Foreign governments have been attempting to compromise the messaging accounts of high-ranking European Union officials through state-sponsored cyber campaigns, according to an internal presentation prepared by the bloc’s cyber defence unit. The document identifies account takeover attempts targeting senior officials as one of the major cyber threats facing the EU this year, with attackers using tailored messages and social engineering techniques on platforms including WhatsApp and Signal.
The presentation, delivered to officials from EU national governments in July, marks an official acknowledgment that EU officials have been targeted through messaging applications. National cyber agencies had earlier flagged an ongoing campaign linked to Russian threat groups, while Dutch intelligence services specifically attributed hacking activity to Russia.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
State-Sponsored Spearphishing Targets Senior Officials
The attacks were described as “state-sponsored spearphishing”, involving targeted campaigns designed to persuade specific individuals to click malicious links or open harmful attachments. According to the presentation, hackers used social engineering techniques and personalised messages intended to increase the likelihood that officials would respond to the bait.
Warnings about such activity had already emerged from national cyber and intelligence agencies. In March, at least five agencies publicly warned of ongoing hacking campaigns involving Signal and WhatsApp.
Dutch intelligence services linked the activity to Russia, while Germany warned that hackers were targeting high-ranking individuals working in politics, the military and diplomacy, as well as investigative journalists.
The European Commission had also told some of its most senior officials earlier this year to shut down a Signal group over hacking concerns. The warning came as national cyber authorities urged governments to move away from commercial messaging applications such as WhatsApp and Signal for official business.
Fake Support Messages Used to Hijack Accounts
One technique identified by authorities involved hackers posing as a fake Signal support chatbot. Users were persuaded to share their codes, potentially allowing attackers to take control of their accounts and gain access to incoming communications and group chats.
The attacks illustrate the risks posed by highly personalised cyber operations against government officials. Rather than relying solely on technical vulnerabilities, the campaigns use deceptive communications designed around individual targets.
The EU presentation also highlighted broader cybersecurity concerns within the bloc. EU institutions have faced eight “significant incidents” so far this year, according to cybersecurity officials cited in the document.
Officials identified another challenge in the different technical cybersecurity systems used across EU institutions. The lack of a common solution for exchanging sensitive and classified documents was also flagged.
EU Institutions Face Wider Cybersecurity Challenge
The campaign comes amid growing concern over attempts to compromise communications used by officials handling sensitive government business. Account takeover attacks could give threat actors access to communications and group conversations if successful.
The internal presentation indicates that foreign-government-linked cyber activity against senior EU officials is now being treated as a significant security concern, alongside the broader problem of protecting sensitive information across institutions using different technical systems.
The European Commission declined to provide details about its internal security practices in response to questions concerning the presentation.
WhatsApp and Signal did not immediately respond to requests for comment.