Russian-backed hackers have gained access to Signal and WhatsApp accounts used ‌by officials, military personnel and journalists, as claimed by two intelligence agencies in the Netherlands.

https://libretechni.ca/post/1016056

Russian-backed hackers have gained access to Signal and WhatsApp accounts used ‌by officials, military personnel and journalists, as claimed by two intelligence agencies in the Netherlands. - LibreTechni.ca

Lemmy

“Despite their end-to-end encryption option, messaging apps ​such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information,” said ​MIVD director, Vice-Admiral Peter Reesink.
You are only allowed to talk to yourself in a vaccum.

Classic phishing. Secure channels are only as good as the gate and key handling surrounding them.

For official org-based accounts like that, I could imagine a messaging system where you can only see and share security codes with a second-person factor. If the user wants to access it, at least another authorized trained person must take part, acknowledge, and authorize the action. As long as users can access key information relatively easily, they are phishable.

It’s a phishing attack but I’m still going to link simplex for people looking for something more secure than signal running on google cloud.

simplex.chat

SimpleX Chat: private and secure messenger without any user IDs (not even random)

SimpleX Chat - a private and encrypted messenger without any user IDs (not even random ones)! Make a private connection via link / QR code to send messages and make calls.