Full Breakdown
Russian-Backed Hackers Target WhatsApp and Signal Accounts of Officials
3/13/2026, 3:15:21 AM
Overview of the Cyber Campaign
Dutch and Portuguese intelligence agencies have issued warnings regarding a global cyber campaign orchestrated by Russian-backed hackers aimed at infiltrating the WhatsApp and Signal accounts of government officials, military personnel, and journalists. The attackers employ sophisticated phishing techniques to trick users into revealing sensitive information, such as passwords and verification codes, thereby gaining unauthorized access to personal and group conversations.
Key Details of the Attacks
The Serviço de Informações de Segurança (SIS) of Portugal and the Dutch intelligence services, including the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD), confirmed that the campaign targets individuals with access to privileged information. The hackers exploit the assumption that end-to-end encryption provided by these messaging apps guarantees complete security. However, the agencies clarified that the platforms themselves have not been compromised; rather, the attacks rely on social engineering tactics that manipulate individual users.
Methods Employed by Hackers
Hackers are known to impersonate support staff, such as a fictitious "Signal Support Bot," to persuade users to share their security verification codes. This allows them to take control of accounts and monitor communications without the user's knowledge. The attackers also exploit the "linked devices" feature of the apps, which can enable them to connect another device to the victim's account. The Dutch authorities have emphasized that these phishing attacks are increasingly sophisticated, utilizing artificial intelligence to create convincing interactions.
Official Statements & Responses
In response to the ongoing threats, Signal has reiterated that its encryption and infrastructure remain secure and have not been compromised. The company has urged users to remain vigilant and avoid sharing their PINs or verification codes. WhatsApp has echoed similar advice, warning users against sharing their six-digit codes and recommending blocking unknown contacts. Vice Admiral Peter Reesink, director of the MIVD, stated, "Despite their end-to-end encryption option, messaging apps such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information."
Criticism & Opposition
Cybersecurity experts have raised concerns about the vulnerabilities inherent in using messaging apps for sensitive communications. Muhammad Yahya Patel, a cybersecurity advisor, noted that while end-to-end encryption protects message content, it does not safeguard user accounts from being compromised. He emphasized the need for users to be aware of the limitations of these security features and to adopt additional protective measures.
Conflicting Reports & Gaps
While Dutch intelligence agencies have attributed the cyber campaign to Russian-backed hackers, the SIS did not specify the state behind the attacks. This lack of clarity raises questions about the broader implications of the campaign and the potential involvement of other actors.
What's Next
As authorities continue to tighten security measures, the focus remains on increasing public awareness regarding the risks associated with using messaging apps for sensitive communications. Both Signal and WhatsApp are expected to enhance their security features and user education initiatives to combat the rising threat of phishing attacks.
