Observed Signal · Mar 9, 2026 · Security Advisory · Source: techcrunch · Impact: 2/5 · Sentiment: Negative
Russian Hackers Target Signal and WhatsApp Users, Warns Dutch Intel
Dutch intelligence agencies MIVD and AIVD warned of a large-scale global hacking campaign by alleged Russian state actors targeting Signal and WhatsApp users — especially government and military officials and journalists. The attackers are reported to use phishing and social‑engineering techniques rather than malware, including impersonating Signal support to request SMS verification codes and PINs, tricking users into scanning malicious QR codes or clicking links, and abusing WhatsApp’s Linked Devices feature to link attacker devices and, in some cases, read past messages. Signal and Meta alerted users not to share verification codes; Meta pointed to Help Center guidance. Dutch spokespeople declined to provide additional operational details. Some techniques match methods previously observed in Russian operations related to the war in Ukraine.
A large-scale account-takeover campaign against widely used messaging apps raises privacy and security risks that can affect journalists, officials and broader user trust; however it is a cybersecurity advisory rather than an industry-changing platform policy or technical release for AdTech.
Track Meta Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- The Netherlands’ Defence Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) published details of a "large-scale global" hacking campaign targeting Signal and WhatsApp users.
- Dutch agencies accused "Russian state actors" of using phishing and social engineering — not malware — to takeover messaging accounts.
- On Signal, attackers impersonate support to request SMS verification codes and the user’s PIN to register a new device and lock victims out.
- On WhatsApp, attackers abuse the "Linked devices" function and malicious QR codes/links to link their devices to victims’ accounts, which can allow access to past messages.
- Signal and Meta advised users not to share verification codes; Meta spokesperson named Zade Alsawah commented and pointed to Help Center guidance.
Connected Companies & Entities
2 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Hackers Target Signal Chat Backups via Phishing
Signal users are being targeted in a new wave of phishing attacks that attempt to steal chat backups by impersonating “Signal Support.” Attackers send messages warning users their backups will be lost unless they provide the recovery key, and include instructions to obtain that key. TechCrunch reported the campaign and Washington Post analyst Josh Rogin posted a screenshot of a sample message on X. Signal warns it will never contact users directly for recovery keys and recommends blocking and reporting fake accounts and contacting Signal via official support pages. Attackers would still need access to the victim’s Signal account to download and decrypt any backups stored on Signal’s servers. The piece cites prior phishing-based account takeovers, reportedly linked to actors operating from Russia.
Phishing Campaign Targets Signal Secure Backups
Hackers are running a phishing campaign targeting Signal users by impersonating a "Signal Support" account and asking victims to share their recovery key to access encrypted online backups. Washington Post analyst Josh Rogin posted a screenshot of the attack; Access Now’s Mohammed Al‑Maskati told TechCrunch that multiple people received similar messages, including some victims who are not Chinese activists, suggesting the campaign may be broader. Stealing a recovery key would let attackers decrypt a user’s Secure Backup archive, but attackers still must fully take over the account to exploit older messages. Signal warns it will never contact users first or ask for registration codes, PINs, or recovery keys. Signal launched its opt‑in Secure Backups feature last year, which encrypts backups with a recovery key that is never shared with Signal’s servers.
WhatsApp Disrupts NSO-Linked Spyware Phishing Campaign
WhatsApp announced it disrupted a spear-phishing campaign it says was linked to NSO Group and that the activity violated a prior court injunction barring NSO from targeting WhatsApp and its users. The Meta-owned messaging app said attackers used malicious links that directed targets to external sites and created test accounts and groups on WhatsApp; those accounts and groups were removed. WhatsApp has filed a contempt motion seeking to hold NSO in contempt of court. The report references prior litigation stemming from a 2019 mass-hacking campaign (leading to a jury award later reduced) and notes NSO’s continued controversy, past U.S. trade restrictions, and a 2025 acquisition by a group of U.S. investors.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
