The officials were the targets of so-called “state-sponsored spearphishing,” the presentation said, a term for state-backed, targeted and bespoke campaigns to get specific people to click on dodgy links or open malicious attachments. Hackers used “social engineering techniques” to trick EU officials, crafting personalized messages that were more likely to get targets to take the bait.

Earlier this year, POLITICO first reported that the European Commission told some of its most senior officials to shut down a Signal group over hacking fears. It came at the same time as a series of warnings by national cyber authorities telling governments to move away from commercial messaging apps like WhatsApp and Signal for official business.

In March, at least five national cyber and intelligence agencies publicly warned about ongoing hacking campaigns on Signal and WhatsApp. Dutch intelligence services specifically pinned this on Russia, and Germany warned that hackers were targeting “high-ranking individuals in politics, the military, and diplomacy, as well as investigative journalists.”

The agencies warned then that hackers were posing as a fake Signal support chatbot to persuade users to share their codes, allowing them to take over an account to read incoming communications and group chats.

EU cybersecurity officials said in the presentation that the bloc’s institutions had faced eight “significant incidents” so far this year. One key challenge, they flagged, is that the different EU institutions still use different technical cybersecurity solutions and lack a common solution to exchange sensitive and classified documents.

The European Commission declined to give details on internal security practices in response to POLITICO’s questions on the presentation.

WhatsApp and Signal did not immediately respond to requests for comment.