Germany’s Public Prosecutor’s Office is investigating possible espionage in connection with a phishing campaign targeting German politicians via the Signal messaging service.

A spokeswoman for the office confirmed to dpa on Friday that Germany’s highest law enforcement authority took over the investigation as early as mid-February.

Germany’s domestic intelligence service (BfV), and the Federal Office for Information Security (BSI) issued a public warning in February regarding the ongoing cyberattack via Signal.

Last week, they published a further security advisory containing specific instructions, after discovering that German journalists, military personnel and politicians had all been affected.

The advice stated that the campaign was “likely being carried out by a state-sponsored cyber actor”. Current findings indicate that the campaign remains active and is gaining momentum.

The German news magazine Der Spiegel reported that members of the Bundestag from virtually all parliamentary groups are said to have been affected by the phishing attacks. NATO officials are also reported to have been targets of the large-scale campaign.

To gain access to the address books and data of specific users, the attackers first send a message asking the user to enter a PIN, click on links or a QR code. This then enables the hackers to move around internal chat groups under a false identity.

Similar attacks via Signal have also been detected in the UK and the Netherlands since winter 2025. The Dutch government has suggested Russia is behind the campaign. Germany’s Public Prosecutor’s Office has not yet commented on a possible instigator.