Russian-backed hackers have launched a global cyber campaign targeting Signal and WhatsApp accounts belonging to government officials, military personnel, and journalists.
The Netherlands’ intelligence agencies, AIVD and MIVD, warned on March 9, 2026, that hackers have likely already gained access to sensitive information from Dutch government employees.
Methods of Compromise
The campaign does not exploit technical flaws in the apps’ encryption. Instead, it relies on social engineering to bypass security:
- Fake Chatbots: Attackers pose as a “Signal Support” chatbot to trick users into sharing their verification codes or PINs.
- Abuse of “Linked Devices”: Hackers use phishing to trick victims into scanning QR codes, allowing the attackers to link their own device to the victim’s account and mirror messages in real-time.
Key Warnings & Indicators
- Official Guidance: Despite end-to-end encryption, intelligence officials warn that these commercial apps should not be used for transmitting classified or highly sensitive information.
- Signs of Compromise: Users should be wary if their own number appears twice in their contact list or shows up as a “deleted account”.
- Security Steps: To protect accounts, experts recommend enabling a Registration Lock on Signal and Two-Step Verification on WhatsApp, and regularly checking “Linked Devices” in app settings.