Foreign governments have successfully targeted the messaging accounts of senior European Union officials, according to an internal assessment circulated to national capitals in July. The bloc's cyber defence unit identified account takeovers as a primary threat for 2026, marking the first formal acknowledgement that state actors are penetrating official communications channels.

The presentation recorded eight significant security incidents across EU institutions so far this year. While encryption on platforms like Signal and WhatsApp remains intact, attackers bypassed technical protections by manipulating the users themselves. This social engineering approach requires no breakthrough in cryptography, only a convincing pretext to extract verification codes from staff.

The limits of commercial encryption

National intelligence agencies have issued parallel warnings regarding commercial messaging applications. In March, authorities in at least five member states advised against using Signal and WhatsApp for official business. Dutch intelligence services attributed similar campaigns to Russia, while Germany specified that high-ranking individuals in politics, the military and diplomacy were being targeted.

The method relies on impersonation. Hackers pose as support chatbots within the application, persuading the target to share a registration code. Once obtained, this code allows the attacker to link a secondary device to the account. The Federal Bureau of Investigation described a related technique in June, noting that Russian intelligence operatives maintained access to Signal messages even after targets replaced their hardware.

The European Commission declined to discuss its internal security practices following the disclosure. WhatsApp and Signal did not respond to requests for comment. The reliance on commercial providers for state business creates a dependency that security training alone cannot resolve.

Fragmentation within the institutions

Beyond external threats, the internal presentation highlighted a structural weakness within the EU bureaucracy. Different institutions operate distinct technical security setups, leaving the bloc without a common method to exchange sensitive or classified documents securely.

This interoperability gap presents a harder challenge than phishing. An institution that cannot transmit a classified file to another branch of the same government relies on workarounds that introduce risk. Fixing this requires harmonising IT infrastructure across multiple autonomous bodies, a political and technical undertaking far more complex than issuing usage guidelines.

Artificial intelligence scales the threat

Separate research indicates that the volume of such operations is increasing due to artificial intelligence. The Taiwanese research firm TeamT5 reported that Chinese state-affiliated groups more than doubled their attack frequency after integrating AI models into their workflows. These groups use the technology to write malware and map network domains.

The model of choice for these operations is DeepSeek. Charles Li, TeamT5's chief analyst, explained the preference for Chinese-developed tools over Western alternatives. Western models impose stricter restrictions that require significant effort to bypass, making them less attractive for rapid deployment.

The economics of intrusion

Cost remains the primary constraint for attackers rather than capability. TeamT5 recorded no attacks using Moonshot's Kimi K3 model, attributing this to the higher expense of running the software. Inference costs for AI models continue to fall, suggesting cheaper options will become available.

Security firm CyCraft identified a company selling hacking software that utilised ChatGPT during an attack on a Western think tank. The vendor charged between 300,000 and 500,000 yuan per package, equivalent to roughly $44,500 to $74,000. Evidence found on a public shared drive showed a ten-person startup building tools for at least four hacking groups.

Activity linked to one customer overlaps with Mustang Panda, a group the US Justice Department says the Chinese government backs. This commercialisation lowers the barrier to entry for sophisticated cyber operations. The EU has moved from sanctioning individual hackers to targeting the machinery that produces them, but the technology continues to diffuse.

People mentioned

  • Charles Li

    Chief analyst, TeamT5

Organisations

European Commission · TeamT5 · Signal · WhatsApp · DeepSeek