EU officials were targeted on WhatsApp, an internal document shows

EU Officials Targeted on WhatsApp: Internal Document Reveals

An internal EU cyber presentation obtained by Politico reveals that senior officials within the bloc have been targeted through messaging apps, specifically WhatsApp. This is a significant development as it marks the first time an EU authority has formally attributed such attacks to a foreign government.

"Account takeover targeting high-ranking officials" is listed among the top threats facing the EU this year in the presentation. The document details state-sponsored spearphishing campaigns, where attackers use personalized messages to trick officials into clicking links or opening attachments.

Key Points:

  • Targeted Attacks: Foreign governments have attempted to gain access to messaging accounts of senior EU officials.
  • Top Threat: The EU's cyber defence unit informed national governments in July about these targeted attacks.
  • Number of Incidents: Eight significant incidents have been reported within EU institutions in 2026 so far.
  • Impact on Infrastructure: Critical infrastructure across Europe has also been hit, with a British power plant being shut down for four days in July due to a cyberattack linked to Iran.
  • Security Challenges: Different EU institutions lack a unified way to exchange classified documents, making it harder to address these security issues.
  • Previous Concerns: Brussels has been concerned about such threats for months, with the European Commission advising senior officials to shut down Signal groups over hacking fears.
  • Attack Method: Attackers use a fake support chatbot in Signal to trick targets into handing over a code, allowing them to access and read messages.
  • Growing State Hacking: A separate report reveals that Chinese state-affiliated groups have doubled their number of cyberattacks.

Politico's obtainment of this internal document sheds light on the evolving landscape of cyber threats targeting European institutions.