The State Messenger: Poland Abandons Signal for Sovereign Encrypted Communications- 185
June 9, 2026
Russia's intelligence services have been systematically compromising Signal accounts belonging to European government officials, journalists, and public figures — not by breaking Signal's encryption, but by calling people and pretending to be Signal support staff. The social engineering is unsophisticated. It has worked repeatedly, including against Dutch government employees. Poland's response is to abandon Signal entirely and build its own messenger. The decision raises a question that every government dependent on foreign-owned communications infrastructure will eventually face: when the threat is not the technology but the trust around it, does switching platforms solve anything?
The Polish government's decision to direct public officials away from Signal and toward a domestically developed encrypted messenger is not primarily a technical story. It is a sovereignty story — one that illustrates how state-sponsored social engineering campaigns against encrypted communication platforms are reshaping government communications policy across Europe, and how the response to that threat creates its own complications.
The immediate trigger is documented: Russia-linked APT groups have been running large-scale phishing campaigns targeting Signal accounts of government officials, journalists, and public figures across Europe. Dutch intelligence agencies AIVD and MIVD reported a successful campaign against their own government employees and journalists, noting that "Russian hackers have likely gained access to sensitive information" through compromised Signal accounts. The FBI, CISA, and Germany's information security department issued near-identical warnings. The attack vectors are not sophisticated in a technical sense: attackers impersonate Signal support staff, create urgency through messages claiming accounts are blocked, abuse the platform's Linked Devices feature via malicious QR codes to clone accounts, or persuade targets to surrender verification codes. The sophistication is social, not technical — and social engineering against any communications platform, however well-designed, does not respect end-to-end encryption.
Poland's response is to launch mSzyfr — developed by the Ministry of Digital Affairs and the Scientific and Academic Computer Network — as "the first secure instant messenger fully under Polish jurisdiction." The policy rationale is explicit: mSzyfr keeps communications infrastructure under Polish legal authority, avoiding the jurisdictional exposure that comes with relying on US-headquartered platforms that operate under American law and may be subject to American legal processes or intelligence community relationships that Poland cannot audit or influence.
The implementation, however, reveals the limits of the sovereignty argument in practice. mSzyfr relies on multi-factor authentication provided by Microsoft, with Google and FreeOTP as alternatives. Users who want to retain message access after logging out must store a recovery key in a password manager — most of which are foreign-owned or open-source. The platform replaces Switzerland-founded Threema, which Poland began endorsing in 2022, but cannot transfer message history due to encryption. mSzyfr is not publicly available; only employees of approved organizations can receive invitations.
The underlying problem mSzyfr is designed to solve — that attackers can socially engineer access to communications platforms regardless of their technical security — is not resolved by switching platforms. The same impersonation, QR code abuse, and urgency-creation techniques that worked against Signal will work against mSzyfr the moment it becomes a sufficiently high-value target. What mSzyfr does offer is jurisdictional clarity and the ability for Polish authorities to audit and control the infrastructure their most sensitive communications depend on. Signal subsequently introduced new warnings and alerts inside its platform to help users identify potential imposters, a response that addresses the social engineering vector directly. The policy outcome — two platforms improving simultaneously under adversarial pressure — is arguably the best available result from an uncomfortable situation.