Monday, August 3, 2026

Apps & Consumer

Russian state hackers are targeting Signal and WhatsApp users

Dutch intelligence warns that Russian state actors are using phishing and social engineering to compromise Signal and WhatsApp accounts in a large-scale global campaign.

Russian state hackers are targeting Signal and WhatsApp users

On Monday, the General Intelligence and Security Service (AIVD) and the Defence Intelligence and Security Service (MIVD)—two Dutch intelligence agencies—published details warning of a “large-scale global” hacking campaign targeting users of Signal and WhatsApp. The agencies attributed the campaign to “Russian state actors” who are bypassing traditional malware. Instead, the hackers are relying on phishing and social engineering techniques to take over user accounts. The campaign has targeted government and military officials, as well as journalists all over the world.

The Dutch intelligence report detailed distinct methods used to compromise each messaging application:

  • Signal: Hackers are masquerading as the platform’s support team, directly messaging targets with warnings of suspicious activity or data leaks. They trick users into sharing a six-digit verification code—which the hackers request from Signal—along with the user’s PIN. The hackers then use these codes to register a new device, impersonate the target, and potentially access contacts, locking the victim out. Although the victim can re-register their number, the report warns of a false sense of security. “Because Signal stores the chat history locally on the phone, a victim can regain access to that history after re‑registering. As a result, the victim may assume that nothing is wrong. The Dutch services want to stress that this assumption could be incorrect,” the report stated.
  • WhatsApp: The campaign exploits the “Linked devices” feature, which allows users to access their accounts from secondary devices like laptops or tablets. Hackers trick targets into scanning malicious QR codes or clicking malicious links under the guise of joining a chat group, which actually links the attacker’s device to the victim’s account. This allows the hackers to potentially read past messages. Because the victim is not logged out of their account, they may not realize that access has been granted.

Some of the techniques highlighted by the Dutch intelligence services have been observed in the context of the war in Ukraine. In response to the campaign, Meta, the parent company of WhatsApp, stated through a spokesperson that users should never share their six-digit verification codes with anyone. The Russian embassy in Washington, D.C. did not respond to a request for comment.

Why it matters

This campaign demonstrates that even encrypted messaging platforms are vulnerable to social engineering, posing a significant risk to high-profile users like government officials and journalists globally.