Russian campaign hijacks Signal and WhatsApp accounts without exploits

Dutch intelligence services AIVD and MIVD report a global campaign attributed to Russian state actors in which targets are contacted directly on Signal and WhatsApp. Dutch government employees are among those targeted. The campaign exploits no vulnerability in the apps. Instead, the user is lured into approving a linked device, which hands the attacker access to the account. The services have published advice on strengthening resilience and checking your settings.

What this means for your business

Many executives and specialists use Signal and WhatsApp for work conversations that never reach corporate systems. If the account is hijacked, the attacker gains both the history and a credible identity from which to contact colleagues and counterparts. The attack needs no technical weakness, only a moment of trust, which makes training and settings the only real controls.

Berigo recommends

  • Have everyone in an exposed role review the linked devices list in Signal and WhatsApp and remove anything unfamiliar.
  • Make it an explicit rule that nobody approves a device link or scans a QR code at someone else's request.
  • Clarify which conversations belong in messaging apps at all, and where work communication should take place.
  • Provide a simple way for employees to report suspicious contact, including contact that arrives outside email.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch