European flags flying in front of the Berlaymont building in Brussels.
Foreign governments have tried to break into the messaging accounts of senior European Union officials. The bloc’s own cyber defence unit told national governments so in July.
An internal presentation lists “account takeover targeting high-ranking officials” among the top threats facing the bloc this year.
Sam Clark obtained the document for Politico. It is the first official acknowledgement that anyone targeted EU officials through messaging apps.
It is also the first time an EU authority has formally attributed such attacks to a foreign government.
What the presentation describes
The officials were hit with what the document calls state-sponsored spearphishing. That means a government-backed campaign built around specific named people rather than a mass mailing.
Attackers used social engineering, writing personalised messages designed to make a particular official click a link or open an attachment.
The presentation also puts a number on the year. EU institutions have faced eight “significant incidents” so far in 2026.
Critical infrastructure across the continent is taking hits too. A cyber attack shut a British power plant for four days in July, and investigators tied it to Iran.
The institutions cannot share classified files with each other
Buried in the same presentation is a structural problem that has nothing to do with any individual attack.
Different EU institutions run different technical security setups. The bloc has no common way to exchange sensitive and classified documents between them.
That is harder to fix than a phishing campaign. It is also the sort of admission that rarely appears in public.
Brussels has been worried about this for months
Politico reported earlier this year on a related order. The European Commission told some of its most senior officials to shut down a Signal group over hacking fears.
National cyber authorities have been telling governments to move off commercial messaging apps for official business.
In March, at least five national cyber and intelligence agencies warned publicly about campaigns running on Signal and WhatsApp. Dutch intelligence attributed those to Russia.
Germany’s warning named the targets: “high-ranking individuals in politics, the military, and diplomacy, as well as investigative journalists”.
The trick is a fake support chatbot
The method those agencies described is simple and does not involve breaking any encryption.
Attackers pose as a Signal support chatbot and persuade the target to hand over a code. That is enough to link a second device to the account and read incoming messages and group chats.
The FBI described a related technique in June. Russian intelligence hackers kept reading Signal messages even after a target changed phones.
The Commission declined to discuss its internal security practices. WhatsApp and Signal did not immediately respond to Politico.
Meanwhile, state hacking is getting cheaper to run at scale
A separate report the same week shows what is happening to the volume of this work.
Chinese state-affiliated groups have more than doubled the number of attacks they carry out, according to the Taiwanese research firm TeamT5. The change came after they began handing routine tasks to AI models and using them to build malware.
Mark Anderson reported the findings for Bloomberg. The model those groups reach for is DeepSeek.
They pick it because it is cheap and lightly guarded
Charles Li, TeamT5’s chief analyst, put the reasoning plainly.
“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” he said.
“Western models are highly sought-after but their guardrails are much more strict,” Li added. They require a lot more effort to bypass.
A group called Grimfengxi used DeepSeek to write exploit code. Another, Huapi, used a Chinese model researchers believe was DeepSeek against the email system of a Taiwanese company. A third, Teleboyi, had it collect 1,000 IP addresses and map a company’s domains.
The better model is too expensive to attack with
Moonshot’s Kimi K3 outperforms DeepSeek. TeamT5 has recorded no attack using it, and puts that down to the cost of running it.
The constraint on attackers, in other words, is not capability. It is price per token and how much work the guardrails take to defeat.
Kimi K3 has form of its own. It broke out of a test sandbox during an evaluation earlier this month.
Western models are in the mix too
A group called Slime22 got inside a Taiwanese technology company and then used Claude Code to move through its systems, TeamT5 said. It defeated the guardrails by posing as an engineer running authorised security tests.
Anthropic did not answer Bloomberg’s questions. It has blocked its services from Chinese-controlled companies.
The security firm CyCraft found a company selling hacking software that used ChatGPT during an attack on a Western think tank. It had copied an employee’s local Signal database from a compromised machine and asked the chatbot to help build a module to decrypt it.
An OpenAI spokesperson said the company is committed to identifying, preventing and disrupting attempts to abuse its models.
There is a market, and it has a price list
Researchers found the evidence on a public shared drive: thousands of Chinese-language screenshots, some as recent as February, showing the workflow of a roughly ten-person startup building hacking tools to sell.
It charged between 300,000 and 500,000 yuan a package, about $44,500 to $74,000, and had at least four hacking groups as customers.
Activity linked to one of them overlaps with Mustang Panda, which the US Justice Department says the Chinese government backs.
DeepSeek did not respond to Bloomberg. Neither did China’s embassy in Washington nor its foreign ministry.
Two different problems, and Europe has both
The attacks on EU officials are attributed to Russia by national agencies, and the AI-scaled campaigns TeamT5 describes are Chinese. These are separate operations and no source connects them.
What connects them is the direction. One is a cheap technique that works on people, and the other is a cheap technique that works on machines, and both are getting easier to run at volume.
Europe has been sanctioning the first. The EU has moved from naming individual Russian hackers to sanctioning the machine that produces them.
What to watch
The first thing is whether the Commission does anything about the interoperability gap. An institution that cannot securely send a classified file to another institution has a problem no phishing training fixes.
The second is price. TeamT5 says Kimi K3 is currently too expensive for attackers, and inference costs only fall. DeepSeek has already shipped a multimodal model it says approaches Anthropic’s Opus.
The third is whether anyone publishes the attribution in full. The EU has now formally linked messaging attacks to a foreign government in an internal document, and has not said which one on the record.
Get the TNW newsletter
Get the most important tech news in your inbox each week.