Dutch Intelligence Warns of Russian-Linked Phishing Attacks on Messaging Apps
A fresh alert from Dutch intelligence agencies has sent ripples through the cybersecurity world. Russian-backed hackers are reportedly running a sophisticated phishing campaign targeting popular messaging platforms like Signal and WhatsApp. This is not a brute-force assault on the apps’ technical defenses. Instead, attackers are relying on social engineering—psychological manipulation rather than code-breaking—to trick users into handing over access to their accounts. The warning applies to everyone from high-ranking government officials to everyday professionals, making it a broad and urgent concern.
The Scope of the Threat
According to reports from the Netherlands’ AIVD and MIVD intelligence services, this campaign is global in scale. The primary targets appear to be individuals who handle sensitive information: government employees, military personnel, journalists, and policy experts. However, the methods used are designed to trap any unsuspecting user. The hackers are not exploiting a flaw in the apps themselves but are instead preying on human trust and haste.
How the Hackers Operate
The attackers employ a mix of phishing and social engineering tactics. One of the most common approaches involves impersonating official support bots or customer service representatives. A user might receive a message claiming suspicious activity has been detected on their account, urging them to complete a verification process. The message then asks for a six-digit SMS verification code or account PIN. Once shared, the hacker can instantly take control of the account, locking out the legitimate owner.
Another technique exploits the “linked devices” feature found in many messaging apps. Hackers send a QR code or a link disguised as a group chat invitation or a security update. When the user scans the code or clicks the link, the attacker’s device silently links to the victim’s account. This grants the hacker full access to read chat histories, monitor ongoing conversations, and intercept new messages—often without the user noticing anything unusual until it is too late.
Official Responses from the Platforms
Signal has stated that its encryption and infrastructure remain secure. The company emphasizes that these attacks do not stem from any technical vulnerability in their system. The weakness, they note, lies in user behavior when faced with deceptive messages. WhatsApp, owned by Meta Platforms, has similarly urged users to never share their six-digit verification code with anyone, regardless of how official a request may appear. Both platforms stress that no legitimate support team will ever ask for such codes.
Practical Steps to Protect Your Account
Cybersecurity experts recommend several straightforward measures to defend against these attacks. Implementing them can significantly reduce the risk of account takeover.
- Never Share Your Code: No matter how convincing the message seems, never give your registration code or PIN to anyone. Legitimate services will never request this information.
- Enable Registration Lock: In Signal, activate the registration lock feature within the settings. This prevents anyone from re-registering your phone number on a new device without your permission.
- Use Two-Step Verification: On WhatsApp, enable two-factor authentication (2FA). This adds an extra layer of security, requiring a personal PIN in addition to the SMS code when setting up the account on a new device.
- Activate Disappearing Messages: Turn on the disappearing messages feature for your chats. If an attacker does gain access, they will not find a backlog of old conversations to exploit.
- Review Linked Devices Regularly: Periodically check your account settings to see which devices are connected. If you spot an unfamiliar laptop, desktop, or phone, remove it immediately.
Why These Attacks Are on the Rise
Technology experts point to a simple reason for the surge in such campaigns: messaging apps have become central to modern communication. People use them for private conversations, business negotiations, and sharing sensitive data. This concentration of valuable information makes these platforms an irresistible target for hackers. Instead of trying to break through encryption, attackers now focus on the weakest link in the chain—the human user. By crafting believable scenarios and exploiting urgency or fear, they can bypass even the strongest digital defenses.
The Dutch intelligence warning serves as a stark reminder that cybersecurity is not just about software updates and firewalls. It is also about staying vigilant against manipulation. As these attacks grow more sophisticated, the best defense remains a healthy dose of skepticism and a commitment to basic security habits.
