',
'inconsistent cybersecurity '
'practices across EU institutions',
'lack of unified secure '
'platforms']},
'recommendations': ['Implement unified cybersecurity standards',
'Enhance secure communication tools',
'Improve digital signature and certificate consistency',
'Establish a unified platform for secure document '
'collaboration'],
'references': [{'source': 'Euronews'},
{'source': 'European Commission Presentation '
'(Interinstitutional Cybersecurity Board)'},
{'source': 'Germany’s security agencies'}],
'response': {'remediation_measures': ['strengthened internal protections',
'encrypted tools for handling sensitive '
'information']},
'threat_actor': 'state-backed threat actors',
'title': 'EU Officials Targeted by State-Sponsored Hacking Campaigns via '
'Signal and WhatsApp',
'type': ['spearphishing',
'account takeover',
'social engineering',
'cloud data breach'],
'vulnerability_exploited': ['inconsistent digital signatures and certificates',
'lack of unified secure document collaboration '
'platform',
'discrepancies in document classification']}