Germany’s Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) have issued a joint cybersecurity warning about an active cyber campaign likely conducted by a state-sponsored threat actor. The operation focuses on phishing attacks carried out through the Signal messaging platform.
The campaign targets high-level individuals in political, military, and diplomatic positions, as well as investigative journalists throughout Germany and Europe. Officials warn that compromised messaging accounts can reveal sensitive private communications and put entire professional and institutional networks at risk through access to group messaging.
A key feature of this campaign is that it doesn’t use malware or exploit technical flaws in Signal itself. Instead, attackers misuse legitimate platform functions to secretly take over user accounts, gaining access to contacts and ongoing messages.
Attack Methods
In the main attack approach, threat actors pretend to be official support, appearing as “Signal Support” or a chatbot called “Signal Security ChatBot.” Victims get direct messages warning of urgent account problems and are told to provide a verification code or PIN sent via SMS to avoid data loss or account suspension.
When victims share these codes, attackers can register the account on a device they control using the victim’s phone number. This gives them access to the victim’s account settings, contact list, and block list. While they can’t see old messages stored on the device, attackers can read new incoming messages and send messages pretending to be the victim. The real user then loses account access and may be told by the fake support to create a new account.
A second attack method takes advantage of Signal’s device-linking feature. Victims are tricked into scanning a malicious QR code that connects their account to an attacker-controlled device. In this scenario, the victim keeps normal access and may not notice that attackers are also viewing their communications. This method can expose chat history from roughly the last 45 days plus contact details.
Authorities note that these same techniques can be used against other messaging platforms like WhatsApp, which has similar device-linking and two-step verification features.
Broader Impact and Attribution
When messenger accounts are compromised, the damage extends beyond individual conversations to endanger wider organizational and professional networks through group chat access and shared communications.
While definitive attribution hasn’t been confirmed, similar campaigns have been previously linked to Russia-aligned threat groups tracked as Star Blizzard, UNC5792 (also called UAC-0195), and UNC4221 (UAC-0185), according to major threat intelligence firms in the past year.
Separately, in late 2025, researchers identified another campaign called GhostPairing, where cybercriminals exploited WhatsApp’s device-linking to hijack accounts for impersonation and fraud.
Wider European Security Threats
This advisory comes alongside broader warnings from European security agencies about state-sponsored cyber operations. Norwegian authorities recently blamed Chinese state-aligned groups, including operations linked to Salt Typhoon, for breaching multiple organizations by exploiting vulnerable network infrastructure. Russia has been accused of closely tracking military and allied activities, while Iranian actors are reportedly targeting dissident groups.
Norway’s Police Security Service (PST) has also warned that Chinese intelligence services actively try to recruit people with access to sensitive information, sometimes encouraging recruits to build their own networks through job postings or outreach on professional platforms like LinkedIn. Authorities caution that collaborative research projects may be exploited to boost foreign intelligence capabilities, especially given Chinese regulations requiring quick reporting of discovered software vulnerabilities to government authorities.
PST additionally reports that Iranian cyber actors continue to compromise email accounts, social media profiles, and personal devices of dissidents to gather intelligence on individuals and their networks, with capabilities becoming more targeted.
Industrial Sector Attacks in Poland
Further activity has been observed in Poland, where CERT Polska attributes coordinated cyber operations against over thirty wind and solar facilities, a manufacturing company, and a major combined heat and power plant to a Russian state-aligned group called Static Tundra.
Investigations found that compromised systems all used FortiGate devices serving as both VPN concentrators and firewalls. In every case, internet-facing VPN interfaces allowed authentication without multi-factor authentication, giving attackers a way to gain unauthorized network access.
Recommended Security Measures
Security agencies recommend that users avoid engaging with unsolicited support accounts and never share verification codes or Signal PINs through messaging. Enabling Signal’s Registration Lock feature adds extra protection by blocking unauthorized re-registration of an account on new devices. Users should also regularly check linked devices in their account settings and remove any unknown entries.
The combination of messaging platform exploitation, infrastructure attacks, and coordinated state-backed operations underscores the increasing need to secure communication platforms and enforce strong authentication practices in both government and industrial settings.