The EU has acknowledged for the first time that cyberattacks targeting the messaging accounts of high-ranking officials have occurred
Foreign governments have attempted to hack into the messaging accounts of high-ranking European Union officials. This has been officially acknowledged for the first time at the level of EU institutions.
The document was presented to representatives of EU member states’ governments in July. It identified “the compromise of high-ranking officials’ accounts” as one of the main cyber threats to the bloc in 2026.
The presentation marked the first official acknowledgment that EU officials have been targeted by cyberattacks via messaging apps. Earlier this year, several national cyber agencies reported similar campaigns, particularly in connection with the activities of Russian hacker groups.
At the same time, the document marks the first recorded instance in which an EU institution has officially linked such attacks to a foreign government.
According to the presentation, officials fell victim to so-called “state-sponsored spear-phishing.” These are targeted attacks in which attackers create personalized messages to trick a specific person into clicking on a malicious link or opening a dangerous file.
Hackers also used social engineering techniques, crafting messages tailored to potential victims.
Earlier this year, the European Commission ordered some high-ranking officials to close a group on Signal due to concerns about potential hacking attacks.
This came amid warnings from national cyber agencies urging government bodies not to use commercial messaging apps, particularly WhatsApp and Signal, for official correspondence.
In March, at least five national cyber and intelligence agencies publicly reported hacking campaigns targeting Signal and WhatsApp users.
Dutch intelligence agencies directly blamed Russia for the attacks. Germany stated that the attackers’ targets included high-ranking officials in the political, military, and diplomatic spheres, as well as investigative journalists.
According to cyber agencies, the attackers disguised themselves as fake Signal support chatbots.
In this way, they attempted to convince users to provide access codes to their accounts. Once they obtained the code, the hackers could take over the account and gain access to incoming messages and group chats.
EU cybersecurity officials noted in a presentation that this year, EU institutions have faced eight “significant incidents.”
One of the main problems remains the lack of a unified approach to cybersecurity. Different EU bodies use different technical solutions and still lack a unified mechanism for the secure exchange of confidential and classified documents.
According to EU cybersecurity officials, this creates additional risks to the security of official communications and the data of European officials.
This is stated in an internal presentation by the EU’s cyber defense unit, which Politico reviewed.
As a reminder, Norway’s Digitalization Agency has been under a large-scale cyberattack for the third consecutive day, described as one of the largest in the country in recent months. Cybersecurity experts are working to restore stable system operations and identify the source of the attack.
In Latvia, a cyberattack on the Road Traffic Safety Directorate (CSDD) resulted in attackers obtaining personal data on 1.2 million people. The CSDD reported this on August 18, according to LSM English.