Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringgovernment-diplomatic-threatstate-sponsored-espionageidentity-impersonation-fraud

Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts

Updated 21d agoFirst seen Mar 9, 202646 sources

The Dutch intelligence and military security services (AIVD and MIVD) warned of a large-scale Russian cyber campaign targeting individual Signal and WhatsApp accounts—particularly those of government officials, journalists, and military personnel—by persuading victims to disclose security verification codes and PINs. The activity does not involve breaking end-to-end encryption or exploiting a technical vulnerability in the apps; instead, it abuses legitimate account and security workflows. One commonly observed tactic is impersonation of a Signal Support chatbot to solicit verification information, enabling account takeover and access to messages and group chats.

The agencies also reported abuse of the apps’ “linked devices” functionality, where attackers attempt to attach an additional device to a victim’s account to mirror messages in real time. AIVD/MIVD assessed that the campaign has already produced victims, including within the Dutch government, and that attackers likely accessed sensitive information as a result. Separate reporting about a fake Red Alert Android app used to spy on Israeli users describes a different mobile-malware operation (SMS lure, sideloaded trojanized app, extensive permissions, and data exfiltration) and is not part of the Signal/WhatsApp account-takeover campaign.

Share:
Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

19 events from the most recent confirmed update back to the earliest known activity.

19 EVENTS
May 30, 202624d ago

Phishing campaign targets Signal backup recovery keys

A targeted phishing campaign impersonating Signal Support was reported as trying to trick users into sharing 64-character backup recovery keys. If attackers also gain account access, they can decrypt victims’ entire encrypted Signal backup archives, exposing historical conversations; observed targets included journalists, activists, and Chinese dissidents.

Signal Phishing Campaign Targets Journalists and Activists to Steal Backup Recovery Keys
May 14, 20261mo ago

Amnesty researcher exposes 13,500-target Signal hijack operation

Amnesty International Security Lab head Donncha Ó Cearbhaill investigated a phishing attempt against his own Signal account and said he uncovered a broader campaign targeting more than 13,500 users. He described attackers impersonating Signal support to steal verification codes for linked-device hijacking and revealed new technical details including an automation system dubbed 'ApocalypseZ,' Russian-language tooling, and translated victim chats.

A spyware investigator exposed Russian government hackers trying to hijack Signal accounts | TechCrunch
May 12, 20261mo ago

Signal rolls out in-app anti-phishing warnings and verification prompts

Signal introduced new in-app confirmations, warning labels, and educational prompts to help users detect social-engineering and phishing attempts. The safeguards include indicators such as 'Name not verified' and 'No groups in common,' stronger prompts on message requests, and reminders that Signal will never ask for a registration code, PIN, or recovery key.

Signal adds security warnings for social engineering, phishing attacks
Apr 29, 20262mo ago

German government members reportedly compromised in Signal phishing campaign

Reporting said a likely Russia-linked phishing campaign abusing Signal’s linked-device QR code feature compromised members of the German government, including Bundestag President Julia Klöckner. German authorities assessed Russia was probably behind the operation, while Chancellor Friedrich Merz’s phone was examined and found not compromised.

Germany Caught Up in Likely Russian Signal Phishing
Apr 22, 20262mo ago

BfV warns Bundestag of Signal phishing campaign affecting hundreds in Germany

Germany’s domestic intelligence agency, the BfV, reportedly warned parliamentary party leaders and Bundestag party offices about an ongoing Signal phishing campaign. Security circles said at least 300 victims were known in Germany, including high-profile figures, and the warning assessed that numerous parliamentary Signal groups might already be monitored by attackers without detection.

Julia Klöckner ist Opfer des Signal-Hacks - DER SPIEGEL
Apr 11, 20262mo ago

Impersonator uses ProPublica reporter identity on Signal and WhatsApp

A ProPublica reporter disclosed that an unknown actor used his name and headshot on WhatsApp and Signal to contact people tied to foreign military and Ukraine-related matters. Reported targets included a Canadian military official and a Latvian businessman supporting the Ukrainian military, and one approach appeared to include fake secure video-call instructions aimed at compromising an email account.

Who’s Been Impersonating This ProPublica Reporter? - ProPublica
Mar 20, 20263mo ago

FBI warns Russian intelligence-linked actors hijacked thousands of messaging accounts

The FBI issued a public service announcement warning that Russian intelligence-linked threat actors are phishing users of Signal and WhatsApp, especially people with access to sensitive information. The bureau said the campaign has already compromised thousands of accounts worldwide through stolen verification codes and malicious QR codes rather than by breaking app encryption.

FBI links Signal phishing attacks to Russian intelligence services

CISA publishes U.S. advisory on Russian targeting of messaging accounts

CISA published guidance on Russian intelligence services targeting commercial messaging application accounts, reflecting broader official concern about the same account-takeover tradecraft. The advisory extended awareness of the threat beyond the Dutch warning.

France’s C4 warns of messaging account targeting in government sectors

France’s Centre de Coordination des Crises Cyber (C4) issued an alert about rising social-engineering attacks against instant-messaging accounts used by political figures, senior officials, and government administrators, especially in sovereign sectors. The alert described abuse of linked-device and account-transfer features across Signal, WhatsApp, and other platforms, warned of risks including exposure of sensitive chats and impersonation, and advised public administrations to favor Tchap for professional exchanges.

Cert Ssi
Mar 9, 20264mo ago

Signal says it is adding safeguards and UI warnings

Signal said it was working on additional safeguards and user-interface improvements to better protect high-risk users from phishing and fraudulent device-linking attempts. It also reiterated that legitimate support would not request verification credentials through messages, SMS, or social media.

Signal confirms targeted phishing caused account takeovers

Signal publicly acknowledged an ongoing wave of targeted phishing and social-engineering attacks that successfully took over some user accounts, including those of journalists and government officials. The company said its infrastructure and end-to-end encryption were not compromised and that attackers were tricking users into sharing SMS verification codes and Signal PINs.

Dutch authorities warn sensitive communications should avoid consumer chat apps

Alongside the advisory, Dutch officials stated that end-to-end encrypted consumer messaging apps are not suitable for classified, confidential, or otherwise sensitive government information. They emphasized that encryption does not protect against account takeover through social engineering.

AIVD and MIVD publish advisory on Signal and WhatsApp phishing

Dutch intelligence and military security agencies issued a public cybersecurity advisory warning about phishing via Signal and WhatsApp. The advisory described tactics such as fake Signal support messages, credential theft, malicious QR codes, and abuse of linked devices, and provided guidance to help users detect and respond to account compromise.

Dutch agencies confirm Dutch government employees were affected

The Netherlands’ AIVD and MIVD said the campaign had already led to compromises, including accounts belonging to Dutch government employees, and assessed that sensitive information was likely exposed. They also warned the activity was not limited to the Netherlands.

Russian-linked campaign compromises Signal and WhatsApp accounts

A large-scale Russia-linked operation targeted Signal and WhatsApp accounts of government officials, military personnel, journalists, diplomats, researchers, and other high-value individuals worldwide. The campaign used social engineering to steal verification codes and PINs and abused linked-device features rather than exploiting vulnerabilities in the apps themselves.

Mar 1, 20264mo ago

Poland launches mSzyfr and directs officials to stop using Signal

Poland said public officials and entities in its National Cybersecurity System should stop using Signal and adopt the state-backed mSzyfr Messenger, citing phishing and social-engineering campaigns against Signal users. The platform was launched through the Ministry of Digital Affairs and NASK as a government-jurisdiction alternative for approved public-sector and cybersecurity organizations.

Poland builds its own Signal amid security concerns
Feb 15, 20264mo ago

German federal prosecutors open preliminary Signal espionage probe

German federal prosecutors opened a preliminary investigation in mid-February 2026 into alleged cyberattacks on Signal accounts, including possible espionage tied to the phishing campaign targeting politicians and others. The probe preceded later public reporting about hundreds of compromised accounts and suspected Russian involvement.

German government suspects Russia in Signal phishing attacks on politicians | AP News
Feb 6, 20265mo ago

BfV and BSI issue joint warning on messenger phishing campaign

Germany’s BfV and BSI issued a joint security advisory warning of phishing attacks via messenger services including Signal. The agencies said a likely state-controlled actor was targeting senior figures in politics, the military, diplomacy, and investigative journalism in Germany and across Europe, with risks extending to confidential chats and wider contact networks.

Bundesamt für Verfassungsschutz - Publikationen - Gemeinsamer Sicherheitshinweis von BSI und BfV zum Phishing über Messengerdienste
Feb 1, 20251y ago

Google documents Russian abuse of Signal linked-device feature

Google Threat Intelligence Group reported that Russia-linked actors were using malicious QR codes to link victims’ Signal accounts to attacker-controlled devices for real-time eavesdropping, particularly in activity tied to the war in Ukraine. Later reporting cited this as an earlier precursor to the broader campaign described by Dutch authorities.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

68 LINKEDOpen in app
Affected products
14 linked
SignalWhatsappMicrosoft OfficeTelegramWindowsCloudflareNetWordpressAsus RoutersFacebookInstagramLinkedinGmailMicrosoft Authenticator
Organizations
34 linked
Signal MessengerSecurity AffairsMeta PlatformsGoogleMicrosoft CorporationXSalesforceCisco SystemsRapid7LinkedinTechCrunchASUSDer SpiegelLumen TechnologiesThreemaTelegramKeybaseBettermentElectronic Frontier FoundationBleepingComputerMalwarebytesCloudflareWireTikTokInformation Security Media GroupGoDaddyReutersAmnesty InternationalAEZA GroupPoliticoProPublicaGen Digital Inc.The New York Times CompanyCorrectiv
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts | Mallory