Russia-Linked Cyberattacks Target Signal & WhatsApp Users: Beware of Scams & Espionage

by priyanka.patel tech editor

A surge in sophisticated cyberattacks targeting encrypted messaging apps like Signal and WhatsApp is raising alarms among security officials in France and the United States. The attacks, which aim to compromise accounts and potentially spread disinformation, are suspected to be linked to Russian intelligence services, according to alerts issued by both governments. The focus on secure communication channels underscores a growing concern about foreign interference and the vulnerability of even encrypted platforms to determined adversaries.

The French government’s cyber crisis coordination center (C4) warned Friday of a “recrudescence of campaigns” targeting instant messaging accounts, particularly those belonging to political figures, government administrators, journalists and industry leaders. These attacks aren’t targeting flaws in the apps themselves, but rather exploiting user behavior to gain access. The potential consequences are significant, ranging from access to sensitive conversations to the ability to impersonate individuals and disseminate false information, especially as France prepares for municipal elections.

The attacks employ two primary methods. The first involves impersonating “Signal Support” with a fraudulent account, claiming to detect suspicious activity and prompting users to share security codes – a tactic that grants attackers control of the account. The second method utilizes QR codes, which, when scanned, link the victim’s account to a terminal controlled by the attacker, allowing access to past messages and the ability to send new messages under the victim’s identity. These techniques highlight the importance of verifying the authenticity of any communication requesting sensitive information, even within seemingly secure apps.

Russia Suspected of Orchestrating Attacks

The Netherlands’ intelligence service first attributed these attacks to the Russian state on March 9th, a finding that French authorities have deemed “particularly credible.” France has repeatedly accused Moscow of conducting various interference operations, including cyberattacks, within its borders. Le Parisien reported in January that these actions are seen as preparation for broader interference efforts leading up to the 2027 elections.

The French C4 issued a detailed alert (available here) outlining the tactics and urging vigilance. The alert emphasizes that attackers aim to access conversation histories and potentially take over accounts to spread disinformation.

US Officials Targeted in Similar Campaign

The threat extends across the Atlantic. FBI Director Kash Patel revealed on X (formerly Twitter) that “cyber actors associated with Russian Intelligence Services” have been identified as targeting users of commercial messaging applications, including Signal.

A joint advisory from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) (available on the IC3 website) confirmed that thousands of accounts have already been compromised. The targets in the US include “highly sensitive” individuals, including current and former government officials, military personnel, political figures, and journalists. The FBI emphasized that the vulnerability lies not within the applications themselves, but with user practices.

“It is essential that you are vigilant and that you act: this vulnerability does not reach from the application, but from you, the conclude user,” Patel wrote in his post. This sentiment underscores the critical need for heightened awareness and cautious behavior when using any messaging application, even those with end-to-end encryption.

WhatsApp Also in the Crosshairs

While Signal is specifically highlighted in the US advisory, both Signal and WhatsApp are named in the French C4 alert as being targeted by these campaigns. Le Parisien noted in March 2025 that WhatsApp’s widespread use also makes it a prime target for scams and potential exploitation.

Neither Signal nor the Russian embassy in Washington immediately responded to requests for comment from Reuters, which first reported on the US advisory. The lack of immediate response adds to the growing concern surrounding the scope and intent of these attacks.

The ongoing attacks represent a significant escalation in the use of cyber tactics for potential political interference. As investigations continue, authorities are urging users to remain vigilant, verify the authenticity of communications, and avoid sharing sensitive information with unverified sources. The next official update from the FBI and CISA is expected in early April, providing further details on the scope of the attacks and potential mitigation strategies.

What are your thoughts on the increasing threat of cyberattacks targeting secure messaging apps? Share your comments below and help spread awareness about these vital security concerns.

You may also like

Leave a Comment