Warns users of these apps: increasing attempts to hijack accounts

Warns users of these apps: increasing attempts to hijack accounts

These threats are warned about by the National Cyber Security Center under the Ministry of National Defence (NKSC), together with the Second Operational Services Department under the Ministry of National Defence (AOTD) and the State Security Department of the Republic of Lithuania (VSD), who have prepared recommendations for the safe use of messaging applications.

Read more A call from Denmark reported a suicide in Kėdainiai

“Social engineering attacks are becoming increasingly convincing. Malefactors use artificial intelligence, publicly available information, and human trust, so their target is not the applications themselves, but their users. Cybersecurity today starts with the ability to critically evaluate received messages and not make decisions solely due to an artificially created sense of urgency,” says NKSC director Antanas Aleknavičius.

One of the most commonly recorded threats currently is phishing campaigns aimed at stealing authentication data of users of “Signal,” “WhatsApp,” and other messaging platforms. After taking over an account, attackers can read private messages, impersonate the account owner, and use their contacts to carry out further social engineering attacks.

The most commonly used scheme is impersonation of the messaging app’s support service. Users receive messages about allegedly detected suspicious activity, login attempts to the account, or other security incidents. Exploiting the sense of urgency, scammers try to extract SMS verification codes, app PIN codes, or other login information. NKSC reminds that “Signal” never contacts users via messages and does not ask for authentication codes or PIN codes.

Another common scenario is messages from a known person’s account or someone impersonating them. These messages invite the user to join a group, open a link, or scan a QR code. Such actions aim to take control of the account or extract other sensitive information.

Read more Ieva Andriulaitytė: the waste crisis would be solved by transporting it elsewhere, incineration, a state of emergency

The prepared recommendations emphasize that so far no technical vulnerabilities of “Signal” have been identified that would allow attackers to take over users’ accounts. Instead, standard app functionality and social engineering methods are exploited, so the main target of attacks is the person, not the technology. Such threats are also relevant to other widely used messaging platforms, including “WhatsApp” and “Telegram.”

To reduce the risk of becoming a victim of such attacks, NKSC, AOTD, and VSD recommend never disclosing SMS verification codes, app PIN codes, account recovery keys, or other login data. It is also important to critically evaluate unexpectedly received messages, avoid clicking on suspicious links, use QR codes cautiously, and verify that the message was indeed sent by a trusted person before performing any unusual action.

Additionally, it is recommended to regularly check devices linked to the account (“Linked Devices”), enable the “Registration Lock” feature in the “Signal” app, use strong device protection, promptly install operating system and app updates, and, where possible, use multi-factor authentication. These actions significantly reduce the likelihood of account takeover even if the user becomes a target of a social engineering attack.

The recommendations prepared with AOTD, NKSC, and VSD regarding the safe use of “Signal” and other communication channels can be reviewed .

Read more Residents can apply for a new benefit: here is who is eligible

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *