Poland Orders Officials Off Signal After Russian APT Groups Target Government Accounts
Poland's
The attack vector exploited account-management features, specifically credential harvesting via impersonated support staff and malicious QR codes that silently linked attacker devices, not cryptographic weakness in Signal. Per official Polish Ministry of Digitization publications, mSzyfr's closed-enrollment, Polish-hosted model transfers account-provisioning and revocation authority to Warsaw in ways Signal's architecture cannot provide, reflecting a broader European preference for sovereign infrastructure over audit transparency. Replacing Threema marks the operational ceiling of official tolerance for commercially managed platforms under active state-linked targeting. Warsaw's institutional drive for sovereign communications may predate the APT campaigns, with the advisory furnishing political leverage rather than generating a new operational trigger.
3 sources
- Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger -
Polish Ministry of Digitization (gov.pl) - Poland urges officials to ditch Signal for state-run messaging apps -
CyberInsider - Poland shifts away from Signal following cyberattacks on officials accounts -
Security Affairs