State-Sponsored Hackers Target EU Officials’ Messaging Apps

A confidential European Commission presentation reveals state actors are targeting EU officials' Signal and WhatsApp accounts through sophisticated spearphishing and social engineering. This unprecedented admission highlights pervasive cyber threats, including specific incidents and broader vulnerabilities, while also outlining challenges in EU-wide cybersecurity measures. The report underscores the urgent need for enhanced protection of sensitive information.
Pelumi Ilesanmi
Pelumi IlesanmiGlobal11 hours ago2 minute read
State-Sponsored Hackers Target EU Officials’ Messaging Apps

A confidential European Commission presentation obtained by Euronews has revealed that state-sponsored actors are targeting the Signal and WhatsApp accounts of EU officials, raising concerns over the security of sensitive communications.

The Interinstitutional Cybersecurity Board identified spearphishing and social engineering as key methods being used to target senior officials, including attempts to take control of their messaging accounts. More than 190 threat actors targeted the broader EU ecosystem over the past 12 months, with eight significant cybersecurity incidents recorded in the first half of 2026.

The presentation highlighted several incidents illustrating the scale of the threat, including a phishing campaign targeting Signal users such as politicians, diplomats, military personnel and journalists.

In another report by YahooNews, a Euronews journalist received a message impersonating Signal Support that sought a verification code, while hackers in March 2026 compromised Amazon Web Services accounts hosting parts of the Europa.eu website. Cybersecurity experts also identified the exploitation of vulnerabilities in widely used Microsoft applications and hardware components.

EU Faces Gaps in Collective Cybersecurity

Image credit: EuroNews

Despite the growing threats, EU cybersecurity experts said institutions are increasingly aligned on the need to protect sensitive information, with many using internal encryption and secure processing tools.

However, differences in digital signatures and certificates, the lack of a unified platform for sensitive documents, and inconsistent document-classification practices continue to complicate the bloc’s collective cybersecurity efforts.

The findings reveals the growing challenge facing EU institutions as state-linked cyber actors increasingly target both officials and the digital infrastructure supporting their work.

Loading...