New data reveals that foreign governments are attempting to gain access to messaging accounts belonging to high-ranking European Union officials. The European Union's own cyber defense unit informed national governments in July, listing attempts to take over high-ranking accounts among the most significant cyber threats of 2026.

This is a particularly significant development, as it is one of the first official admissions by a European institution that officials have been targeted through messaging applications and that a state-backed actor is behind the attacks .
Personalized phishing to officials instead of mass attacks
The attacks are mainly based on spearphishing and social engineering techniques. The attackers do not send thousands of random messages, but create personalized communications aimed at specific individuals.
See also: WhatsApp introduces web calling
The goal is to convince the victim to open a file, visit a link, or hand over a security code. The method is simple, but particularly effective when used against people who have access to sensitive information.
The threat is becoming even more serious as European institutions have already faced eight major cybersecurity incidents in 2026.
The problem is not just attacks
The internal presentation also highlights a deeper issue: the lack of a common infrastructure for the secure exchange of classified information between different EU institutions.
Different security techniques and policies create gaps in interoperability. So, even if a system is well protected, communicating securely with another European organization can still be difficult.
This problem is not simply addressed by more anti-phishing training. It requires common standards, secure infrastructure, and clear processes for sharing sensitive data.

Signal and WhatsApp in the spotlight
Concerns about the use of commercial messaging apps have grown in recent months. National cybersecurity and intelligence agencies have warned of campaigns leveraging Signal and WhatsApp, with Dutch agencies attributing related activities to Russia.
In one of the techniques described, attackers pose as a fake support service and try to convince the user to reveal a code. With this, they can link a second device to the account and gain access to messages and group chats.
The crucial element is that the application's encryption does not need to be "broken". The attacker attacks the user himself.
See also: WhatsApp Beta version reveals alternative for iPhone backups
Artificial intelligence is changing the scale
At the same time, a second development shows that artificial intelligence is reducing the cost of conducting cyberattacks. According to research by TeamT5, groups linked to China have significantly increased their activity, using AI for tasks such as code generation, target identification and infrastructure mapping.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
DeepSeek seems to be the preferred choice due to its lower cost and less stringent security restrictions. Other groups have used tools such as Claude Code and ChatGPT , attempting to integrate them into real attacks.
A market for cyberattacks is now emerging
The investigation also reveals that the malicious use of AI is also taking on a commercial dimension. Researchers found evidence of a small business that was allegedly developing cyberattack tools for sale, with packages reaching tens of thousands of dollars.
This development shows that the technology does not only function as a tool for individual hackers. It can be integrated into an organized ecosystem of services, automating tasks that previously required specialized teams.

Europe faces a dual challenge
The two trends are not directly related, but they demonstrate the same problem: the cost of cyberattacks is decreasing, while the ability to execute them on a large scale is increasing.
See also: Hackers target Windows users via WhatsApp
Europe is therefore called upon to address both the human side of the threat, by protecting officials from targeted social engineering, and the technological side, by limiting the automation of malicious actions through AI.
The next crucial step is to see whether European institutions will create common infrastructures for secure communication and whether they will make more evidence public for accountability. In an environment where technology makes attacks faster and cheaper, cybersecurity can no longer rely solely on user attention.
