Sci & Tech
Russia-Backed Hackers Breach Signal, WhatsApp Accounts Of Officials, Journalists, Netherlands Warns
- Hackers have likely gained access to sensitive information
- Hackers use fake Signal Support chatbots to access accounts
AMSTERDAM, March 9 (Reuters) – Russian-backed hackers have launched a global cyber campaign to gain access to Signal and WhatsApp accounts used by officials, military personnel and journalists, two intelligence agencies in the Netherlands warned on Monday.
Users are persuaded in chats initiated by the hackers to divulge security verification and pin codes, giving them access to personal accounts and group chats, they said in a statement.
“The Russian hackers have likely gained access to sensitive information,” the General Dutch Intelligence Agency (AIVD) and Dutch Military Intelligence and Security Service (MIVD) said.
“Targets and victims of the campaign include Dutch government employees” and journalists, the agencies said.
The chat apps offering end-to-end encryption are popular with government officials for sharing confidential or classified information, making them “the ideal place for malicious actors to try to capture sensitive information,” they said.
WhatsApp, in a reaction sent to Reuters, said users should never share their six-digit code with others and that it continued to build ways to protect people from online threats.
Signal said on social media that the targeted attacks were “executed via sophisticated phishing campaigns, designed to trick users into sharing information” and that its encryption and infrastructure had not been compromised.
USERS PERSUADED TO DIVULGE SECURITY CODES
The hackers most frequently masquerade as a Signal Support chatbot to induce targets to divulge the codes, enabling them to take control of the accounts, the statement said.
Another method is to use the ‘linked devices’ function within Signal, it said.
Contacts appearing twice in a user’s contact list, or numbers showing up as ‘deleted account’ could indicate that an account has been compromised, the agencies said.
Dutch authorities issued a cyber advisory notifying government colleagues of the vulnerability and providing assistance to eliminate the threat, a spokesman said, citing the joint operation with the AIVD general intelligence service.
“Despite their end-to-end encryption option, messaging apps such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information,” said MIVD director, Vice-Admiral Peter Reesink.
Kenya Insights allows guest blogging, if you want to be published on Kenya’s most authoritative and accurate blog, have an expose, news TIPS, story angles, human interest stories, drop us an email on [email protected] or via Telegram
-
Investigations18 hours agoHow Did a Sh468K KRA Salary Allegedly Turn Into Sh30 Billion? Questions Deepen Over Commissioner George Obel and Ciala Resort Owner’s Wealth
-
Business1 week agoNairobi Freezes Binance Accounts in Sweeping Anti-Fraud Crackdown as Global Scandal Record Haunts World’s Largest Crypto Exchange
-
Investigations1 week agoTHE FIXER IN THE FILE ROOM: How Parliamentary Health Committee Clerk Adan Gindicha Cleared Mediheal Hospital of Organ Harvesting Claims Despite Mounting Evidence
-
Investigations7 days agoThe Man Behind the Badge: How Prof. Erastus Kanga Turned Kenya’s Premier Wildlife Agency into a Theatre of Corruption, Fear and Impunity
-
Investigations1 week agoEXCLUSIVE: Odibets Bought Stolen Data From Millions Of Kenyans
-
Investigations1 week agoTHE BRAZEN RETURN: Triton Thief Yagnesh Devani, Who Pillaged Kenya of Sh7.6 Billion and Fled, Now Asks the Same Courts He Escaped to Restore His Stolen Wealth
-
Business2 weeks agoTHE FUEL CABAL: How Mohamed Jaffer, a KPC Insider, and a Ministry Official Are Alleged to Have Manufactured Kenya’s Worst Petroleum Crisis in Three Years, While Kenyans Burned
-
Investigations7 days agoKNH ON THE BRINK: How Corruption, Revenue Plunder and State Neglect Are Destroying Kenya’s Flagship Hospital
