The President, two ministers, and Chancellor Merz's inner circle
Spiegel first reported on Tuesday, April 22, that the victims included Julia Klöckner — Bundestag President and a member of the CDU presidium, which communicates via a Signal group chat that also includes Chancellor Friedrich Merz. SecurityAffairs ↗ On Friday, April 25, the same magazine added the names of two ministers: Verena Hubertz (SPD, Construction) and Karin Prien (CDU, Education and Family). Spokespeople for both ministries declined to confirm the attacks to Spiegel. Euronews ↗According to Spiegel, staff from the Bundesamt für Verfassungsschutz (BfV) — Germany's domestic counterintelligence agency — personally examined the Chancellor's device. No anomalies were found on Merz's Signal account. Euronews ↗ Factions across the political spectrum are affected — the CDU, SPD and Die Linke have all acknowledged that their members of parliament were affected; the victims also include officials, diplomats, NATO soldiers and journalists. Courthouse News ↗
Mechanism: exploiting the "linked devices" feature
The attack did not break Signal's encrypted communication — instead, it exploited the legitimate "linked devices" feature, which allows a single account to be used on multiple devices at once. The Hacker News ↗ The attackers sent messages posing as Signal support, a fake CDU group chat, or security alerts containing a QR code. When the QR code was scanned, a second device controlled by the attacker was linked to the victim's account — allowing the attacker to receive new messages in real time. Google TIG ↗In a second variant of the attack, the victim was prompted to enter a PIN or open a link; once the victim was successfully deceived, the attacker gained access to chats, groups and shared photos and files — and could even impersonate the victim. Courthouse News ↗ The BfV and the Bundesamt für Sicherheit in der Informationstechnik (BSI) had already warned about this technique back in February; the warning was renewed last week. Euronews ↗
Attribution: between a "state actor" and Russia
The official German line is cautious. On Friday, a BMI spokeswoman spoke of an attack "probably conducted by a state actor" — without naming a specific country. The Generalbundesanwalt is investigating on "initial suspicion of espionage," likewise without public attribution. Courthouse News ↗ In its notice to Bundestag factions, the BfV speaks of a "state-directed cyber actor" and warns that, through compromised accounts, "sensitive information is flowing massively to Russia." Euronews ↗Marc Henrichmann (CDU), chairman of the parliamentary body overseeing intelligence services (PKGr), took the political attribution further. "The latest phishing attempt from Russia against German politicians and journalists is a wake-up call for all of us," he told the public broadcaster ZDF. Euronews ↗ The Dutch civilian intelligence service AIVD had already linked the wave of phishing attacks on Signal to "Russian state actors." Handelsblatt ↗
The technical context significantly strengthens the Russian trail. Microsoft Threat Intelligence recorded a campaign by the group COLDRIVER (also known as Star Blizzard), which Western intelligence services — including the UK's NCSC, the US CISA and the FBI — have attributed since December 2023 to Center 18 of Russia's Federal Security Service (FSB). CISA ↗ Google Threat Intelligence Group identified parallel activity by the clusters UNC5792 and UNC4221, which it likewise ties to Russian state intelligence. Google TIG ↗ Moscow denies any responsibility. Courthouse News ↗
Response: Bundestag issues warning, debate over desktop version
The Bundestag leadership — specifically its digitalization department — sent a security warning to all members of parliament this week, the Berliner Morgenpost reported. Euronews ↗ Bundestag Deputy President Andrea Lindholz (CSU) told Politico that a complete ban on Signal was ruled out — members of parliament are free to decide for themselves, in her view — but parliament is considering at least restricting the desktop version of the app on official computers. Euronews ↗Konstantin von Notz (Greens), deputy chairman of the PKGr, warned AFP that "the number of unreported victims will continue to grow in the coming days." He added a sentence about the broader risk to parliamentary communication: "At this point, no one can say with certainty whether the integrity of members' communications is still guaranteed." Courthouse News ↗
Broader context: a series of hybrid activities
The Signal affair is not an isolated incident. In early April, German intelligence services accused hackers linked to Russian military intelligence of infiltrating internet routers to collect sensitive data. The same group has also been linked to attacks on air traffic control and to spreading disinformation ahead of last year's elections. Courthouse News ↗A concrete precedent for phishing via Signal in Germany was already reported by Spiegel in March, when an attack hit Arndt Freytag von Loringhoven, former deputy president of Germany's BND intelligence service and co-author of the book "Putins Angriff auf Deutschland." The attackers posed as Signal support and requested his PIN; they succeeded in breaking into his account and sending malicious links to his contacts. SecurityAffairs ↗
Read also: Germany summons Russian ambassador over hybrid actions
What hotinfo is watching
- The scale of the targeting — how many of the 300+ are publicly confirmed, and which other ministries and MPs (Spiegel, Tagesspiegel, Politico)
- Berlin's public attribution — whether the interior ministry or the BfV officially names Russia or "a state actor"
- Political consequences — the Bundestag's decision on the desktop version of Signal (Lindholz, CSU)
- Technical forensics — the APT group (COLDRIVER/Star Blizzard, UNC5792, UNC4221), Microsoft TI and Google TIG
- Moscow's response — a denial through the foreign ministry or a diplomatic reaction (a PNG declaration by Berlin?)
- Loringhoven and other affected ex-BND figures — further incidents against former intelligence officers






