• News/
  • https://www.theregister.com/2025/11/25/cisa_spyware_gangs/

CISA warns spyware crews are breaking into Signal and WhatsApp accounts

The Register
·
Carly Page
·
Published Nov 25, 2025
·
Updated

CISA has warned that state-backed snoops and cyber-mercenaries are actively abusing commercial spyware to break into Signal and WhatsApp accounts, hijack devices, and quietly rummage through the phones of what the agency calls "high-value" users. In an alert published Monday, the US government's cyber agency said it's tracking multiple miscreants that are using a mix of phishing, bogus QR codes, malicious app impersonation, and, in some cases, full-blown zero-click exploits to compromise messaging apps which most people assume are safe. The agency says the activity it's seeing suggests an increasing focus on "high-value" individuals – everyone from current and former senior government, military, and political officials to civil society groups across the US, the Middle East, and Europe. In many of the campaigns, attackers delivered spyware first and asked questions later, using the foothold to deploy more payloads and deepen their access. "CISA is aware of multiple cyber threat actors actively leveraging commercial spyware to target users of mobile messaging applications," the agency said. "These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim's messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim's mobile device." The campaigns CISA flags in its bulletin show attackers doing what they do best: sidestepping encryption entirely by ...

Read full article

Affected Software

2 affected components
Open Systems Signal
Meta WhatsApp
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses warnings from CISA about spyware groups targeting Signal and WhatsApp accounts.

2

What security implications are discussed?

The article highlights the risk of state-sponsored actors using commercial spyware to infiltrate personal messaging apps and compromise users' privacy.

3

What products or software are affected?

The affected software mentioned in the article includes Signal and WhatsApp.

4

Who is behind the spyware attacks?

The article indicates that both state-backed snoopers and cyber-mercenaries are involved in these spyware attacks.

5

What methods are used to compromise these apps?

The article reveals that attackers are utilizing commercial spyware to seize control of accounts and access personal devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203