State-Backed Hackers Targeted EU Officials on WhatsApp, Internal Document Reveals

RksNews
RksNews 3 Min Read
3 Min Read

Foreign governments have targeted the messaging accounts of senior European Union officials in sophisticated cyberattacks, according to an internal presentation by the EU’s cybersecurity unit obtained by POLITICO.

The presentation, delivered to representatives of EU national governments in July, identifies “account takeover targeting high-ranking officials” as one of the bloc’s major cyber threats this year.

It marks the first known official acknowledgment by an EU institution that senior officials have been targeted through messaging applications and the first reported case in which an EU authority has formally linked such attacks to a foreign government.

The attacks involved what EU cybersecurity officials described as “state-sponsored spearphishing” — highly targeted campaigns designed to persuade specific individuals to click malicious links, open harmful attachments or disclose authentication information.

Hackers reportedly used sophisticated social-engineering techniques, tailoring messages to individual targets in an effort to make the attacks appear legitimate.

The disclosure follows warnings issued earlier this year by several European national cyber and intelligence agencies about campaigns targeting officials through applications including WhatsApp and Signal.

Dutch intelligence services previously attributed such activity to Russia, while Germany warned that high-ranking figures in politics, the military and diplomacy, as well as investigative journalists, were being targeted.

In one reported method, attackers posed as a fake Signal support chatbot and attempted to trick users into handing over verification codes. Obtaining those codes could allow attackers to take control of accounts and gain access to incoming messages and group conversations.

The European Commission had previously instructed some senior officials to shut down a Signal group amid concerns over possible hacking attempts. European governments have also been advised to reconsider the use of commercial messaging applications for official communications involving sensitive information.

EU institutions face wider cybersecurity challenges

EU cybersecurity officials said the bloc’s institutions had experienced eight “significant incidents” so far this year.

The presentation also highlighted structural weaknesses within the EU’s cybersecurity infrastructure, including the fact that different institutions use different technical security systems and do not yet have a common solution for exchanging sensitive and classified documents.

The European Commission declined to provide details about its internal security practices when asked about the presentation.

WhatsApp and Signal had not immediately responded to requests for comment.

The latest disclosure underscores growing concerns in Europe over state-backed cyber espionage targeting senior officials, particularly as governments face increasing pressure to secure communications involving sensitive diplomatic, military and political information.