Suspected Russian hackers use fake Google sign-ins and WhatsApp links to trick victims and hijack private accounts.
Cybersecurity researchers have uncovered a new wave of online attacks where suspected Russian espionage groups are abusing official sign in systems on Google and WhatsApp to take over private user accounts.
Rather than trying to break down complex computer defenses, the hackers create realistic fake login pages and malicious device links that trick victims into giving away total access to their personal messages, emails, and cloud storage.
The sneaky campaign targets defense workers, government officials, university researchers, and policy groups across Europe and the United States.
The widespread safety warning was officially published by threat researchers on August 20, 2026, following detailed tracking by the Google Threat Intelligence Group.
Security analysts identified three distinct hacking teams, including groups known as UNC5976 and UNC7005, that have been setting up fake website addresses since early March 2026.
Although technology teams regularly shut down these malicious addresses, the attackers quickly create fresh web domains to target people working in European defense organizations, military groups, and non profit centers in Ukraine, Armenia, and NATO-aligned nations.
The primary reason these online traps are so successful is that they take advantage of standard habits people use every day when logging into digital services.
In one common scam, targets receive emails inviting them to join a secure online video call or view important shared documents.
When victims click the link, the fake site asks them to scan a QR code or approve a Google access request to sign in. Because the prompt looks completely normal, users unknowingly link their WhatsApp account directly to the hackerโs laptop or give the attackers a digital passkey that lets them read private emails indefinitely without needing passwords.
See Also: Texas College Student Exposes Rogue AI Hacking Attempt on Open Source Code
Explaining how the groups trick victims by mimicking legitimate European defense platforms, Google security researchers reported that “UNC7005 registered domains spoofing the legitimate Finnish Operations Center (FOC), which supports Finnish companies in the defense and security markets, specifically in the context of the North Atlantic Treaty Organization (NATO)”.
Detailing how the WhatsApp trap operates when a victim opens a malicious link to view shared files, Google threat analysts added, “The phishing pages distributed by the attacker lure targets into linking their WhatsApp accounts with an attacker controlled device to join a secure WhatsApp call, chat, or document share”.
Highlighting the main targets and regions affected by these ongoing account hijacking campaigns, official reports confirmed, “Its operational focus is primarily centered on the military, aerospace, defense industrial base, and NGOs/think tanks,” adding that “much of the group’s geographic targeting has centered on Ukraine and Armenia”.
By taking advantage of routine daily sign ins, cybercriminals are proving that a single careless click can compromise sensitive personal data.
Staying safe requires double checking website addresses, avoiding unexpected sign in requests, and checking connected device settings inside chat apps to disconnect unknown logins immediately.

