German intelligence services warn of attempts to hack Signal accounts: WhatsApp could be the next target

German intelligence services warn of attempts to hack Signal accounts: WhatsApp could be the next target

Los german intelligence services have issued a statement warning that they are taking place attempts to instant messaging app accounts Signal belonging to important personalities such as politicians, military, diplomats or journalists to obtain sensitive information.

The German intelligence warning comes after the Federal Office for the Protection of the Constitution of and the German Federal Office for Information Security have collected information in this regard.

Hackers impersonate the app’s help desk with the aim of power access conversations that the victims maintain and also the contact list that they have.

“The goal is surreptitiously access individual and group conversationsas well as the contact lists of the affected people,” the German intelligence services have warned.

Two methods

Specifically, cybercriminals (who are probably supported by countries interested in obtaining this sensitive information) use two methods to try to deceive victims.

The first of them allows you to take full control of the account through the sending a PIN or verification code. The second is based on associating the Signal account with a device controlled by a hacker using the use of a QR code which allows direct access to the messages that are sent and received in the application.

In this sense, German intelligence highlights that These types of attacks are “effective” because most users do not have the habit of periodically checking the linked devices section.

WhatsApp, in the spotlight

On the other hand, the German authorities have highlighted that WhatsApp offers linking features similar to Signalhence These types of hacking attempts could also be used in that other messaging app.

Consequently, the German intelligence services, whether Signal or WhatsApp, ask the population to “never respond to messages supposedly sent by the support service” and block and report those accounts.

source