According to the Computer Emergency Response Team (CERT-EU), cybercriminals are targeting organizations based in the European Union through spear phishing attacks, using EU political and diplomatic events to lure them.

In a recent report, CERT-EU says that lures exploiting the EU agenda were particularly prevalent in 2023.
“2023 was the first time in recent years that we observed so many attacks in a short period of time (a few months) directly linked to EU consultation and decision-making processes,” CERT-EU researchers wrote.
See also: SNS Sender Malware distributes Phishing SMS via Amazon
Cybercriminals sent spear phishing emails containing malicious attachments, links or PDF files related to EU affairs and policies.
For example, some of the baits used were related to the following EU bodies, programs and events:
- Swedish Presidency of the Council of the EU
- EU – Community of Latin American and Caribbean States (CELAC) Summit.
- Working Party of Foreign Relations Counselors (RELEX)
- EU LegisWrite (a European Commission program)
The cybercriminals "did not necessarily target the mentioned organizations," but were targeting individuals and organizations involved in EU events and policies who might be tempted to open the decoy document.
To make spear phishing emails more convincing, attackers often impersonated government officials from the Union or the public administration of EU countries.
According to the report, in 2023, Spear phishing was one of the top attack against organizations based in the European Union.
See also: Phishing campaign targets Microsoft Azure accounts
Apart from public administration, the sectors most targeted were diplomacy, defense and transportation.
CERT-EU also observed new spear phishing techniques, such as the move to instant messaging and social media.
Some of the incidents observed are the following:
- A European Union entity reported targeted phishing emails and WhatsApp messages impersonating a head of the entity
- The head of an entity was targeted by a smishing (SMS phishing) attack that attempted to deliver mobile spyware.
Some cybercriminals combined spear phishing campaigns with other information theft operations.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Microsoft Teams: Used in phishing attacks to distribute DarkGate malware
“We assess that spear phishing operations carried out as a prelude to information sourcing pose a significant threat to European Union entities, especially in view of the upcoming EU elections,” the report states.

Protection against spear-phishing
- Staff training is crucial. Staff should be aware of spear phishing techniques and how to recognize suspicious emails .
- Using security software is another good practice. This software can identify and block suspicious emails before they reach their destination.
- It is important to keep your computer's software and operating system up to date. Updates often include security that can protect your computer from new spear phishing techniques (e.g., those exploiting EU themes).
- Using multi-factor authentication can provide an extra layer of protection. Even if a hacker manages to gain access to your username and password, they will still need additional information to gain access to an account.
- Finally, it's important to have a response plan in case you become a victim of spear phishing. This may include notifying authorities, changing passwords , and informing your customers.
Source: www.infosecurity-magazine.com
