Back to News
policy

Russian government hackers targeting Signal and WhatsApp users, Dutch spies warn

Lorenzo Franceschi-Bicchierai
Loading...
4 min read
0 likes
⚡ Quantum Brief
Dutch intelligence agencies exposed a large-scale Russian state hacking campaign targeting Signal and WhatsApp users globally, focusing on government officials, military personnel, and journalists. The attackers use phishing and social engineering—posing as Signal support to trick victims into sharing SMS verification codes and PINs, then hijacking accounts without malware. Victims lose access but can re-register, though Signal’s local chat storage may mask the breach, leaving contacts exposed while hackers impersonate them. On WhatsApp, hackers exploit the "Linked Devices" feature via malicious QR codes, gaining access to past messages without logging victims out, unlike Signal’s limited data exposure. Known Russian tactics from the Ukraine war are being repurposed, with no official responses from Signal, Meta, or Russian authorities to the allegations.
AI Audio Summary
0:00 / 0:00
Click to play
Gemini_Generated_Image_h5l2xxh5l2xxh5l2 (1).png
Quantum News · Media Library

Russian government hackers are targeting Signal and WhatsApp users, particularly government and military officials, as well as journalists all over the world, Dutch intelligence said on Monday. The Netherlands’ Defence Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) published details about a “large-scale global” hacking campaign against Signal and WhatsApp users. The two agencies accused “Russian state actors” of using phishing and social engineering techniques — rather than malware — to take over accounts on the two messaging apps. In the case of Signal, the hackers are masquerading as the app’s support team and messaging targets directly with warnings of suspicious activity, “a possible data leak,” or of attempts to access the target’s private data. If the target falls for it, the hackers ask for a verification code sent via SMS — the hackers themselves request this code from Signal — as well as the targets’ PIN code.

Contact Us Do you have more information about this hacking campaign, or other campaigns targeting Signal and WhatsApp? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. The hackers then use the verification and PIN codes to register a new device with a new phone number, impersonate the target, and potentially access their contacts, according to the report. Also, the target gets locked out of their account, but can re-register their number. “Because Signal stores the chat history locally on the phone, a victim can regain access to that history after re‑registering. As a result, the victim may assume that nothing is wrong. The Dutch services want to stress that this assumption could be incorrect,” the report reads. Signal does not provide support directly through the app. And it’s important to note that, generally speaking, when a user adds a new device to their Signal account, the new device does not have access to previous messages. Signal did not respond to a request for comment. Image: an example of a malicious Signal message sent by the hackers, currently “the most common illustration of such a message and the method of account takeover.” (Image Credits: Netherlands’ General Intelligence and Security Services) Hackers are also trying to trick targets on both apps into scanning malicious QR codes or clicking on malicious links. “For example, an actor may send a QR code or link to a victim to add them to a chat group, but this QR code or link actually links the actor’s device to the victim’s account,” the report explained. In the case of WhatsApp, the hackers are abusing the “Linked devices” function, which allows users to access WhatsApp from a secondary device such as a laptop or a tablet. If the hackers successfully trick their targets, — unlike with Signal — they can potentially read past messages. And sometimes, the victim may not realize that they have granted access to the hackers’ given that they don’t get logged out of their account. WhatsApp suggests users to never share their six-digit code with anyone. Meta declined to comment about the hacking campaign.

The Dutch Ministry of Interior and Ministry of Defense did not respond to a request for more information about the hacking campaign. The Russian embassy in Washington D.C. did not respond to a request for comment. Some of the techniques highlighted by the Dutch intelligence services in this report have been known to be used by Russian government hackers in the context of the war against Ukraine. Topics cybersecurity, hackers, hacking, Netherlands, russia, Security, signal, WhatsApp Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio June 9 Boston, MA Actively scaling? Fundraising? Planning your next launch?TechCrunch Founder Summit 2026 delivers tactical playbooks and direct access to 1,000+ founders and investors who are building, backing, and closing.Register by March 13 to save up to $300. REGISTER NOW Most Popular Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year Julie Bort Cursor is rolling out a new kind of agentic coding tool Russell Brandom Meta sued over AI smart glasses’ privacy concerns, after workers reviewed nudity, sex, and other footage Sarah Perez Jensen Huang says Nvidia is pulling back from OpenAI and Anthropic, but his explanation raises more questions than it answers Connie Loizos Anthropic CEO Dario Amodei calls OpenAI’s messaging around military deal ‘straight up lies,’ report says Amanda Silberling Father sues Google, claiming Gemini chatbot drove son into fatal delusion Rebecca Bellan ChatGPT uninstalls surged by 295% after DoD deal Sarah Perez

Read Original

Tags

aerospace-defense
government-funding
quera

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.