Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencestate-sponsored-espionagecredential-access-methodidentity-impersonation-fraud

German Agencies Warn of Signal Account Hijacking via Support Impersonation and Linked-Device QR Codes

Updated 3mo agoFirst seen Feb 6, 202610 sources

Germany’s Federal Office for the Protection of the Constitution (BfV) and Federal Office for Information Security (BSI) warned of suspected state-linked phishing operations targeting high-ranking individuals—politicians, military officers, diplomats, and investigative journalists—across Germany and Europe via messaging apps, notably Signal. The advisory emphasizes the campaign relies on social engineering, not malware or exploitation of technical vulnerabilities, with attackers contacting targets directly inside the app while impersonating Signal support personnel or a “security chatbot.”

Authorities described two primary tactics to gain covert access to victims’ communications and networks: (1) full account takeover by tricking targets into sharing their Signal PIN or SMS/one-time verification code, enabling attackers to register the account on an attacker-controlled device and lock out the victim; and (2) silent monitoring by persuading targets to scan a QR code that abuses Signal’s legitimate linked devices feature to pair an attacker-controlled device, allowing ongoing access to one-to-one and group chats and contact lists. The agencies noted that while the activity is assessed as likely state-backed, the same methods could be replicated by non-state or financially motivated actors.

Share:
German Agencies Warn of Signal Account Hijacking via Support Impersonation and Linked-Device QR Codes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 6, 20265mo ago

German agencies publish defensive guidance for targeted users

Alongside the warning, BfV and BSI advised users to ignore and report unsolicited support messages, never share PINs or verification codes, enable Signal's Registration Lock, and regularly review linked devices for unauthorized access. The guidance emphasized that these attacks can succeed without malware because they abuse legitimate app functionality.

Germany warns similar messaging-app abuse could affect WhatsApp

German authorities said the same social-engineering approach could be adapted to other messaging platforms with comparable account-linking and verification features, specifically naming WhatsApp. The warning expanded the significance of the campaign beyond Signal alone.

Authorities detail PIN/code theft and QR-linking attack methods

In the advisory, German authorities described two main techniques: impersonating Signal support or chatbots to steal a victim's Signal PIN or SMS verification code for account takeover, and tricking victims into scanning a QR code that links an attacker-controlled device to the account. They warned that successful access could expose chats, contact lists, and enable impersonation or broader compromise through group conversations.

BfV and BSI issue joint warning on Signal phishing campaign

On 2026-02-06, Germany's BfV and BSI issued a joint advisory warning that a likely state-backed actor was targeting senior political figures, military officials, diplomats, and investigative journalists in Germany and across Europe via Signal. The agencies said the campaign used social engineering and legitimate app features rather than malware or software vulnerabilities.

Jan 31, 20265mo ago

German interior minister cites ongoing hybrid cyberattacks

At the end of January 2026, Interior Minister Alexander Dobrindt said Germany was facing constant cyberattacks against institutions, infrastructure, and companies, and referenced hybrid attacks including those from Russia. He also said the Interior Ministry was preparing a center to coordinate defense against hybrid threats later in the year.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Affected products
5 linked
SignalWhatsappFortigateDiscordLinkedin
Organizations
13 linked
Signal MessengerMeta PlatformsBleepingComputerGoogleDiscordLinkedinOktaAvastFortinetHackReadSnapMicrosoft CorporationTines
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.