اختراق واتساب وسيجنال

Dutch intelligence warns of Russian attacks targeting WhatsApp and Signal

Written by

Picture of فريقنا

فريقنا

Communications Consultant

Intelligence and security agencies in the Netherlands have warned of a global and serious cyber campaign run by Russian-backed hackers to breach officials' accounts on messaging apps like WhatsApp and Signal using social engineering techniques.

Amid escalating geopolitical tensions and cold information wars, European security agencies are sounding the alarm again, warning of sophisticated tactics targeting the personal communications of government officials for espionage and national security breaches.

Introduction to the strict intelligence warning and coordinated attacks

On Monday, intelligence and military security agencies in the Netherlands issued an official, urgent, and detailed warning stating that professional hacker groups, directly and documentedly backed by Russian authorities, have launched what can be described as a “broad and globally oriented cyberattack campaign.” This malicious, coordinated, and ongoing campaign specifically and precisely targets the hacking and complete takeover of personal and professional accounts belonging to prominent government officials, active-duty military personnel, well-known investigative journalists, and senior civil servants on famous secure and encrypted messaging apps, specifically “Signal” and “WhatsApp.” Security agencies confirmed in their official media briefing that these skilled attackers have already successfully victimized Dutch government employees, expressing concern that they very likely managed to obtain sensitive, precise, and confidential information through this ongoing campaign that threatens the security of official and personal communications on the European continent.

Employed tactics and social engineering instead of breaking encryption

What raises extreme concern and interest in these cyberattacks is the mechanism and tactic used to execute them. Instead of wasting vast time and computing resources trying to break the extremely complex and robust end-to-end encryption wall that these apps rely on to protect message content and boast about, attackers rely entirely, fundamentally, and craftily on advanced psychological “social engineering” methods to trick users into unwittingly handing over their own credentials and security codes. The most common, successful, and dangerous method in this attack is hackers impersonating an official automated technical support account for the “Signal” app. Through this fake identity, they begin convincing targets and victims via persuasive messages that appear official of the need to share their security verification codes or personal identification numbers under the guise of security checks or system updates. Once hackers obtain these sensitive numbers, they can instantly take over and completely control the account within seconds, locking out the original user.

Exploiting the linked devices feature for silent and covert espionage

Crafty Russian tactics do not stop there, but extend to include a clever exploitation of the apps’ own features. Another dangerous method has been detected relying on the exploitation of the “linked devices” feature provided by apps, which allows legitimate users to connect additional computers or phones to their accounts to facilitate and speed up messaging. If attackers manage to trick the user and covertly link their own devices to the victim’s account, it grants them absolute ability to clone and monitor all incoming and outgoing messages in real-time silently and without raising any commotion. Once an account is breached in this hidden manner, hackers can read old historical messages and monitor secret group chats without the victimized user noticing any immediate change that would arouse suspicion. The General Intelligence and Security Service and the Military Intelligence and Security Service advised users to pay close attention to signs of a breach, such as the strange appearance of duplicate contacts in the list or numbers suddenly registered as deleted accounts in their lists without justification.

Official warnings against using the applications for confidential information

In an attempt to reassure the public about the security of the technical platforms themselves and prevent public panic, General Intelligence and Security Service Director-General Simone Smit stressed in her explicit speech that the problem lies in individual actions and human error rather than server hacks. She stated: “This is not about hacking the Signal or WhatsApp applications as integrated platforms or breaking their systems at all; rather, the real threat is basically confined to individual user accounts who fall victim to direct deception operations.” However, Military Intelligence Director Vice Admiral Peter Reesink issued a more comprehensive, strict, and firm warning to official bodies, saying: “Despite the availability of complex and strong end-to-end encryption options, these commercial messaging apps must absolutely not be relied upon as secure channels for transmitting and circulating confidential military information or highly sensitive government documents to avoid human breaches that encryption cannot prevent.”

Motives for strategic targeting and responses from app owners

According to the comprehensive 2024 security report, the Netherlands is considered a very strategic and attractive target for Russian operations due to several core geopolitical factors, most notably the active and important role the country plays in providing logistical and military support to Ukraine in its conflict, in addition to hosting the headquarters of major global tech companies and hosting very sensitive international institutions such as the International Criminal Court, which handles sensitive cases affecting the global landscape. Dutch authorities have issued strict guidance directives and are currently providing immediate technical and assistance to affected users to secure their hacked accounts. For its part, WhatsApp management stated in comments on the report that all users should completely refrain from sharing six-digit verification codes with anyone under any circumstances and claims, stressing that it continues to build strong protections against online threats. Meanwhile, no immediate comment was issued by the management of the other app in response to these attacks and reports.

Frequently asked questions

Question: What are the main entities and categories targeted in this Russian cyber campaign?

Answer: The Russian campaign targets the accounts of government officials, military leadership, prominent journalists, and civil servants in the Netherlands to steal their information.

Question: How do hackers manage to hack personal accounts encrypted with high security?

Answer: They do not break encryption; instead, they use social engineering methods by impersonating technical support to trick users into providing security and verification codes themselves.

Question: What are the signs of a breach that authorities demanded be monitored in private apps?

Answer: Among the most prominent warning signs are the appearance of duplicate contacts in private lists, or noticing numbers registered with the phrase deleted account that the user did not add personally.

Question: Why is the Netherlands considered a prominent and vital target for Russian-backed hackers?

Answer: Because of its direct and strong support for Ukraine, the presence of major tech company headquarters on its soil, and its hosting of prominent and influential international institutions like the International Criminal Court.

شارك هذا الموضوع:

شارك هذا الموضوع:

اترك رد

Leave a Reply

الفئات

المنشورات الأخيرة

Discover more from Buzzinga

Subscribe now to keep reading and get access to the full archive.

Continue reading