Foreign governments are behind attempts to compromise the messaging accounts of senior European Union officials, according to an internal presentation by the EU’s cyber-defense unit obtained by Politico.
The document, presented to officials from EU member states in July, ranks the “takeover of accounts targeting senior officials” among the most significant cybersecurity threats facing the EU in 2026. According to Politico, it represents the first official acknowledgment by a European authority that EU officials have been targeted through cyberattacks on messaging applications, and the first time such attacks have officially been linked to a foreign state.
The attacks are described in the presentation as “state-sponsored spearphishing” — targeted phishing operations backed by state actors and specifically designed to target particular individuals. Hackers use social-engineering techniques, crafting personalized messages to increase the chances that a recipient will click on a malicious link or open an infected file.
Warnings over Signal and WhatsApp
Earlier this year, Politico reported that the European Commission had asked some of its most senior officials to leave a Signal group because of concerns about potential attacks.
Around the same time, national cybersecurity authorities began warning governments and public officials to limit their use of commercial applications such as WhatsApp and Signal for official communications.
In March, at least five national cybersecurity and intelligence agencies issued public warnings about active campaigns targeting accounts on the two applications.
Dutch intelligence agencies specifically attributed some of the operations to Russia, while German authorities warned that hackers were targeting “senior figures in politics, the military and diplomacy, as well as researchers and journalists.”
The fake Signal chatbot trick
One of the methods used was particularly simple but effective. According to authorities’ warnings, attackers posed as a supposed Signal technical-support chatbot and attempted to persuade victims to share their security codes.
This could allow the attackers to take control of an account and read incoming messages as well as conversations in group chats. The technique does not necessarily require breaking the application’s encryption itself. Instead, it relies on tricking the user into handing over the information that allows the attacker to gain access.
Eight “significant incidents” in the EU this year
The same presentation states that EU institutions have dealt with eight “significant cybersecurity incidents” so far this year.
One problem identified is the fragmentation of security systems across European institutions.
Different EU bodies continue to use different cybersecurity solutions, while there is still no unified system for securely exchanging sensitive or classified documents.
The lack of common infrastructure creates additional challenges at a time when attacks are becoming increasingly targeted, focusing not only on networks and information systems but also on the individuals holding critical positions.
The European Commission declined to provide details about its internal security practices when responding to Politico’s questions about the presentation. Signal and WhatsApp had not immediately responded to requests for comment.
Ask me anything
Explore related questions