Signal
Submitted
Apr 28, 2026, 14:35 UTC
German security agencies warn on 6 February 2026 of state-linked phishing attacks targeting Signal messenger users, primarily European politicians, military, and journalists.
On 6 February 2026, the German Federal Office for the Protection of the Constitution and the Federal Office for Information Security warned of a sophisticated phishing campaign targeting users of the encrypted messenger app Signal. The phishing messages impersonate Signal, claiming the recipient's account was hacked and requesting PIN codes or re-registration of linked devices to capture sensitive information. The attackers employ psychological tricks by warning victims not to share their PIN with others and to only communicate with Signal, thereby gaining trust. Victims are urged to report to German security agencies. Though no official attribution is given, authorities strongly suspect a state actor behind the campaign, as targets include politicians, military personnel, and journalists across Europe. The incident underscores ongoing cyber threats against key societal actors in the European context.
Confidence: High
The article explicitly details a phishing attack targeting Signal messenger users, describes the likely state-sponsored nature, and lists vulnerable populations, clearly indicating a hostile hybrid warfare aggression event.
Source URL
https://www.tagesschau.de/inland/verfassungsschutz-signal-warnung-100.html
Source reliability
B
Info credibility
6
Event time
Feb 6, 2026, 15:15 UTC
Event time confidence
exact
Location
Cyberspace
Primary actor
German Federal Office for the Protection of the Constitution
Country
Unknown
Tags
Signal, phishing, cyber attack, Germany, Federal Office for the Protection of the Constitution, BSI, state-sponsored, politicians, military, journalists
Nodes
Node 2: 5th Column