{"id":27236,"date":"2026-03-10T11:35:17","date_gmt":"2026-03-10T11:35:17","guid":{"rendered":"https:\/\/microvibenews.com\/?p=27236"},"modified":"2026-03-10T11:35:17","modified_gmt":"2026-03-10T11:35:17","slug":"russian-government-hackers-targeting-signal-and-whatsapp-users-dutch-spies-warn","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=27236","title":{"rendered":"Russian government hackers targeting Signal and WhatsApp users, Dutch spies warn"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Russian government hackers are targeting Signal and WhatsApp users, particularly government and military officials, as well as journalists all over the world, Dutch intelligence said on Monday.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Netherlands\u2019 Defence Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) <a href=\"https:\/\/english.aivd.nl\/documents\/2026\/03\/09\/cybersecurity-advisory.-phishing-via-messaging-apps-signal-and-whatsapp\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">published<\/a> details about a \u201clarge-scale global\u201d hacking campaign against Signal and WhatsApp users. The two agencies accused \u201cRussian state actors\u201d of using phishing and social engineering techniques \u2014 rather than malware \u2014 to take over accounts on the two messaging apps.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the case of Signal, the hackers are masquerading as the app\u2019s support team and messaging targets directly with warnings of suspicious activity, \u201ca possible data leak,\u201d or of attempts to access the target\u2019s private data. If the target falls for it, the hackers ask for a verification code sent via SMS \u2014 the hackers themselves request this code from Signal \u2014 as well as the targets\u2019 PIN code.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this hacking campaign, or other campaigns targeting Signal and WhatsApp? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/03\/09\/russian-government-hackers-targeting-signal-and-whatsapp-users-dutch-spies-warn\/mailto:lorenzo@techcrunch.com\/\">email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/03\/09\/russian-government-hackers-targeting-signal-and-whatsapp-users-dutch-spies-warn\/mailto:lorenzo@techcrunch.com\/\">.<\/a>\t\t<\/div>\n<p class=\"wp-block-paragraph\">The hackers then use the verification and PIN codes to register a new device with a new phone number, impersonate the target, and potentially access their contacts, according to the report. Also, the target gets locked out of their account, but can re-register their number.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cBecause Signal stores the chat history locally on the phone, a victim can regain access to that history after re?registering. As a result, the victim may assume that nothing is wrong. The Dutch services want to stress that this assumption could be incorrect,\u201d the report reads.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Signal does not provide support directly through the app. And it\u2019s important to note that, generally speaking, when a user adds a new device to their Signal account, the new device does not have access to previous messages.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Signal did not respond to a request for comment, but <a href=\"https:\/\/bsky.app\/profile\/signal.org\/post\/3mgnap76pnk2a\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">posted a thread on social media<\/a> sharing advice for users on how to protect themselves, including advising against ever sharing the SMS verification code and PIN.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" height=\"680\" width=\"379\" src=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?w=379\" alt=\"\" class=\"wp-image-3100468\" srcset=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png 475w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=84,150 84w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=167,300 167w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=379,680 379w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=240,430 240w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=401,720 401w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=446,800 446w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=372,668 372w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=209,375 209w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=344,617 344w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=296,531 296w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/signal-phishing-scam.png?resize=28,50 28w\" sizes=\"auto, (max-width: 379px) 100vw, 379px\"\/><figcaption class=\"wp-element-caption\"><span class=\"wp-element-caption__text\">an example of a malicious Signal message sent by the hackers, currently \u201cthe most common illustration of such a message and the method of account takeover.\u201d<strong style=\"display: inline !important;\"\/><\/span><span class=\"wp-block-image__credits\"><strong>Image Credits:<\/strong>Netherlands\u2019 General Intelligence and Security Services<\/span><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Hackers are also trying to trick targets on both apps into scanning malicious QR codes or clicking on malicious links. \u201cFor example, an actor may send a QR code or link to a victim to add them to a chat group, but this QR code or link actually links the actor\u2019s device to the victim\u2019s account,\u201d the report explained.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the case of WhatsApp, the hackers are abusing the \u201cLinked devices\u201d function, which allows users to access WhatsApp from a secondary device such as a laptop or a tablet. If the hackers successfully trick their targets, \u2014 unlike with Signal \u2014 they can potentially read past messages. And sometimes, the victim may not realize that they have granted access to the hackers\u2019 given that they don\u2019t get logged out of their account.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Meta\u2019s spokesperson Zade Alsawah said that WhatsApp <a href=\"http:\/\/yes - some warnings on linked devices here: https:\/\/faq.whatsapp.com\/378279804439436\/?cms_platform=android  and not sharing code: https:\/\/faq.whatsapp.com\/479314433984258\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">suggests<\/a> users to never share their six-digit code with anyone, and pointed to <a href=\"https:\/\/faq.whatsapp.com\/2286952358121083?helpref=faq_content\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a Help Center page<\/a> to help users recognize suspicious messages, and a page about the <a href=\"https:\/\/faq.whatsapp.com\/378279804439436\/?cms_platform=android\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Linked Devices feature<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Laurens Bos, a spokesperson for the Ministry of Defence declined to provide more details about the campaign.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Russian embassy in Washington, D.C. did not respond to a request for comment.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Some of the techniques highlighted by the Dutch intelligence services in this report <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/russia-targeting-signal-messenger\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">have been known to be used<\/a> by Russian government hackers in the context of the war against Ukraine.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/09\/russian-government-hackers-targeting-signal-and-whatsapp-users-dutch-spies-warn\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Russian government hackers are&hellip; <\/p>\n","protected":false},"author":1,"featured_media":22760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[1662,3210,1665,3452,2502,3619],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/27236"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27236"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/27236\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/22760"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}