Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • Dutch Intelligence Warning: Russian State Actors Targeting Signal and WhatsApp
  • Cybercriminals

Dutch Intelligence Warning: Russian State Actors Targeting Signal and WhatsApp

Do Son March 10, 2026 3 minutes read
0
WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
Add Daily CyberSecurity as a preferred source on Google

In a significant Cybersecurity Advisory released in March 2026, the Netherlands Defence Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) issued a joint alert regarding a “large-scale global attempt to compromise Signal and WhatsApp accounts”.

The campaign specifically targets dignitaries, civil servants, and military personnel, though researchers deem it probable that journalists and other persons of interest to the Russian government are also at risk.

What makes this campaign particularly dangerous is that it does not rely on technical exploits or malware. Instead, the attackers “utilise legitimate security functions of the apps in combination with social engineering techniques”.

Signal/WhatsApp Account TakeoverSocial Engineering Attack
Example of Signal message

The advisory details two primary modes of attack:

  1. Account Take-over: Attackers pose as official support teams. As the advisory notes:”The victim receives a message purportedly from the Signal Security Support Chatbot, claiming for example that suspicious activities have been observed in the victim’s account”. The attackers then trick the user into sharing an SMS verification code and their Signal PIN, allowing them to link the account to a new phone number and gain full access to contact lists and messages.
  2. Linked Devices & QR Codes: Using malicious invitations to join chat groups, actors persuade victims to scan a QR code. This seemingly innocent action “actually links the actor’s device to the victim’s account,” providing full access to all chats and history.

Victims of an account take-over can often re-register their number and regain access to their local chat history. Because the app appears normal, “the victim may assume that nothing is wrong”. The Dutch services warn this is a false sense of security, as the attacker may still be active or have already exfiltrated sensitive data.

The MIVD and AIVD stress that Signal and WhatsApp themselves have not been compromised; the issue lies in the manipulation of individual accounts. To stay safe, the advisory offers several key recommendations:

  • Never send classified or sensitive information via these apps; only use organization-approved tools.
  • Verify Support: “Signal’s customer services will never contact you directly via a Signal message, neither will they ask you for your verification codes”.
  • Audit Devices: Regularly check “Linked devices” in your app settings and delete any unknown entries immediately.
  • Enable Protections: Activate Registration Lock in Signal and consider using Disappearing Messages to limit the data available if a compromise occurs.

“The loss of an account is irreversible and can lead to lasting damage,” the advisory warns. If you suspect you have been targeted, inform your contacts via a different channel—such as a phone call or email—to prevent further spread of the campaign.

Related coverage

  • Crypto Crash: Alabama Man Sentenced for Hijacking SEC’s X Account
  • The Interview Trap: Malicious Next.js Repositories Weaponize Coding Tests to Hack Developers
  • Operation Saffron: Authorities Smash ‘First VPN’ Cybercrime Network
  • LastPass Warns of New SEO Poisoning Attack Targeting Mac Users
  • OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover AIVD cyber-espionage cybersecurity infosec MIVD Signal social engineering threat intelligence WhatsApp

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
  • CVE-2026-53362
    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-46242CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-56155CVSS 7.8
    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate...
    CISA KEV📅 Added to KEV: Jul 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64625CVSS 9.8
    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps...
  • CVE-2026-53595CVSS 9.4
    FreeScout is a free help desk and shared inbox built with PHP's...
  • CVE-2026-44231CVSS 9.1
    RT is an open source, enterprise-grade issue and ticket tracking system. Versions...
  • CVE-2026-63766CVSS 9.8
    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where...
  • CVE-2026-63767CVSS 9.8
    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization...
  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
  • CVE-2026-35048CVSS 9.8
    The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for...
  • CVE-2026-51027CVSS 9.9
    An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.