Published on
State actors have been attempting to hack into EU officials’ Signal and WhatsApp accounts, according to a confidential European Commission presentation obtained by Euronews.
ADVERTISEMENT
ADVERTISEMENT
The presentation, prepared by the Interinstitutional Cybersecurity Board – a body set up in January 2024 to ensure EU institutions comply with the bloc’s cybersecurity rules – provides an updated overview of the threat landscape facing Brussels over the past year.
In an unprecedented admission, first reported by Politico, the EU body acknowledged for the first time that state-sponsored actors have engaged in “spearphishing”, a highly targeted cyberattack method in which hackers send personalised messages to specific individuals or organisations to steal data or install malware.
According to the EU cyber experts, these attempts have taken two main forms: trying to take over the Signal and WhatsApp accounts of senior officials, and using “social engineering” techniques that reference EU-related topics such as sanctions or official statements.
In February, Germany’s security agencies warned of an ongoing phishing campaign likely linked to state-controlled actors and targeting Signal, aimed at politicians, military personnel, diplomats and journalists.
More than 190 threat actors were reported targeting the EU ecosystem over the past 12 months, with eight significant incidents registered in the first half of 2026.
A Euronews journalist also received a suspicious message in October 2025 from an account posing as Signal Support, requesting a verification code and citing “suspicious activity on your device, which could have led to data leak”.
The presentation also points to a cloud data breach in late March 2026, after hackers compromised Amazon Web Services accounts hosting parts of the Europa.eu website, as well as a broader tendency to exploit vulnerabilities in widely used productivity software such as Microsoft applications, and in hardware components.
The experts noted “strong convergence from all represented Institutions on the need to protect sensitive information,” adding that “the majority of the institutions use internal tools to encrypt and safely process sensitive information internally.”
Still, challenges include differing digital signatures and certificates used across EU bodies, the absence of a common platform for collaborating on sensitive documents, and inconsistencies in how documents are classified.
