Article content
In briefShow moreShow lessA fake support message could give attackers access to contacts and closed groups if the PIN was disclosed.
- A fake support message could give attackers access to contacts and closed groups if the PIN was disclosed.
- Signal encryption does not prevent social engineering or compromise of the account itself.
- NSM’s notice was operational security advice, not a new statutory duty.
NSM described an attempted attack targeting users of the popular messaging application Signal. The attackers presented themselves as Signal Chat Support and used that identity to build trust. Their objective was to obtain the user’s PIN, rather than break the messaging service’s encryption.
A PIN in the wrong hands can enable account takeover or make it easier to misuse the account. NSM connected the risk to access to contacts and closed groups. The incident therefore demonstrates why identity verification and user behaviour must be part of security work around encrypted applications.
Encryption and account security are different protection layers. End-to-end encryption can protect message content in transit, but it does not stop an attacker who persuades a user to disclose a secret or gains control of the account. Organisations should explain this distinction clearly in training and incident procedures.
A practical control is to treat unexpected support messages as suspicious, especially when they request a PIN, verification code or other authentication information. Users should verify the request through an independent, known channel and never disclose such information in response to an inbound message.
If compromise is suspected, the organisation should have a predefined process for securing the account, notifying responsible personnel and assessing which contacts or groups may be affected. The incident should also be documented and used to improve training, access controls and channel-selection decisions.
NSM’s thematic report on mobile applications for service devices provides a broader framework for the assessment. The question is not only whether an application has strong security features, but whether it is approved for the information and work context in which the organisation intends to use it.
This was not a new statutory duty or a general ban on Signal. Existing security rules, internal classification requirements and any controls for classified or sensitive information determined which channels were approved. Application choices therefore had to be assessed against the information’s protection needs and the organisation’s own rules.
Sources
Norwegian National Security Authority: “Attempted attacks in a popular messaging app,” 18 March 2026.
Norwegian National Security Authority: “Mobile applications on work devices,” revised 2025.
For discussion
Does the organisation have a clear process for handling fake support messages, compromised accounts and messaging applications used for sensitive information?

