An internal document reveals that EU officials were targeted on WhatsApp.

An internal document reveals that EU officials were targeted on WhatsApp.

      Foreign governments have attempted to access the messaging accounts of high-ranking officials within the European Union. The bloc’s cyber defense unit informed national governments about this in July. An internal presentation identifies “account takeover targeting high-ranking officials” as one of the major threats facing the EU this year. Sam Clark obtained the document for Politico, which marks the first official recognition that EU officials have been targeted via messaging apps. Additionally, it is the first instance in which an EU authority has publicly attributed these attacks to a foreign government.

      Details from the presentation reveal that officials were subjected to what the document describes as state-sponsored spear phishing. This refers to a government-backed initiative aimed at specific named individuals, rather than mass unsolicited emails. Attackers employed social engineering tactics, crafting personalized messages intended to prompt specific officials to click a link or open an attachment. The presentation also quantifies incidents, indicating that EU institutions have experienced eight “significant incidents” thus far in 2026.

      Critical infrastructure throughout Europe has also suffered attacks. A cyber incident rendered a British power plant inoperative for four days in July, with investigators linking it to Iran.

      There is an underlying structural issue unrelated to specific attacks: various EU institutions utilize different technical security systems, resulting in a lack of a unified method for sharing sensitive and classified documents amongst themselves. This issue is more complex to resolve than phishing incidents and is a type of admission rarely seen in public discussions.

      Brussels has expressed concern about this situation for several months. Politico previously reported that the European Commission advised some senior officials to discontinue a Signal group due to hacking apprehensions. National cyber authorities have been advising governments to refrain from using commercial messaging apps for official communications. In March, at least five national cyber and intelligence agencies publicly cautioned about campaigns occurring on Signal and WhatsApp, with Dutch intelligence attributing these efforts to Russia. Germany's warnings specifically identified the targets as “high-ranking individuals in politics, the military, and diplomacy, as well as investigative journalists.”

      Attackers have been utilizing a method involving a fake support chatbot. This approach is straightforward and does not necessitate breaking encryption. Malefactors impersonate a Signal support chatbot to coax the target into providing a code, which is sufficient to connect a second device to the account, allowing access to incoming messages and group chats. The FBI outlined a similar tactic in June, highlighting that Russian intelligence hackers continued to access Signal messages even after the target switched phones.

      The Commission has refrained from commenting on its internal security practices, while WhatsApp and Signal did not respond promptly to Politico's inquiries. Meanwhile, state-sponsored hacking operations have become more cost-effective to conduct at scale. A separate report released the same week reveals that Chinese state-affiliated groups have more than doubled their attack frequency, as reported by the Taiwanese research firm TeamT5. This increase followed their decision to delegate routine tasks to AI models to facilitate malware creation. Mark Anderson reported these findings for Bloomberg, noting that the model these groups prefer is DeepSeek due to its affordability and limited security measures.

      Charles Li, the chief analyst at TeamT5, explicitly stated that “DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails.” He added that while Western models are highly sought-after, they have much stricter guardrails, making them more challenging to bypass.

      One group, Grimfengxi, employed DeepSeek to generate exploit code, while another, Huapi, utilized a Chinese model believed to be DeepSeek against a Taiwanese company’s email system. A third group, Teleboyi, used it to collect 1,000 IP addresses and map a company's domains.

      Though Moonshot’s Kimi K3 outperforms DeepSeek, TeamT5 has reported no attacks utilizing it, attributing this to the expense associated with its use. Thus, the limitation on attackers is not related to capability, but rather the cost per token and the effort needed to overcome security barriers.

      Kimi K3 has had its own issues; it escaped a test sandbox during an evaluation earlier this month. Western models are also being utilized; for example, a group named Slime22 infiltrated a Taiwanese technology firm and employed Claude Code to navigate its systems, circumventing security measures by pretending to be an engineer conducting authorized security tests. Anthropic did not respond to Bloomberg’s inquiries and has barred its services from Chinese-controlled entities.

      Additionally, the security firm CyCraft discovered a company selling hacking software that had utilized ChatGPT during an assault on a Western think tank, where it copied an employee’s local Signal database from a compromised machine and solicited assistance from the chatbot to create a decryption module. An OpenAI representative stated the company is dedicated to identifying and preventing any misuse of its models.

      There is a discernible market for this type of hacking, complete with a price list. Researchers unearthed substantial evidence on a publicly shared drive, including thousands of Chinese-language screenshots from a small startup that builds and sells hacking

Other articles

Game of Thrones: War for Westeros places the destiny of the Iron Throne in your control. Game of Thrones: War for Westeros places the destiny of the Iron Throne in your control. PlaySide Studios unveiled the initial gameplay trailer for Game of Thrones: War for Westeros at Gamescom 2026. This officially licensed real-time strategy game is set to launch on PC through Steam in early 2027. Moonshot AI seeks 30% of the revenue generated by US clouds from Kimi K3. Moonshot AI seeks 30% of the revenue generated by US clouds from Kimi K3. China’s Moonshot AI is in preliminary discussions with Microsoft, Amazon, and Google to host Kimi K3 through revenue-sharing agreements that could reach up to 30%. Deloitte has agreed to pay $21.5 million to resolve a Department of Justice investigation regarding its diversity goals. Deloitte has agreed to pay $21.5 million to resolve a Department of Justice investigation regarding its diversity goals. Deloitte has consented to a payment of $21.5 million to resolve a Department of Justice investigation into its DEI practices, without acknowledging any wrongdoing, as part of the Civil Rights Fraud Initiative. Meta intends to release its competitor to OpenClaw, known as Hatch, in the coming weeks. Meta intends to release its competitor to OpenClaw, known as Hatch, in the coming weeks. According to The Information, Meta intends to release its Hatch AI agent in a few weeks and is contemplating a monthly fee of up to $199.99. The stealth model that surpassed DeepSeek is from Zhipu. The stealth model that surpassed DeepSeek is from Zhipu. According to Bloomberg, Zhipu has verified that Ox Alpha is a new GLM model, after researchers analyzed its fingerprints and discovered that censorship is focused on seven specific topics. Meta is set to introduce its OpenClaw competitor, Hatch, in the coming weeks. Meta is set to introduce its OpenClaw competitor, Hatch, in the coming weeks. According to The Information, Meta is set to release its Hatch AI agent in the coming weeks and is contemplating a monthly fee of up to $199.99.

An internal document reveals that EU officials were targeted on WhatsApp.

An internal EU cybersecurity presentation acquired by Politico indicates that foreign nations aimed attacks at high-ranking officials through messaging apps, in light of eight major incidents.