Summary
- A confidential EU cybersecurity assessment says state-sponsored attackers have tried to compromise senior officials’ Signal and WhatsApp accounts through spearphishing and social engineering.
- More than 190 threat actors reportedly targeted the EU institutional ecosystem during the previous year.
- The same assessment identifies fragmented practices around digital signatures, document classification, and secure collaboration across EU bodies.
State-sponsored attackers have attempted to compromise the Signal and WhatsApp accounts of senior officials across European Union institutions, according to a confidential cybersecurity assessment that also points to persistent weaknesses in how sensitive information moves between EU bodies.
The Interinstitutional Cybersecurity Board presentation, seen by Euronews, describes targeted spearphishing and social-engineering attempts rather than a technical compromise of Signal or WhatsApp encryption. Attackers have reportedly tried to take over accounts directly and used messages referring to subjects such as sanctions and official EU statements to make approaches appear credible.
More than 190 threat actors reportedly targeted the EU institutional ecosystem during the previous 12 months, while eight significant incidents were recorded in the first half of 2026. The assessment also refers to a March cloud breach involving compromised Amazon Web Services accounts used by parts of the Europa.eu estate.
Because the underlying presentation is not public, the detail depends on reporting by an organisation that has inspected it rather than a document that can be independently reviewed in full. Even with that limitation, the activity fits a broader pattern of intelligence-linked campaigns targeting politicians, diplomats, military personnel, journalists, and public bodies through the communication tools they use every day.
Encrypted messaging still depends on secure identities
The reported attacks expose a distinction that can disappear in discussions about secure messaging. End-to-end encryption protects message content while it travels between authorised participants, but it does not stop an attacker from stealing a verification code, compromising a device, abusing an account-recovery process, or persuading a user to approve a malicious login.
Germany’s security authorities warned earlier this year about phishing activity aimed at Signal users, with politicians, members of the armed forces, diplomats, and journalists among the intended targets. The pattern suggests that attackers are looking for weaknesses around the application rather than attempting to defeat the cryptography underneath it.
For senior officials, a compromised account can expose more than message content. Contact networks, timing information, trusted identities, and contextual material can all help an attacker build more convincing approaches to colleagues, while control of an account can turn one victim into an entry point for others.
Security therefore extends beyond choosing an encrypted application. Organisations have to protect registration workflows, linked devices, credentials, recovery processes, mobile endpoints, and the human routines through which sensitive communication takes place.
Institutional fragmentation adds another weakness
EU institutions have operated under a common cybersecurity regulation since January 2024, requiring bodies to establish governance frameworks, implement baseline measures, conduct maturity assessments, and report incidents to CERT-EU. The regime also created the Interinstitutional Cybersecurity Board to oversee implementation across organisations that otherwise retain significant operational independence.
The confidential assessment suggests that technical and procedural differences remain. EU experts reportedly identified varying digital-signature and certificate systems, inconsistent approaches to document classification, and no common platform for secure collaboration on sensitive material.
Those differences become security issues when work crosses organisational boundaries. A document protected inside one institution eventually has to reach another, and incompatible controls can encourage workarounds through email, messaging tools, file transfers, or manually managed access.
The same problem applies to identity. Attackers do not need to respect the administrative boundary between the Commission, Parliament, an agency, and a committee when officials and documents move between them, leaving security teams to defend a communication network that is organisationally fragmented but operationally connected.
The March cloud incident referenced in the assessment reinforces the point. Public web infrastructure may not contain the Union’s most sensitive material, but compromised cloud accounts still show how identity and configuration weaknesses can expose systems without an attacker having to defeat the cloud platform itself.
With more than 190 threat actors reportedly showing interest in the institutional ecosystem, the task is unlikely to be solved by finding one vulnerable application. The stronger defence is reducing inconsistent processes and exploitable identities across a sprawling collection of organisations while ensuring that the secure route remains practical enough for officials to use when information has to move between them.












