Attacks on EU Officials’ Messaging Accounts Raise Questions About Official Communication in Personal Apps
Verified Context
Politico reported that, according to an internal presentation by an EU cyber defense unit, foreign governments have attempted to compromise messaging accounts of high-ranking European Union officials.
The topic follows already published warnings from national security services, including in the Netherlands, about campaigns targeting Signal and WhatsApp accounts of government officials, military personnel, diplomats and journalists.
A clear distinction is important: the public information does not show that WhatsApp or Signal encryption has been broken. The risk is account takeover, device pairing, verification codes and social engineering. If an attacker takes control of an account or links a new device to it, they may be able to view communications as the legitimate user.
How the Attack Works
Warnings from the Dutch AIVD and MIVD describe a tactic in which attackers impersonate Signal technical support. The victim receives a message that appears to warn about a security issue, data leak or suspicious activity.
The goal is to persuade the user to share a verification code or perform an action that allows attackers to take over the account or link a new device.
This is a classic attack against identity, not cryptography. The application may use strong encryption, but if the account is taken over through a legitimate feature or the user is tricked into sharing a code, channel security does not solve the problem.
Why This Matters for Institutions and Leadership Teams
Personal messaging apps are often used because they are fast, convenient and already part of daily work. In an institutional environment, however, convenience creates governance risk.
Official communication in personal or commercial applications may include sensitive topics, political positions, operational coordination, internal decisions, contact networks and group conversations. Even without attachments or passwords, the content and context may have intelligence value.
For high-ranking individuals, the risk is not only individual. One compromised account can expose group chats, contacts, incoming messages and follow-on spear phishing opportunities against other participants.
The Operational Signal
This topic should not be read as “WhatsApp and Signal are not secure.” The more accurate takeaway is that communication security does not depend only on the chosen application.
Organizations need to manage the entire process: which channels are approved for official communication, how identity is verified in sensitive conversations, how linked devices are managed, how teams respond to suspected account takeover and how leadership teams are trained against social engineering.
Encryption protects content in transit. It does not automatically protect the user from being tricked into granting access.
What Organizations Should Check
Organizations using messaging apps for official communication should review not only technical settings, but also usage rules.
Practical checks:
- which applications are approved for official communication;
- what type of information may and may not be discussed in them;
- whether personal devices are allowed for official conversations;
- whether linked devices and active sessions are reviewed;
- whether leadership and sensitive roles are trained not to share verification codes;
- whether an alternative channel exists to verify suspicious “support” messages;
- whether there is a process to leave compromised groups and notify participants quickly;
- how official communication is archived, retained and protected according to internal and regulatory requirements.
The main question is not only “which app do we use.” It is “who controls the account, the devices and the rules for sensitive communication.”
DIAMATIX Comment
From the DIAMATIX perspective, this case shows why identity security and communication discipline need to be part of leadership protection.
Attackers do not always look for a technical vulnerability. Often, they look for the right moment, a trusted channel and an action the user performs voluntarily. This is especially relevant for people with access to strategic information, partner conversations, political decisions, financial data or operational coordination.
SOC (Security Operations Center) and MDR (Managed Detection and Response) processes should treat identity as an active attack surface. This includes unusual logins, new devices, account changes, suspicious MFA (Multi-Factor Authentication) actions and user-reported signals.
Protecting communication is not only about choosing an app. It is a combination of policies, training, technical controls, fast response and clear boundaries for what can be shared in informal channels.
Questions for CISO, IT and Leadership Teams
- Which official topics are discussed in personal or commercial messaging apps?
- Are there approved channels for sensitive communication?
- Do leadership teams review linked devices and active sessions?
- Is there a strict rule never to share verification codes?
- How is identity verified when a message claims to come from “support”?
- What happens if an executive account is taken over?
- Can participants in an affected group be notified quickly?
- Is training tailored to executive phishing and messaging-based social engineering?
The practical takeaway: an encrypted app is only one layer. If the account is taken over, the attacker no longer needs to break encryption — they enter through identity.
Check whether official communication is protected as a process, not only as an app
DIAMATIX can help assess identity risk, messaging practices, MFA settings, account visibility and response readiness for social engineering targeting leadership and sensitive roles.
Request an official communication and identity protection risk review with DIAMATIX.
Trusted · Innovative · Vigilant
Sources
- Politico. State-backed hackers targeted EU officials on WhatsApp, document shows.
- AIVD / MIVD. Russia targets Signal and WhatsApp accounts in cyber campaign.
- Reuters. Russia-backed hackers breach Signal, WhatsApp accounts of officials, journalists, Netherlands warns.
- CERT-EU. Threat Landscape Report 2025: A Year in Review.
- CERT-EU. Cyber Brief 26-08 — July 2026.
This article summarizes publicly available information as of August 2026.






