Alongside international partners, the NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.
What has happened?
While apps like WhatsApp, Messenger, and Signal are essential tools for our daily communication, they have become prime targets for cyber threats.
The NCSC, alongside international security partners, has observed an increase in malicious activity from Russia-based actors. These groups are specifically leveraging messaging platforms to target high-risk individuals.
Who is affected?
Why High-Risk Individuals are Targeted
High-profile users are at an elevated risk of account compromise because of their professional roles, public influence, or access to sensitive data and influential contacts. You are likely considered a high-risk individual if your work involves managing information that would be valuable to foreign intelligence services.
Historical data from the NCSC confirms that state-affiliated groups—including China’s APT31, Russia’s Star Blizzard (FSB), and Iran’s IRGC—have consistently targeted the personal and professional accounts of government officials.
Common Attack Strategies
Malicious actors use sophisticated social engineering and technical exploits to gain access. Be alert for attempts to:
-
Hijack Accounts: Tricking you into revealing login credentials or two-factor authentication (2FA) recovery codes.
-
Unauthorized Access: Silently linking their own devices to your messaging accounts.
-
Infiltration: Sneaking into private group chats to eavesdrop on sensitive discussions.
-
Impersonation: Posing as a trusted colleague, friend, or family member.
-
Social Engineering: Sending malicious links or deceptive QR codes designed to steal data or install malware.
What should I do?
While social engineering remains a universal threat, you can significantly lower your risk by adopting these defensive habits:
Communication Best Practices
-
Information Sensitivity: Avoid sharing highly confidential data over standard messaging apps.
-
Professional Boundaries: Use company-provided devices and messaging platforms for work, ensuring you strictly follow your organization’s security policies.
-
Zero Trust: Never share verification codes and avoid scanning unsolicited or unexpected QR codes.
Account Security Settings
-
Multi-Factor Authentication: Enable two-step verification immediately (Signal users should look for “Registration Lock” in settings).
-
Passkeys: Activate passkeys on apps that support them, such as WhatsApp and Signal, for more secure logins.
-
Data Minimization: Use disappearing messages on personal accounts to limit the history available to an attacker.
-
Note: Ensure this complies with any legal or professional record-keeping obligations.
-
Proactive Monitoring
-
Audit Devices: Periodically check your “Linked Devices” settings to ensure no unauthorized hardware has access.
-
Group Vigilance: Review group chat members regularly; independently verify or remove any unrecognized participants.
-
Identity Checks: Be wary of impersonation attempts, messages from unknown contacts, or duplicate contacts appearing in your list.
More reading
https://www.ncsc.gov.uk/news/ncsc-warns-of-messaging-app-targeting