OSHI

The Messenger Security Review

Targeted attacks · Social engineering

Spear-phishing does not care about your cryptography

State-linked actors have spent the past year going after the Signal and WhatsApp accounts of European officials. Throughout, the cryptography did precisely what it promises. That is not a defence of it. It is a description of where the fight is.

On 6 February 2026 two German federal agencies — the domestic intelligence service, BfV, and the federal cybersecurity office, BSI — issued a joint security notice about phishing over messaging services. The characteristic of the campaign, they wrote, is that weder Schadsoftware eingesetzt noch technische Schwachstellen der Messengerdienste ausgenutzt werden: neither is malware deployed nor are technical weaknesses in the messengers exploited. What the attackers use instead is the applications’ own legitimate security functions, combined with social engineering. The people named as targets are senior figures in politics, the military and diplomacy, together with investigative journalists. The stated objective is covert access to individual and group chats, and to contact lists. Signal is the primary focus; WhatsApp is judged comparable because it is built the same way.

Six months later the problem acquired an institutional owner. On 26 August 2026 Euronews reported on a confidential European Commission presentation in which the Interinstitutional Cybersecurity Board — the body created in January 2024 to hold the EU institutions to the bloc’s own cyber rules — acknowledged for the first time that state-sponsored actors had spear-phished EU officials. The presentation counts more than 190 threat actors against the EU ecosystem over twelve months, and eight significant incidents in the first half of 2026. The attempts took two shapes: taking over the Signal and WhatsApp accounts of senior officials, and social engineering built on EU subject matter — sanctions, official statements, the things a real colleague would actually write to you about.

One concrete example, from the same reporting: in October 2025 a Euronews journalist received a message from an account presenting itself as Signal Support, warning of “suspicious activity on your device, which could have led to data leak” and asking for verification codes. Read that as a design document. It is not attempting to defeat a cipher. It is impersonating the safety mechanism.

What the protocol actually promises

It is worth being exact here, because “end-to-end encrypted” is often used as though it named a perimeter. Signal’s X3DH specification, which defines how two parties first agree on a key, states the limit in one line: “If authentication is not performed, the parties receive no cryptographic guarantee as to who they are communicating with.” The protocol secures a session between two identity keys. It does not, and cannot, tell you whose keys those are, or how many devices hold a copy of yours.

The phishing chain runs entirely outside the encrypted session Four steps — a pretext message, a reply, a link, a scanned QR code — sit in a box marked as outside the cryptography. They lead into the account, where the relay now delivers a separately encrypted copy to the attacker's linked device as well as to the owner's phone. The protocol's guarantees cover only the second box. NO CRYPTOGRAPHY IS INVOLVED IN ANY OF THIS 1 · Pretext a plausible message 2 · Reply rapport established 3 · Link a page with a QR 4 · Scan a device is enrolled WHAT THE PROTOCOL GUARANTEES YOUR PHONE RELAY holds no keys LINKED DEVICE encrypted encrypted
The lure, the reply, the link and the scan happen where no cipher has any jurisdiction. Afterwards the attacker’s screen is not eavesdropping on the session — it is one of the session’s legitimate ends, and the sender’s own app encrypts a copy for it. There is no cryptographic anomaly to detect, because nothing cryptographic went wrong.

So consider what the ratchet is doing while a phishing chain runs to completion. Forward secrecy holds. Post-compromise security holds. The relay never sees plaintext. And the attacker’s device, once enrolled, is not an outsider to the session — it is a legitimate participant, and every message is encrypted for it, correctly, by the sender’s own app. There is no anomaly at the cryptographic layer to detect, because nothing at the cryptographic layer went wrong.

Every step in the chain is a system behaving exactly as specified. The failure is that no part of it is specified to say anything about it.

The shape of the lure

Microsoft’s write-up of a Star Blizzard campaign in January 2025 remains the best-documented illustration of the craft. The first email carries a QR code that is deliberately broken. It does not work, and that is the function: the target replies to say so, and now there is a conversation. The follow-up carries a shortened link, the link leads to a page of instructions with a working code, and that code, in Microsoft’s words, “is actually used by WhatsApp to connect an account to a linked device and/or the WhatsApp Web portal.” The named targets are current and former government and diplomatic officials, researchers on Russia and defence policy, organisations assisting Ukraine, journalists, think tanks and NGOs. Microsoft recorded it as the first shift in that actor’s longstanding tactics.

What actually helps

Nothing on the following list is cryptographic, which is the honest summary of the entire subject.

Set the app’s PIN before anything happens. CERT‑FR’s March 2026 alert on messenger targeting recommends exactly this, alongside never responding to unverified contacts and never divulging codes. A PIN configured today costs a minute. A number re-registered by somebody else is, per that alert, an irreversible loss of the account.

Treat any request for a code or a QR scan as hostile by default — including, and especially, one that arrives dressed as the platform’s own support team. The October 2025 message above is the template, and it will be reused.

Audit linked devices, and prefer software that audits them for you. GTIG’s standing recommendation to high-risk users is to “audit linked devices regularly for unauthorized devices.” That is correct advice, and it is also an indictment: it has to be given because the software will not raise its hand.

Move the confirmation off the channel. When a message from a known colleague asks for something out of pattern, the check belongs on a different medium that you chose — not a reply, which whoever now holds that account will happily answer.

The only lever a messenger has

We build one of these applications, so the question that concerns us is not what users ought to do but what we owe them, and the answer is narrow. We cannot make anyone un-phishable, and a product claiming otherwise is selling something. What a messenger can do is make the consequence loud: when a device joins your account, that should arrive as an event, not sit as a row in a screen you have never opened. Until this week OSHI did not do that. It listed linked web sessions and it could revoke them; it never announced a new one. The fix ships on iOS in 1.0.45, submitted 13 September 2026, and on Android the same day.

The cryptography was never the weak part of this, and it is not going to become the strong part by getting stronger.

Sources

  • BfV and BSI, Gemeinsamer Sicherheitshinweis — Phishing über Messengerdienste, 6 February 2026. bsi.bund.de
  • Bundesamt für Verfassungsschutz, short notice on the joint BfV/BSI advisory, 6 February 2026. verfassungsschutz.de
  • Euronews, State actors tried to hack EU officials’ messaging apps, cybersecurity body warns, 26 August 2026 — on a confidential European Commission presentation from the Interinstitutional Cybersecurity Board. euronews.com
  • Microsoft Threat Intelligence, New Star Blizzard spear-phishing campaign targets WhatsApp accounts, 16 January 2025. microsoft.com
  • Signal, The X3DH Key Agreement Protocol (specification) — prekey bundles, and the authentication the protocol does not provide. signal.org
  • CERT-FR (ANSSI), alert CERTFR-2026-ALE-003, « Ciblage des messageries instantanées », 20 March 2026 (updated 18 June 2026). cert.ssi.gouv.fr
  • Google Threat Intelligence Group, Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger, 19 February 2025. cloud.google.com

Readers' notes

No account, no name, no email. Nothing is stored about you — not an address, not a browser string. Notes appear immediately and are not reviewed first, so they are capped at 160 characters, and a link can be typed here but will never be made clickable.

160 characters left

    Loading notes…