Poland shifts away from Signal following cyberattacks on officials’ accounts

(Pierluigi Paganini – Security Affairs) Poland has instructed government officials to stop using Signal for sensitive communications and move to a state-developed alternative. The decision follows repeated cyberattacks targeting Signal accounts belonging to politicians, military personnel, and public servants. Officials believe the campaigns are linked to Russian-backed APT groups. The attacks did not break Signal’s encryption but instead targeted users through account compromise and social engineering tactics. In one scenario, attackers impersonate Signal support staff or automated security bots, warning users about suspicious activity and tricking them into sharing verification codes or PINs, which allows full account takeover. Another method uses malicious QR codes or links that secretly connect an attacker-controlled device to the victim’s account. Once linked, attackers can silently access private chats, group messages, and conversation history. – Poland shifts away from Signal following cyberattacks on officials’ accounts

Latest articles

Related articles