Quick Summary
The Securityish Brief
Germany’s Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) have issued a joint advisory regarding a phishing campaign targeting high-ranking individuals in politics, military, and journalism across Germany and Europe. The campaign, attributed to a likely state-sponsored threat actor, leverages the Signal messaging app to carry out its attacks.
The attackers initiate contact by masquerading as ‘Signal Support’ or a chatbot named ‘Signal Security ChatBot.’ They urge victims to provide their Signal PIN or verification code received via SMS, claiming that failure to do so could result in data loss. If victims comply, the attackers can register the account and access the victim’s profile, settings, contacts, and block list.
Another method involves tricking victims into scanning a QR code to link devices, allowing attackers to access messages from the last 45 days while the victim remains unaware that their chats are exposed. Although the current focus is on Signal, similar tactics could be applied to WhatsApp due to its comparable features.
While the specific threat actors behind this campaign remain unidentified, similar tactics have been linked to Russia-aligned groups like Star Blizzard, UNC5792, and UNC4221. In December 2025, another campaign named GhostPairing was reported, where attackers exploited WhatsApp’s device linking feature to hijack accounts.
The implications of these attacks are severe, as unauthorized access to messenger accounts can compromise not only individual communications but also entire networks through group chats. The BfV and BSI emphasize the need for vigilance among users, especially those in sensitive positions.
Protecting Yourself from Phishing Attacks
To mitigate risks, users are advised to avoid engaging with support accounts that request their Signal PIN via text. Enabling Registration Lock is crucial, as it prevents unauthorized users from registering a phone number on another device. Regularly reviewing linked devices and removing any unknown ones is also recommended.
Key Takeaways
- Do not engage with support accounts requesting your Signal PIN via text message.
- Enable Registration Lock on your Signal account to prevent unauthorized access.
- Regularly review the list of linked devices in your Signal settings and remove any unknown devices.
- Be cautious of unsolicited messages claiming to be from support, especially those asking for sensitive information.
- Consider using additional security measures, such as two-factor authentication, where available.
Key Terms & Concepts
- Signal: Signal is a privacy-focused messaging app that allows users to send encrypted messages.
- PIN: A PIN is a personal identification number used to verify a user’s identity for account access.
- Registration Lock: Registration Lock is a security feature that prevents unauthorized users from registering a phone number on another device.
- QR Code: A QR code is a type of matrix barcode that can be scanned to access information or services.
- GhostPairing: GhostPairing is a cyber campaign where attackers exploit device linking features to hijack accounts.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.