Poland limits the use of Signal in public administration
The Polish government has recommended that public administration limit the use of the Signal app for official communication and switch to national communication platforms. This is a response to phishing campaigns that, according to Polish authorities, targeted publicly exposed individuals and employees of state institutions.

The reason isn’t broken ciphers, but phishing against officials
The Polish government has recommended that public administration limit the use of the Signal app for official communication and switch to national communication platforms. This is a response to phishing campaigns that, according to Polish authorities, targeted publicly exposed individuals and employees of state institutions.
This is not a report that Signal’s encryption has been broken. The Polish warning describes a different problem: attackers are trying to take over user accounts using social engineering, fraudulent messages, and abuse of authentication mechanisms.
Attackers impersonated Signal support
According to the Polish Ministerstvo cyfryzacji, national CSIRT teams identified phishing campaigns run by advanced APT-type groups. They reportedly impersonated, for example, the technical support of the Signal app and sent victims messages about an alleged account suspension.
The goal was to trick users into clicking a malicious link, handing over a verification code, or taking a step that would allow the attackers to take control of the communications.
Similar campaigns have appeared in other European countries in recent months. The Dutch intelligence services AIVD and MIVD have previously warned about attacks on accounts in Signal and WhatsApp that targeted government employees, journalists, and other sensitive individuals.
Signal was not "broken." The weak point was the user and account management
It is crucial to distinguish two things.
Signal as an encrypted messenger has not, according to available information, been cryptographically broken. The attacks did not target the end-to-end encryption itself, but the users and the processes around account verification.
Attackers can, for example, convince a victim to give them a verification code, PIN, or to scan a QR code that the attacker uses to add their own device as an additional device on the account. This can give them access to part of the communications without having to break the encryption.
This is a fundamental problem for public administration. For an ordinary user it is a privacy breach. For a politician, soldier, or official it can mean access to sensitive contacts, work groups, and information that should never have left a controlled environment.
Poland recommends mSzyfr and SKR-Z
Polish authorities therefore recommend using state-managed national tools for official communication.
The first is mSzyfr, an encrypted messenger intended for public administration and entities of the Polish national cyber security system. It is being developed by Ministerstvo cyfryzacji together with NASK-PIB. According to the government, the infrastructure is to be operated in Poland and under Polish jurisdiction.
The second tool is SKR-Z, a system for classified communication up to the level of „ZASTRZEŻONE“, i.e. „EU RESTRICTED“ and „NATO RESTRICTED“. It is intended to operate in an environment isolated from the internet.
With this, the Polish government clearly separates routine official communication from communication with a higher level of sensitivity. It also recommends that Signal not be used for transmitting classified or sensitive information.
Europe faces the same problem: a secure tool is not enough
The Polish case fits into a broader European trend. States increasingly face the question of how politicians, officials, the military, or critical infrastructure should communicate outside ordinary email systems.
The problem is not only whether a particular application is technically secure. Even a very well-designed messenger can fail when an attacker convinces the user to open the door themselves.
That is precisely why attacks on Signal, WhatsApp, or other messengers are attractive to espionage groups. Instead of breaking encryption, it is enough to exploit trust, time pressure, and user inattention.
Attribution to Russia remains sensitive
The Polish announcement speaks of APT groups linked to the services of hostile states. Some media and security sources associate these campaigns with actors supported by Russia.
However, this attribution should be treated cautiously. In publicly available Polish documents the primary emphasis is on phishing campaigns, account takeovers, and the risk to public administration. Direct technical evidence clearly tying a specific group to the attacks has not been published in sufficient detail in available sources.