{"id":13557,"date":"2026-04-28T14:27:25","date_gmt":"2026-04-28T14:27:25","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/29\/kloeckner-prien-graichen-top-level-phishing-april-2026-2\/"},"modified":"2026-05-20T20:28:21","modified_gmt":"2026-05-20T20:28:21","slug":"klockner-prien-graichen-when-the-top-brass-clicks-a-phishing-link","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/04\/28\/klockner-prien-graichen-when-the-top-brass-clicks-a-phishing-link\/","title":{"rendered":"**Top-Tier Phishing: How CISOs Protect Their Channels**"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">5 Min. Reading time<\/p>\n<p><strong>Bundestag President Julia Kl\u00f6ckner, Education Minister Karin Prien and Building Minister Verena Hubertz were compromised via Signal phishing because they forwarded a verification code to a seemingly trusted contact. Account-Takeover via messenger, technically not a classic link click. Federal Prosecutor General Jens Rommel has been investigating since February on suspicion of espionage. Patrick Graichen, former State Secretary for critical infrastructure, simultaneously posted on X a pay\u2011for\u2011likes scam and falsely accused world editor\u2011in\u2011chief Ulf Poschardt of book marketing. Different vectors, a shared management lesson: awareness was built on the wrong floor.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Around 300 accounts affected, BAW investigation since February.<\/strong> Federal Prosecutor General Rommel pursues espionage suspicion. BSI and BfV classify the actor as likely state\u2011controlled. Roderich Henrichmann (PKGr) publicly named Russia as the probable source; technical attribution is pending.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Verification code as vector.<\/strong> Kl\u00f6ckner, Prien and Hubertz forwarded the 6\u2011digit Signal code to a seemingly trusted contact. Standard vector for two years in every BSI awareness notice.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Graichen case follows a different pattern.<\/strong> Public false accusation against Ulf Poschardt after scam detection, without account compromise. Shared lesson with the Signal wave: top\u2011level reflex without a second pair of eyes check.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Procurement consequence for CISOs.<\/strong> Top\u201150 accounts need their own protection model of technology, process and behavior, not the 25\u2011minute mandatory e\u2011learning for staff.<\/li>\n<\/ul>\n<\/div>\n<p><strong>What is verification\u2011code theft?<\/strong> In an account takeover via Signal or WhatsApp, an attacker registers the account on a foreign device. The messenger sends a 6\u2011digit confirmation code via SMS to the legitimate owner. Whoever forwards this code to a seemingly trusted contact hands over the account. Protection: a two\u2011factor PIN in the Signal settings prevents takeover even if the code is intercepted.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What happened in April<\/h2>\n<p>The Signal wave has been active since February 2026. According to security circles, roughly 300 accounts are affected in Germany, with additional targets in the Netherlands. The vector is identical for the three female politicians: a known contact address asks via direct message for the 6\u2011digit verification code that has just arrived by SMS. Whoever forwards the code hands over the account login. Kl\u00f6ckner was made public on Wednesday, <a href=\"https:\/\/www.berliner-zeitung.de\/article\/spionageverdacht-auch-bundesministerinnen-prien-und-hubertz-offenbar-von-signal-hacks-betroffen-10032624\">Prien and Hubertz followed on Friday<\/a> as part of the same investigation.<\/p>\n<p>Federal Prosecutor Jens Rommel opened the case already in February 2026 on suspicion of intelligence\u2011agency activity. BSI and the Federal Office for the Protection of the Constitution place the actor within a state\u2011run espionage program. Roderich Henrichmann, member of the Parliamentary Oversight Committee, publicly named Russia as the likely source. A technical attribution by the Federal Prosecutor&#8217;s Office is still pending as of 28\u202fApril\u202f2026.<\/p>\n<p>The <a href=\"https:\/\/nius.de\/gesellschaft\/sicherheitsrisiko-entscheidungstraeger-internet\">Graichen incident<\/a> follows a different pattern: a public false accusation after scam detection, without account compromise. He screenshot a WhatsApp group where money was promised for likes on influencer accounts, and tagged World editor\u2011in\u2011chief Ulf Poschardt, assuming he was behind the request. The mechanism has been staple material in every awareness training for years: foreign country code, micro\u2011reward, gradual escalation to prepaid fees or account details. Graichen was for years responsible for critical infrastructure and energy supply. The link to the Signal wave lies not in the vector but in the reflex: fast, mobile, without intermediate checks.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why awareness thins out at the top<\/h2>\n<p>Three mechanisms explain the finding. At C\u2011level, the inbox is processed in 30\u2011second slots between meetings. Awareness trainings are built for 25\u202fminutes of attention, which simply isn\u2019t available there. The pre\u2011filter performed by office staff disappears as soon as a message lands on a private smartphone. That is exactly where Signal, WhatsApp and an increasing share of political daily coordination run. Anyone who drinks coffee with the chancellor unconsciously treats the everyday swarm scam as a lower\u2011level problem.<\/p>\n<p>The operational consequence has been felt by security teams for years. In internal awareness tests, top\u2011level accounts are rarely better protected than the employee average, and in some sectors measurably worse. Communication pressure, mobile channels and delegation patterns raise the risk, and the experience bonus does not offset it. Procurement reality moves in the opposite direction: awareness budgets flow into mandatory e\u2011learnings for the entire workforce because they are compliance\u2011friendly and billable. The high\u2011value accounts with access to strategy papers, bidding talks and cabinet drafts remain in the same standard module.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What CISOs need to change now<\/h2>\n<p>Top\u2011level protection requires three layers. Technology locks the account, process governs the interim call, behavior trains the reflex. Anyone who only addresses one layer merely shifts the risk instead of reducing it.<\/p>\n<h3>Technology: Account hardening at the device level<\/h3>\n<p>Two\u2011factor PIN for Signal and WhatsApp is mandatory for the top\u201150 accounts, as is the device\u2011pairing overview in the account settings. A session\u2011review routine with the office team checks monthly which endpoints are currently linked to the account. Anyone who finds an unknown entry has the first indicator before any official report. MDM profiles on corporate smartphones filter out risky messenger configurations before they become incidents.<\/p>\n<h3>Process: Callback rule and press office escalation<\/h3>\n<p>No verification code is ever forwarded via messenger, to anyone, not even to one\u2019s own assistant or press spokesperson. Anyone who asks is verified through a callback to a known number. As soon as a board member comments on a security incident or accuses a third party on a private X or LinkedIn account, the matter must be routed to Corporate Communications before posting. The four\u2011eyes principle on private channels is organizationally cumbersome but, with real reach, the only safeguard against false accusations that attract press attention.<\/p>\n<h3>Behavior: Top-50 Coaching as its own procurement<\/h3>\n<p>Extract awareness for the board, supervisory board, legally responsible bodies and their direct assistants. A 1:1 coaching per quarter, delivered by an external pentester with a live demo of the current vector on a second smartphone. Duration 60 minutes, content pre\u2011aligned with the current BSI situation. Costs calculable, impact documentable in the audit, compliance argument solid. Coaching without technology and process remains talking material, that is the lesson of the three female politicians.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Frequently Asked Questions<\/h2>\n<h3>What was the attack vector in the Signal wave?<\/h3>\n<p>The attackers contacted targets from a known address book and asked for the 6\u2011digit verification code that is sent via SMS to a foreign device during new registration. Anyone who passed the code on handed over the account. A two\u2011factor PIN in the Signal settings prevents exactly this breach, because the login additionally requires the self\u2011chosen PIN.<\/p>\n<h3>Who is behind the attacks?<\/h3>\n<p>Federal Prosecutor General Jens Rommel has been investigating since February 2026 on suspicion of espionage. BSI and the Federal Office for the Protection of the Constitution classify the actor as probably state\u2011controlled. Roderich Henrichmann (PKGr) named Russia as the likely source. An official technical attribution by the Federal Prosecutor&#8217;s Office is pending as of 28 April 2026.<\/p>\n<h3>Why was the Graichen tweet a security incident?<\/h3>\n<p>The tweet contained a screenshot of a classic pay\u2011for\u2011likes scam plus a false accusation against world editor\u2011in\u2011chief Ulf Poschardt. The technical vector differs from the Signal wave; the account was not compromised. Both cases share the reflex structure: fast, mobile, without a second pair of eyes check. The reputational fallout from public rapid shots without a press office is the management lesson.<\/p>\n<h3>Which immediate measure is recommended for board members?<\/h3>\n<p>First, enable the two\u2011factor PIN on Signal and WhatsApp. Second, unlearn the reflex of forwarding codes via messenger. Third, verify every unusual direct message by calling back on a known number, never by replying on the original channel.<\/p>\n<h3>How should CISOs reshape their awareness budgets?<\/h3>\n<p>Treat the Top\u201150 accounts as a separate procurement category, with 1:1 coaching per quarter and live demos of current vectors. Mandatory e\u2011learning for staff remains relevant, but does not replace targeted protection for the accounts with strategy and bidder access. Technology and process must run in parallel, otherwise coaching remains ineffective.<\/p>\n<div class=\"evm-styled-box\" style=\"background:#f0f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;\">\n<h3 style=\"margin-top:0;margin-bottom:12px;font-size:1.05em;\">Reading tips from the editorial team<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/28\/eu-ai-act-high-risk-deadline-august-2026-supervisory-gap\/\">EU AI Act 2 August 2026: Where the high\u2011risk gap really lies<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/?p=13213\">ITDR alongside SIEM and EDR: Detection architecture 2026<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/25\/gdpr-fine-april-2026-renault-yoti-enel-bakeca-midsized-cyber\/\">DSGVO enforcement 2026: What the April cases mean for SMEs<\/a><\/li>\n<\/ul>\n<\/div>\n<div class=\"evm-styled-box\" style=\"background:#f8f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;\">\n<h3 style=\"margin-top:0;margin-bottom:12px;font-size:1.05em;\">More from the MBF Media Network<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.digital-chiefs.de\/ai-governance-2026-system-level-vorstand-trust-plattform-eu-ai-act\/\">Digital Chiefs: AI Governance 2026 \u2013 System\u2011Level instead of Use\u2011Case\u2011Level<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudmagazin.com\/2026\/04\/28\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026\/\">cloudmagazin: BSI\u2011KRITIS and cloud usage \u2013 Multi\u2011cloud compliance under NIS2 and C5<\/a><\/li>\n<li><a href=\"https:\/\/mybusinessfuture.com\/made-for-germany-zwischenbilanz-april-2026-foerder-status\/\">MyBusinessFuture: Made for Germany in April 2026 \u2013 Where the 800\u2011billion offensive really lies<\/a><\/li>\n<\/ul>\n<\/div>\n<p style=\"text-align: right;\"><em>Photo: Chaddy \/ Wikimedia Commons (CC BY-SA 4.0)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"Signal verification code theft at Kl\u00f6ckner, Prien, Hubertz plus Graichen own goal on X. Three CISO moves for 2026.","protected":false},"author":50,"featured_media":13545,"comment_status":"closed","ping_status":"closed","sticky":true,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Kl\u00f6ckner signal phishing","_yoast_wpseo_title":"Kl\u00f6ckner, Prien, Graichen: When the top brass clicks a phishing link","_yoast_wpseo_metadesc":"Signal verification code theft at Kl\u00f6ckner, Prien, Hubertz plus Graichen's own goal on X. Three CISO moves for 2026.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/04\/kloeckner-prien-graichen-top-level-phishing-april-2026-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/04\/kloeckner-prien-graichen-top-level-phishing-april-2026-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_wp_old_slug":["kloeckner-prien-graichen-top-level-phishing-april-2026-2"],"footnotes":""},"categories":[3,251],"tags":[],"class_list":["post-13557","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-news"],"wpml_language":"en","wpml_translation_of":13513,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=13557"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13557\/revisions"}],"predecessor-version":[{"id":15139,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13557\/revisions\/15139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/13545"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=13557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=13557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=13557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}