Full Breakdown
German Officials Targeted in State-Sponsored Signal Phishing Campaign
4/26/2026, 6:37:05 AM
Phishing Campaign Compromises High-Profile Signal Accounts
German authorities confirmed a phishing operation that compromised the Signal account of Bundestag President Julia Klöckner, accessed the accounts of ministers Karin Prien and Verena Hubertz, and targeted Chancellor-candidate Friedrich Merz, other CDU members, deputies, civil servants, diplomats, journalists and NATO officials.
Context: Cyber Threats Since Russia’s Invasion of Ukraine
Since Russia’s invasion of Ukraine in February 2022, German security services have reported a rise in cyber espionage, including attacks on critical infrastructure. Early 2024, BfV and BSI warned of targeted attacks on encrypted messaging apps, especially Signal.
Victims and Methodology
Around 300 Signal accounts were compromised, covering deputies from most factions, two ministers, civil servants, diplomats, journalists and NATO officers. Attackers sent messages posing as Signal support, requesting verification codes or QR-code scans, enabling hijack, chat reading, file retrieval and impersonation without malware.
Investigation Timeline
The Federal Prosecutor’s Office opened an espionage case in February 2024. In April, BfV said the campaign remained active. Late April, Der Spiegel reported Kloeckner’s breach and 300 affected accounts. In early May, an interior- ministry spokeswoman called the intrusion “probably led by a state actor.”
Official Responses
Prosecutors have not named suspects. BfV and BSI reiterated warnings about a state actor, and the interior ministry confirmed a foreign origin. Officials stressed that chancellor and minister communications remain on secure channels and that compromised devices are being secured.
Parliamentary Criticism
MP Konstantin von Notz, deputy chief of the intelligence-oversight committee, called the scale “extremely worrying” and warned unreported cases would keep rising, questioning communication integrity. Andrea Lindholz opposed a full Signal ban but suggested limiting its desktop client. SPD and Die Linke confirmed victims among their members.
Attribution Dispute
Germany has not named Russia. Der Spiegel and the Dutch AIVD attribute the campaign to Russian state hackers, a view cited by FBI Director Kash Patel. Russian authorities deny involvement, labeling the claims anti-Russian propaganda. The precise number of compromised accounts beyond the 300 estimate remains unclear.
Verbatim Quotes
"Recent findings indicate that the campaign is still active and gaining momentum." — Federal Office for the Protection of the Constitution (BfV)
"Russian state hackers are engaged in a large-scale global cyber campaign to gain access to Signal and WhatsApp accounts belonging to dignitaries, military personnel, and civil servants." — Netherlands' General Intelligence and Security Service (AIVD)
"This attack presumably originated in Russia." — Berlin officials cited by Der Spiegel
"The number of unreported cases will continue to rise in the coming days." — Konstantin von Notz, MP, deputy chief of the intelligence-oversight committee
"It can be assumed that numerous Signal groups within the parliamentary environment are currently being read by the attackers almost imperceptibly." — security warning issued by German authorities
Implications and Next Steps
The incident highlights the vulnerability of encrypted messaging for high-level officials and may prompt stricter usage policies, including possible limits on Signal’s desktop client and mandatory cybersecurity training. Ongoing investigations aim to identify the perpetrators, assess data loss and coordinate with allied nations that have reported similar campaigns.
