Smartphone messaging app with confidential data being pulled into a digital vortex, illustrating messaging security and data-loss risks.

Forget Ransomware: The Real Data Loss Problem is in Your Pocket

DLP vendors pitched “context, not content” at Black Hat. EU hacks, a TikTok reversal, and a Pentagon violation just proved the point.

Nation-state actors are actively targeting the commercial messaging apps used by high-ranking government officials.

It’s the latest chapter in a broader reckoning over consumer platforms and national security.

U.S. officials have accused TikTok of spying on users, shaping public opinion, and exposing the confidential movements of American troops. These were serious enough concerns to get the app banned from government devices under a 2022 law.

Beyond the Break weekly cybersecurity newsletter — Subscribe

And in March 2025, the risk cut the other way. Defense Secretary Pete Hegseth shared sensitive, nonpublic operational strike details in a Signal group chat that inadvertently included a journalist, an episode that became known as Signalgate.

Is anyone starting to see a pattern?

Using consumer-grade apps instead of state-controlled apps for official business is becoming more than a Hegseth problem. It’s a European one too.

The latest example comes from an internal presentation obtained by POLITICO, revealing that foreign governments have been targeting the WhatsApp and Signal accounts of high-ranking European Union officials.

The trendline here isn’t just “heads of state need to be more careful while doomscrolling social media and chatting with strangers.” It’s about a lack of security hygiene at the intersection of business and personal app choices. This isn’t applicable to just senior officials, but for any workforce.

It’s the kind of trend that lets data-loss-prevention vendors say, “we told you so”.

Verizon’s 2026 Data Breach Investigations Report, which tracked more than 22,000 confirmed breaches, flagged the same blind spot at the corporate level. Attackers are increasingly reaching employees through WhatsApp, social media, and personal email instead of the corporate inbox. Why? Because those are the attack vectors most enterprise security tools don’t cover. Mobile-based social engineering, such as fake texts, spoofed calls, are now succeeding 40% more often than traditional email phishing, VDBIR reports.

At Black Hat 2026 earlier this month, Jazz Director of Product Management Roi Vanunu boiled the DLP problem down to one question: “Is it okay for this data to leave the organization?”

The harder question, he said, is context: “Is that a sanctioned application? Is that an unauthorized external party?”

Comms Apps: Love vs. Hate vs. It’s Complicated

Signal isn’t a stranger to Brussels. The European Commission recommended it to staff in February 2020 as the preferred app for external communications with people outside the institution – encrypted, open-source, and vetted after earlier breaches hit EU diplomatic systems.

That guidance didn’t quietly fade. As recently as December 2025, the Commission was still steering staff toward Signal over WhatsApp or Telegram, this time adding a specific caveat. Users must enable disappearing messages, and verify contacts through a separate channel. These were precautions aimed squarely at preventing a Brussels version of Signalgate.

In other words, the Commission was actively hardening its Signal guidance against a Hegseth-style failure just seven months before its own officials turned up as hacking targets.

Then came a phishing campaign that Dutch intelligence disclosed back in March.

According to General Intelligence and Security Service reporting at the time, hackers impersonated Signal’s own support system, walking targets through a fake verification process that handed over account access. The goals was to plant malware on the phone so adversaries could read incoming messages and monitor group chats without the victim necessarily noticing anything was wrong.

The Dutch report came at the same time as a series of warnings from national cyber and intelligence agencies – at least five, led publicly by the Netherlands’ AIVD and MIVD and echoed by German authorities – telling governments to move away from commercial messaging apps like WhatsApp and Signal for official business.

That contradictory advice came from the same institution that had spent five years telling its own staff to do essentially the opposite. The Dutch advisory itself pointed at the reason that Signal and WhatsApp’s encryption is exactly what makes them attractive for handling sensitive material. It’s also exactly what makes an official’s account worth hacking.

The U.S. has been navigating its own version of this calculus, in the opposite direction.

In August, the White House formally lifted its ban on TikTok on federal government devices, after the Justice Department concluded the app’s new majority-American ownership structure. Oracle, Silver Lake, and MGX now hold the controlling stakes, with ByteDance reduced to just under 20%. That meant TikTok no longer qualified as a “covered application” under the 2022 law that triggered the original ban.

Where TikTok’s national security story ended in a green light, Signal’s within the Pentagon went the other way. An inspector general report released in December 2025 found that Defense Secretary Pete Hegseth violated existing DoD policy, which permits Signal only for unclassified recall exercises, not for processing or storing classified information such as sharing operational strike details in a Signal chat that included a journalist.

Two governments, two consumer apps, two opposite rulings. Neither one settles the underlying question Vanunu raised in a Black Hat hallway. Is it okay for this data to leave the building, and through what door?

The Fix Nobody’s Finished Building

The EU’s answer, on paper, is sovereignty. Six member states are building their own messenger apps. NATO and the German military already run Matrix-based systems. The Commission says it’ll finish its own switch by year’s end. Belgium’s is already live. Prime Minister Bart De Wever and other officials use BEAM, a closed government app built with WhatsApp and Signal’s features but none of their exposure. Belgian Secure Communications director Brandon De Waele put it simply, a closed system with only government employees on it removes the opening hackers used.

That leaves the Commission stuck recommending the very app it’s telling everyone else to abandon by a 2026 year-end deadline. Meanwhile, the July presentation underscores the risk during the transition and the mixed message around using commercial apps.

Sovereignty of secure messaging apps is the plan, but they aren’t deployed yet.

None of this makes Signal or WhatsApp insecure. The encryption held the accounts didn’t.

Consider the scale of the problem: 34% of organizations report at least one account-takeover incident every month, according to Barracuda’s latest Email Threats Report. That is via the email channel alone. The one with the most mature defenses.

Messaging apps largely lack the kind of enterprise tooling built to protect an inbox. Signal can’t out-encrypt a fake support chatbot catching a tired official at the wrong moment. That takes a hardened platform built for institutions, not a harder lock on the consumer one.

Until those platforms are fully deployed and adopted, the pattern holds true to Brussels, Washington, or anyone who’s chosen a commercial app over the sanctioned one. Whether it’s TikTok’s ownership chart, or Hegseth’s Signal chat, or an EU cyber presentation – these are all different stories that hover around the same unresolved question.

Who decides what’s okay to leave the building, and who enforces it once they have.

Total
0
Shares
Previous Article
Retro robot AI agent orchestrating an autonomous ransomware attack from initial access through encryption and extortion

Fully Autonomous AI Agent Executed a Ransomware Attack, NCC Group Says

Next Article
Chain-link security fence with a high-voltage warning sign at a power substation

White House Declares Cyber National Emergency Over Power Grid Backdoors

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading