{"id":371005,"date":"2026-04-02T09:56:07","date_gmt":"2026-04-02T09:56:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/371005\/"},"modified":"2026-04-02T09:56:07","modified_gmt":"2026-04-02T09:56:07","slug":"ncsc-warns-high-risk-individuals-of-signal-and-whatsapp-social-engineering-attacks","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/371005\/","title":{"rendered":"NCSC warns high-risk individuals of Signal and WhatsApp social engineering attacks"},"content":{"rendered":"<p>&#13;<\/p>\n<p>High-risk individuals have been urged to take steps to reduce their exposure to social engineering attacks against encrypted messaging apps, including Signal, WhatsApp and Facebook Messenger.<\/p>\n<p>The UK\u2019s National Cyber Security Centre, part of GCHQ, <a href=\"https:\/\/www.ncsc.gov.uk\/news\/ncsc-warns-of-messaging-app-targeting\" rel=\"nofollow noopener\" target=\"_blank\">warned that politicians, academics, journalists and lawyers are at greater risk<\/a> from social engineering attacks by nation-state-backed hackers attempting to gain access to messaging services.<\/p>\n<p>Government officials have also been targeted by China, the Russian Federal Security Service (FSB) \u2013 <a href=\"https:\/\/www.computerweekly.com\/news\/252525366\/How-Russian-intelligence-hacked-the-encrypted-emails-of-former-MI6-boss-Richard-Dearlove\" rel=\"nofollow noopener\" target=\"_blank\">which hacked the encrypted emails of a former head of MI6<\/a> \u2013 and Iran\u2019s Islamic Revolutionary Guard Corps (IRGC).<\/p>\n<p>The NCSC\u2019s alert follows <a href=\"https:\/\/www.computerweekly.com\/news\/366619473\/Warning-over-privacy-of-encrypted-messages-as-Russia-targets-Signal-Messenger\" rel=\"nofollow noopener\" target=\"_blank\">warnings from Google\u2019s Threat Intelligence Group<\/a> in February that Russian state-backed groups were making increasing efforts to target the Signal accounts of people of interest to the Russian intelligence services.<\/p>\n<p>Hacking groups were using social engineering techniques to trick high-risk individuals into linking their Signal, or other messaging accounts to devices controlled by the hackers, allowing them to read messages sent and received by the target.<\/p>\n<p>Techniques include attempts to trick victims into sharing login or account recovery codes, to persuade people to join group chats, to impersonate someone known to the victim, or to send malicious links or QR codes.<\/p>\n<p> Journalists targeted<\/p>\n<p>Journalists working on sensitive stories using the Signal messaging services were targeted with phishing messages in late January.<\/p>\n<p>Stefania Maurizi, an Italian investigative journalist, told Computer Weekly that she had been working on investigations into the activities of <a href=\"https:\/\/www.yahoo.com\/news\/articles\/trump-sparks-fresh-outrage-secret-184418621.html\" rel=\"nofollow noopener\" target=\"_blank\">US Immigration and Customs Enforcement<\/a> (ICE), the Israel Defence Forces and Italian police when she received a phishing message purporting to be an update to Signal.<\/p>\n<p>\u201cSince I have worked on WikiLeaks for over a decade and on the Snowden files, I became acutely aware of how journalists are a target,\u201d she said. Checks revealed there was no Signal update available for her phone.<\/p>\n<p>Maurizi was sent a second phishing message a few days later on a second phone purporting to come from the \u201c<a href=\"https:\/\/support.signal.org\/hc\/en-us\/articles\/9922048370586-Did-Signal-Support-or-Signal-Security-contact-me\" rel=\"nofollow noopener\" target=\"_blank\">Signal security support chatbot<\/a>\u201d, a non-existent service.<\/p>\n<p>  <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2026\/04\/Signal-Phishing-Message_half_column_mobile.png\" class=\"lazy\"  height=\"622\" width=\"279\"\/><\/p>\n<p>   Phishing message received by Stefania Maurizi<\/p>\n<p>Russian attackers have exploited Signal\u2019s \u201clinked devices\u201d feature that enables Signal to be used on multiple devices simultaneously by sending the victim malicious QR codes masquerading as legitimate Signal messages.<\/p>\n<p>If the attacks are successful, future messages will be sent simultaneously to the victim and to the hacker, allowing the hacker to eavesdrop on secure conversations without having to compromise the victim\u2019s device.<\/p>\n<p>The <a href=\"https:\/\/www.ncsc.gov.uk\/collection\/defending-democracy\/guidance-for-high-risk-individuals\" rel=\"nofollow noopener\" target=\"_blank\">NCSC advises people at risk<\/a> not to share sensitive information through messaging apps, which may be difficult for some users, to use two-step authentication in Signal, and passkeys.<\/p>\n<p>It recommends regularly checking in settings for devices linked to a messaging account, reviewing membership of discussion groups and removing or verifying any unrecognised participants and the use of disappearing messages.<\/p>\n<p> FSB hacked Brexit supporters<\/p>\n<p><a href=\"https:\/\/www.computerweekly.com\/news\/252525366\/How-Russian-intelligence-hacked-the-encrypted-emails-of-former-MI6-boss-Richard-Dearlove\" rel=\"nofollow noopener\" target=\"_blank\">Computer Weekly revealed in 2022<\/a> that a Russian FSB-linked hacking group, known variously as Coldriver, Seaborgium, Callisto and <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/01\/16\/new-star-blizzard-spear-phishing-campaign-targets-whatsapp-accounts\/\" rel=\"nofollow noopener\" target=\"_blank\">Star Blizzard<\/a>, hacked and leaked emails and documents belonging to <a target=\"_blank\" href=\"https:\/\/www.computerweekly.com\/news\/366565960\/Russia-hacked-ex-MI6-chiefs-emails-what-they-reveal-is-more-Dads-Army-than-deep-state\" rel=\"noopener nofollow\">a former head of MI6<\/a>, and other members of a right-wing network campaigning for an extreme hard Brexit. The hacking group also <a href=\"https:\/\/www.computerweekly.com\/news\/366562534\/UK-names-Russian-FSB-agents-behind-political-hacking-campaign\" rel=\"nofollow noopener\" target=\"_blank\">conducted attacks against journalists, MPs and an NGO<\/a> in the UK.<\/p>\n<p>Academics from the universities of Bristol, Cambridge and Edinburgh, including the\u00a0late\u00a0<a href=\"https:\/\/www.computerweekly.com\/news\/366577932\/Obituary-Professor-Ross-Anderson-pioneer-in-security-engineering-and-campaigner%20https:\/arxiv.org\/abs\/2301.05653\" rel=\"nofollow noopener\" target=\"_blank\">Ross Anderson<\/a>, professor of security engineering, first published researched in 2023 warning that linked desktop versions of Signal and WhatsApp could be compromised if accessed by a border guard or a malicious actor, enabling them to read all future messages.<\/p>\n<p>Last year, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/02\/13\/storm-2372-conducts-device-code-phishing-campaign\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft warned that a Russian-linked group<\/a> dubbed Storm-2372 was targeting victims on WhatsApp, Signal and Microsoft Teams, building up a rapport before sending them invites to online events or meetings through phishing emails.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"&#13; High-risk individuals have been urged to take steps to reduce their exposure to social engineering attacks against&hellip;\n","protected":false},"author":2,"featured_media":371006,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[85,46,125],"class_list":{"0":"post-371005","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-il","9":"tag-israel","10":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/371005","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=371005"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/371005\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/371006"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=371005"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=371005"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=371005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}