Overview
- Dutch intelligence agencies AIVD and MIVD report a large-scale global effort by Russian state‑affiliated actors targeting officials, military personnel and journalists.
- Attackers initiate chats to phish for verification codes or PINs, often posing as a Signal support bot, and exploit linked‑devices features and malicious group invites.
- Confirmed victims include Dutch government employees, and investigators say the intrusions have likely exposed sensitive information.
- Officials emphasize that no malware or service flaws were used and that end‑to‑end encryption offers no protection once an account is taken over.
- The Netherlands issued a cybersecurity advisory and is assisting victims; WhatsApp urged users never to share their six‑digit code, and Signal had not provided a public comment in initial reports.