In August 2026, CERT-EU disclosed that EU bloc governments had faced eight significant spearphishing incidents over WhatsApp and Signal since the beginning of the year. More than 190 threat actors were reported targeting the EU ecosystem over the preceding twelve months. Account takeover of high-ranking officials was identified as one of the greatest threats to EU governments in 2026. This is not a forecast. It is a status report on an active, ongoing campaign.

The attacks follow a pattern that has been documented independently by German, Dutch, and Portuguese intelligence agencies, by Google's Threat Analysis Group, and by ANSSI in France. The targets are senior government officials, diplomats, military personnel, journalists, and members of European Commissioners' cabinets. The attackers are state-linked actors. Germany and the Netherlands have publicly attributed the campaigns to Russia. The method is consistent across every target country. And it does not require a single line of malicious code.

How the Attacks Work

The campaigns employ two primary techniques, both of which exploit the architecture of consumer messaging apps rather than any flaw in their encryption.

The first is verification code theft. A message arrives from a profile impersonating Signal's official support team or a similar authority. It warns the target that their account is at risk and asks them to provide their verification code and PIN. Once provided, the attacker registers the victim's account on a new device, taking full control. The victim loses access. The attacker gains the complete message history, every contact, every group membership.

The second is linked device exploitation. The target is persuaded to click a link or scan a QR code — often embedded in what appears to be a legitimate invitation, a policy document, or a meeting link referencing EU sanctions or official statements. The action silently adds an attacker-controlled device to the victim's account using Signal's or WhatsApp's "linked devices" feature. The victim retains access. They see no indication that anything has changed. The attacker reads every subsequent message in real time, silently, indefinitely.

"The linked devices attack is the more dangerous of the two because it is invisible. The victim continues using their account normally. Every message they send and receive is mirrored to the attacker's device. There is no alert, no notification, no sign of compromise."

Neither technique involves breaking encryption. Neither exploits a software vulnerability. Neither delivers malware that endpoint protection could detect. The attacks succeed because consumer messaging apps authenticate individuals, not institutions — and because a single compromised individual exposes every conversation they are part of.

The Campaign Timeline

The current wave is not a single incident. It is a sustained, multi-country campaign that has accelerated throughout 2026.

In February, Germany's Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) published a joint security notice warning that a "likely state-controlled" threat actor was systematically targeting Signal accounts of politicians, military personnel, diplomats, and journalists. The warning was specific: the attackers were impersonating known contacts and official support channels.

In March, the Dutch General Intelligence and Security Service (AIVD) issued a parallel warning covering both Signal and WhatsApp, confirming that the campaign targeted dignitaries, military personnel, and civil servants across multiple European countries. The Netherlands publicly identified Russia as the perpetrator. Germany subsequently confirmed the same attribution.

By April, the European Commission itself had ordered senior officials to shut down Signal group chats they had been using for institutional coordination, after members of Commissioners' cabinets were directly targeted by phishing messages impersonating Signal support staff. The EU's own cybersecurity review concluded that consumer messaging had become a single point of failure for institutional communications.

By August, CERT-EU's count had reached eight significant incidents in the first half of the year alone — a rate that represents a fundamental and sustained targeting of European government communications through the consumer platforms those governments chose to rely on.

Why Consumer Apps Cannot Defend Against This

The structural problem is not that Signal and WhatsApp have weak security. The structural problem is that their security model was designed for a different threat.

Consumer messaging apps authenticate users by phone number. There is no institutional identity layer. There is no way for an organization to verify that the person in a group chat is who they claim to be beyond trusting a phone number that may have been hijacked. There is no administrative visibility into which devices are linked to which accounts. There is no ability for an institution to detect that one of its members' accounts has been compromised, to revoke a linked device remotely, or to enforce a session policy across its users.

When an attacker links a device to a senior official's Signal account, the institution that official belongs to has no mechanism to detect it, no mechanism to prevent it, and no mechanism to respond to it. The official themselves may not know. The app was not designed to give institutions that visibility because the app was not designed for institutional use.

This is not a failure of encryption. It is a failure of architecture. The encryption protects message content between devices. The architecture provides no protection against an unauthorized device being silently added to the conversation.

"One hundred and ninety threat actors targeting the EU ecosystem. Eight significant messaging compromises in six months. Zero software vulnerabilities exploited. The attack surface is not the software. The attack surface is the decision to use consumer tools for institutional communications."

The Institutional Gap

The EU's response — shutting down Signal group chats, issuing warnings, publishing advisories — addresses awareness. It does not address the structural vulnerability. The officials who were using Signal and WhatsApp for institutional coordination still need to communicate in real time, on mobile devices, across borders and time zones. If they cannot use Signal, they will use something else. If the something else is another consumer app, the same attack surface applies.

The campaigns documented across Germany, the Netherlands, France, and the European Commission in 2026 are targeting a gap that no consumer application can close: the absence of institutional communications infrastructure that provides the convenience of consumer messaging with the identity verification, session management, access controls, and administrative visibility that institutional use demands.

An institutional communications platform would verify identity at the organizational level, not the phone number level. It would give administrators visibility into linked devices and the ability to revoke them. It would enforce session policies that prevent a socially engineered QR code from granting indefinite silent access. It would provide audit capabilities so that a compromise could be detected and scoped, rather than discovered months later — or never discovered at all.

The spearphishing campaigns targeting European governments are not sophisticated. They do not need to be. They are effective because the infrastructure they target — consumer messaging apps adopted for institutional use — was never built to resist them. The attackers are not outpacing the technology. They are exploiting the decision to use the wrong technology for the purpose.

What Eight Incidents in Six Months Means

Eight significant incidents is not a number that describes isolated targeting. It describes systematic, sustained operational activity against European institutional communications. It describes a threat actor — or multiple threat actors — who have identified consumer messaging as the most productive attack surface against Western government officials and are investing resources in exploiting it at scale.

The trajectory is not ambiguous. The campaigns are accelerating. The techniques are being refined and shared across threat groups. The target set is expanding from senior officials to their staffs, their advisors, and their institutional contacts. Every compromised account provides the attacker not only with that individual's communications but with the identity and contact information of everyone they communicate with — fuel for the next round of targeting.

Eight incidents in six months is not a trend to monitor. It is a pattern that has already matured. The question for every allied government is whether to continue defending consumer messaging apps against threats they were never designed to withstand, or to replace them with infrastructure that was built for the threat environment that now exists.

If your organization relies on consumer messaging for sensitive communications and recognizes that the threat has outpaced the tool, we should talk.

Get in Touch