Allied Intelligence — 2026-05-19

Poland Orders Officials Off Signal After Russian APT Groups Target Government Accounts

BLUFPoland's retreat to sovereign platforms signals other NATO members will likely follow, trading the security assurance of audited commercial encryption for state-controlled account provisioning whenever Russian intelligence targets officials directly.

Poland's Government Plenipotentiary for Cybersecurity on May 14, under Deputy Prime Minister Krzysztof Gawkowski's signature, directed National Cybersecurity System entities to abandon Signal for two domestic platforms: mSzyfr, managed by NASK-PIB, and SKR-Z for classified communications 12. National CSIRT teams identified active phishing campaigns by APT groups the advisory attributes to hostile foreign intelligence services, targeting politicians, military personnel, and government employees 12; Security Affairs reported officials specifically tie the campaigns to Russian-backed actors 3. The advisory states Signal's encryption was not broken; attackers impersonated support staff to harvest verification codes and PINs, or deployed malicious QR codes to silently link attacker-controlled devices to victim accounts 23. mSzyfr replaces Threema, Poland's recommended platform since 2022, and operates entirely within Polish jurisdiction 23.

Analysis
The attack vector exploited account-management features, specifically credential harvesting via impersonated support staff and malicious QR codes that silently linked attacker devices, not cryptographic weakness in Signal. Per official Polish Ministry of Digitization publications, mSzyfr's closed-enrollment, Polish-hosted model transfers account-provisioning and revocation authority to Warsaw in ways Signal's architecture cannot provide, reflecting a broader European preference for sovereign infrastructure over audit transparency. Replacing Threema marks the operational ceiling of official tolerance for commercially managed platforms under active state-linked targeting. Warsaw's institutional drive for sovereign communications may predate the APT campaigns, with the advisory furnishing political leverage rather than generating a new operational trigger.
3 sources
  1. Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger - Polish Ministry of Digitization (gov.pl)
  2. Poland urges officials to ditch Signal for state-run messaging apps - CyberInsider
  3. Poland shifts away from Signal following cyberattacks on officials accounts - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE