Germany suspects Russia behind Signal phishing of senior officials
Germany suspects Russia is behind a phishing campaign targeting the Signal accounts of senior officials in Germany and the Netherlands. The attacks reportedly used fake security warnings to trick politicians, military personnel and journalists into linking their Signal accounts to attacker-controlled devices, giving access to messages and contacts. Around 300 accounts may have been compromised. German authorities have opened an espionage investigation, while Dutch intelligence warns of a broader Russian-linked campaign against encrypted messaging apps. The attribution has not been formally confirmed.
What this means for your organisation
The attack goes around the encryption rather than through it. Link a new device to the account and that device reads everything, legitimately. Many Norwegian executives use Signal precisely because they believe it is safe, and therefore use it for conversations that would otherwise stay in more controlled channels. If you have board members, executives or advisers exposed to foreign policy, defence or energy, they sit in the target group for this kind of operation.
Berigo recommends
- Have your leadership team check the list of linked devices in Signal and remove anything they do not recognise.
- Enable registration lock in Signal so the account cannot be moved without a PIN.
- Train leadership specifically on how device linking works, rather than on generic phishing awareness.
- Decide which conversations should not take place in messaging apps at all, and where they belong instead.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch