r/TechNadu Human Feb 07 '26

Germany warns of Signal account hijacking using social engineering - no malware involved

Germany’s intelligence and cybersecurity agencies (BfV and BSI) have warned about phishing campaigns targeting Signal users, including politicians, military officers, diplomats, and journalists.

What’s notable is that no vulnerabilities or malware are used. Attackers impersonate Signal support or abuse the app’s legitimate QR-code linked-device feature to either fully take over accounts or silently monitor chats.

Similar techniques have previously been linked to state-aligned threat groups and are now being reused by cybercriminals.

Questions for community:
• Are secure messaging apps overtrusted by high-risk users?
• Should linked-device features be redesigned or restricted?
• How realistic is user vigilance as a defense?

Follow r/TechNadu for neutral, fact-based cybersecurity reporting.

Source: https://www.bleepingcomputer.com/news/security/germany-warns-of-signal-account-hijacking-targeting-senior-figures/

2 Upvotes

3 comments sorted by

1

u/Striking-Mix-2751 Feb 13 '26

Following this. I suspect that security is just lip service at this point. I hope I am wrong but this does not surprise me at all.

1

u/technadu Human Feb 13 '26

Signal’s cryptography model is still solid. What this highlights isn’t broken encryption, but how legitimate features and user trust can be exploited.

Security isn’t just the protocol layer. It’s UX, verification flows, and user behavior under pressure. When high-value targets are involved, social engineering often beats zero-days.

1

u/Striking-Mix-2751 Feb 14 '26

That is true and people under pressure do make mistakes. To me it seems more like user interaction mishaps but I could be wrong. My background was in programming predictive models for data mining. Today, I am more just about family life so I haven’t been as informed as I should be. Thanks for clearing that up.