Dutch intel warns governments off Signal and WhatsApp

Photo by Jan van der Wolf on Pexels
Dutch intelligence services AIVD and MIVD say a large-scale Russian-linked campaign is hijacking Signal and WhatsApp accounts using six digit verification codes and device linking features. The services warned these consumer apps "should not be used as channels" for official communication, after similar alerts from Germany’s BfV and BSI, and Australia’s conclusion in March 2025 that consumer messengers expose sensitive data, according to multiple reports including Element Blog and The Register.
Until now, many public sector teams leaned on WhatsApp or Signal for speed under the assumption that end to end encryption equaled safety. The new guidance makes a harder point. If the attacker becomes the endpoint through social engineering, encryption does not help.
This is not a crypto break, it is an account takeover problem
Attackers are impersonating support, tricking targets into sharing one time codes, or abusing the apps’ link device features to silently add a second client. Once linked, messages flow to the attacker without tripping content protections. The Dutch services describe a sustained campaign targeting government employees, journalists, and military personnel. The vector is simple, scalable, and hard to detect inside consumer apps.
Element characterizes these tools as "insecure by design" for official use. You do not need to agree with the phrasing to see the operational gap. Consumer messengers prioritize virality and convenience, not organization wide controls or rigorous identity binding. That trade off is acceptable for family chats. It is reckless for state work.
Policy implications for EU buyers
This is, functionally, a policy decision by security authorities. When national services say not to use apps, procurement and risk teams must act. Acceptable use policies should be updated to prohibit consumer messengers for any official or sensitive thread, including crisis response and interactions with contractors. Training must shift from “do not click suspicious links” to a concrete rule: no verification codes, no device links, no exceptions.
Migration is the hard part. Moving away from WhatsApp or Signal introduces friction, new apps, and account management. That is the price of control. EU teams have viable options that align with data sovereignty goals, including Element, Wire, and Threema. Each requires rollout planning, onboarding, and policy tuning. The upside is clear accountability over identities, devices, and retention, which consumer apps do not provide to institutions.
The real question is timing. Germany has already raised flags. The Netherlands raised them again on Monday. If you handle public sector communications or critical infrastructure coordination, treating this as a Q2 task is the safer bet than waiting for a breach locally.
Why This Matters
If your department or supplier network still runs official chats on WhatsApp or Signal, you now carry a documented takeover risk. Move sensitive threads to an EU controlled platform like Element or Wire, and write policy that bans device linking and code sharing for work accounts. For municipal IT or emergency services, this is not theoretical. It is the difference between controlling an incident channel and briefing an adversary in real time.
Sources
Share this article
Products Mentioned
Timing is an automatic time tracking software for Mac that records time spent on various activities without the need for manual timers. It tracks usage across apps, documents, and websites, and provides AI-generated summaries to help users understand their productivity. Timing also supports manual time entry and integrates with calendar events and phone calls.
Cloud-based messaging app with group chats, channels, bots, and file sharing. Known for speed, large group support, and cross-platform availability.
Chinese AI company offering open-source language models competitive with leading US models at lower cost.
Team messaging platform with channels, direct messages, file sharing, and integrations with hundreds of business tools.
Element is a secure and interoperable communications platform built on the Matrix open standard. It offers organisations control over their communications with features like end-to-end encrypted messaging, voice and video calls, and desktop collaboration. Element supports digital sovereignty by allowing self-hosted solutions and ensuring independence from vendor-locked systems.
Stoat (formerly Revolt, rebranded in October 2025) is an open-source, privacy-focused messaging platform built in the UK. It provides a familiar Discord-like experience with servers, channels, voice chat, and rich media sharing — but with full GDPR compliance and EU data hosting. Stoat is fully self-hostable, giving communities and teams complete control over their data. It features fine-grained role-based permissions, end-to-end encryption, and does not require a phone number or real name to register. Ideal for privacy-conscious communities looking for a feature-rich alternative to Discord.
Threema is a Swiss encrypted messenger founded in 2012 by Manuel Kasper in Pfäffikon, Switzerland. Unlike most messaging apps, Threema requires no phone number or email to register — users get a random Threema ID, enabling truly anonymous communication. All messages, calls, and files are end-to-end encrypted, and metadata is minimized by design. Threema is fully open source and has been independently audited. It's widely adopted in German-speaking countries and used by the Swiss government and military.
Wire is a secure communication platform designed for organizations, offering end-to-end encrypted messaging, calls, and file sharing. It provides flexible deployment options including cloud, on-premises, and hybrid solutions. Wire is trusted by enterprises and governments for its security, compliance, and digital sovereignty features.
Ready to Switch to EU Alternatives?
Explore our directory of 400+ European alternatives to US tech products.