Threat Intelligence

Russian State-Backed Hackers Target EU Officials Through Signal and WhatsApp

Dark Reading · 27 Aug 2026
Key Takeaway Treat messages received via WhatsApp, Signal, or similar apps with the same scepticism as email—verify unexpected links or requests before clicking or responding.

European Union governments are reassessing their use of popular messaging apps after reports that Russian state-backed hacking groups are shifting their phishing tactics away from email and toward platforms like Signal and WhatsApp. These apps, widely trusted for their encryption and used by officials for sensitive communications, are increasingly being targeted as attackers look for new ways to bypass traditional email security defences.

This shift highlights a broader trend in cyber espionage: as organisations harden their email systems with spam filters, authentication checks, and staff training, threat actors are adapting by exploiting the platforms people now trust most. Messaging apps often lack the same layers of security scrutiny as corporate email, making them an attractive new avenue for phishing and social engineering attacks.

While this particular campaign targets EU government officials, the underlying tactic is a warning for businesses of all sizes. Attackers go where the trust is highest and the defences are weakest, and many small and medium businesses now rely heavily on messaging apps for internal and client communication without applying the same caution they would to email.

phishing nation-state threats messaging apps Signal WhatsApp

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.