Germany's Federal Office for the Protection of the Constitution ( BfV) and the Federal Office for Information Security (BSI) have issued a joint warning about a malicious cyber campaign, possibly by a state-backed threat actor, involving phishing attacks via the messaging app Signal.

These attacks are targeting high-ranking figures in politics, the military and diplomacy, as well as investigative journalists in Germany and Europe. Unauthorized access to messaging accounts allows access to confidential private communications and potentially compromises entire networks.
See also: Odyssey Stealer: New malware campaign targets Mac computers
Notably, this campaign does not involve distributing malware or exploiting security vulnerabilities in the messaging platform. Instead, the attackers leverage legitimate features to covertly gain access to victims’ conversations and contact lists.
Signal: How does a phishing attack work?
The attack chain begins with threat actors pretending to be “Signal Support” or a support chatbot named “Signal Security ChatBot” to contact potential targets, prompting them to provide a PIN or verification code received via SMS (under threat of data loss).

If the victim complies, attackers can register the account and gain access to the victim's, settings, contacts, and block list via a device and mobile phone number they control. While the stolen PIN does not provide access to past conversations, it allows the threat actor to record incoming messages and send messages as if they were the victim.
See also: Man pleads guilty to hacking nearly 600 women's Snapchat accounts
The victim, having lost access to their account, is guided by the threat actor, who pretends to be the support chatbot, to register for a new account.
An alternative method involves tricking victims into scanning a QR code, giving attackers access to the victim’s account, including messages from the last 45 days (on a device they manage). In this scenario, targeted individuals retain access to their account, unaware that their conversations and contact lists are exposed to the threat actors.
Security authorities have warned that while the current focus is on Signal, the attack could also extend to WhatsApp, which has similar device and PIN login features as part of its two-step verification. Successful access to messaging accounts allows not only viewing confidential communications but also the potential compromise of entire networks through group chats.

While the identity of the attackers remains unknown, similar attacks have been linked to multiple Russian -aligned threat groups , such as Star Blizzard, UNC5792 (also known as UAC-0195), and UNC4221 (also known as UAC-0185), according to reports from Microsoft and Google Threat Intelligence Group.
See also: 'DKnife': New malicious framework for AitM attacks
In December 2025, Gen Digital described another campaign codenamed GhostPairing, where cybercriminals exploited the device pairing feature in WhatsApp to take over accounts, possibly to impersonate users or commit fraud.
To protect themselves from these threats, users are urged to avoid interacting with support accounts and not enter their Signal PIN as a text message. It is also important to enable Registration Lock, which prevents unauthorized users from registering a phone number on another device. Finally, users should check the list of connected devices and remove any unknown devices.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
