Foreign Governments Tried to Hack EU Officials’ WhatsApp Accounts
An internal EU cyber presentation says foreign governments have used targeted spearphishing and social engineering in attempts to take over messaging accounts belonging to high-ranking officials.
Foreign governments have attempted to take control of WhatsApp and other messaging accounts belonging to senior European Union officials, according to an internal presentation by the bloc’s cyber defense unit.
The July briefing to officials from EU national governments identified “account takeover targeting high-ranking officials” as one of the EU’s leading cyber threats this year, according to Politico.
The document marks an official EU acknowledgment that senior officials have been targeted through messaging applications and formally attributes such activity to foreign governments.
State-Sponsored Spearphishing
EU cybersecurity officials described the attacks as “state-sponsored spearphishing”, involving tailored attempts to induce specific targets to open malicious attachments or follow suspicious links.
Attackers also relied on “social engineering techniques”, according to the presentation, using personalized approaches designed to increase the chances that officials would respond.
The focus on individual accounts underscores the threat posed by attempts to compromise communications used by senior political, military and diplomatic figures.
Messaging Platforms Under Pressure
Concerns over commercial messaging services had already prompted action inside the European Commission earlier this year.
Some of the Commission’s most senior officials were told to shut down a Signal group because of hacking concerns.
National cyber authorities also warned governments to reduce their reliance on commercial platforms such as WhatsApp and Signal for official communications.
At least five national cyber and intelligence agencies warned in March of active campaigns targeting users of the two services.
Dutch intelligence services attributed the activity to Russia, while Germany said hackers were targeting “high-ranking individuals in politics, the military, and diplomacy, as well as investigative journalists.”
Account Takeover Tactics
One technique involved attackers impersonating a Signal support chatbot.
Targets were persuaded to hand over verification codes, allowing attackers to seize control of accounts and access incoming communications and group chats.
The EU presentation placed such account takeover attempts among the most significant cyber threats confronting the bloc.
Eight Significant Incidents
EU institutions had recorded eight “significant incidents” so far this year, according to the presentation.
Cybersecurity officials also highlighted structural weaknesses across the bloc’s institutions.
Different EU bodies continue to operate separate technical cybersecurity systems, while no common solution exists for exchanging sensitive and classified documents.


